USMT脚本调用scanstate.exe返回错误码71,已提权仍报错问题排查
USMT脚本调用scanstate.exe返回错误码71问题
问题描述
我正在开发用于用户配置文件迁移的USMT脚本,调用scanstate.exe时遇到返回码71报错,错误提示为:"无法启动,请确保使用提升权限运行USMT"。
按照官方说明该错误只需退出USMT后以管理员权限重新运行即可解决,但我已经使用域管理员账号登录管理服务器,且以管理员身份运行PowerShell,仍然触发该报错,无法定位问题原因。
已验证配置
- 源计算机与目标计算机均已执行
Enable-PSRemoting -Force完成远程管理配置 - 管理服务器、源计算机、目标计算机的组策略均已开启"允许委派新凭据",且服务器列表中已添加"WSMAN/*.domain.com"规则
- 已检索大量相关资料,和团队成员交叉核对所有配置,仍未找到问题根源
报错代码段
报错发生在远程调用源计算机执行scanstate的逻辑中:
# 启动源端扫描 Write-Host 'Starting startscan on source computer & passing credentials' #Write-Log -Message "Starting startscan on source computer" -File Invoke-Command -ComputerName $SourceComputer -Authentication Credssp -Credential $Credential -Scriptblock { $BSTR = [System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($Using:SecureKey) $Key = [System.Runtime.InteropServices.Marshal]::PtrToStringAuto($BSTR) c:\USMTFiles\scanstate.exe "$Using:SharePath\$Using:Username" /i:c:\usmtfiles\printers.xml /i:c:\usmtfiles\custom.xml /i:c:\usmtfiles\migdocs.xml /i:c:\usmtfiles\migapp.xml /v:13 /ui:$Using:Domain\$Using:UserName /c /localonly /encrypt /key:$Key /listfiles:c:\usmtfiles\listfiles.txt /ue:pcadmin /ue:$Using:Domain\* } -ArgumentList {$UserName,$SharePath,$SecureKey,$SourceComputer,$Domain}
完整脚本代码
#Import-Module -Name 'P:\Information Technology\WindowsPowerShell\Scripts\Modules\Write-Log' -Verbose $PSDefaultParameterValues = @{ 'Write-Log:Label' = 'USMT' } function Invoke-USMT { [CmdletBinding()] param( [Parameter(Mandatory=$true)] [string]$SourceComputer, [Parameter(Mandatory=$true)] [string]$DestinationComputer, [Parameter(Mandatory=$true)] [string]$UserName, [Parameter(Mandatory=$true)] [string]$SharePath, [Parameter(Mandatory=$true)] [string]$USMTFilesPath, [Parameter(Mandatory=$true)] [string]$Domain, [Parameter(Mandatory=$true, HelpMessage='Enter USMT key')] [Security.SecureString]$SecureKey, [pscredential]$Credential ) begin { # 测试源、目标计算机在线状态 Write-Host 'Begin function' Write-Host 'Attempting to ping source computer' if (!(Test-Connection -ComputerName $SourceComputer -Count 2 -ErrorAction Continue)) { Write-Host 'Ping to source computer failed' #Write-Log -Message "Count not ping $SourceComputer" -Level "Warning" -File Break } else { Write-Host 'Success' } Write-Host 'Attempting to ping destination computer' if (!(Test-Connection -ComputerName $DestinationComputer -Count 2 -ErrorAction Continue)) { Write-Host 'Ping to destination computer failed' #Write-Log -Message "Count not ping $DestinationComputer" -Level "Warning" -File Break } else { Write-Host 'Success' } } process { # 复制USMT文件到远程计算机 Try { Write-Host 'Attempting to copy USMT files to source computer' #Write-Log -Message "Attempting to copy USMT files to source computer" -File Copy-Item -Path $USMTFilesPath -Destination "\\$SourceComputer\C$\USMTFiles" -ErrorAction Stop -Recurse -force -con Write-Host 'Attempting to copy USMT files to destination computer' #Write-Log -Message "Attempting to copy USMT files to destination computer" -File Copy-Item -Path $USMTFilesPath -Destination "\\$DestinationComputer\C$\USMTFiles" -ErrorAction Stop -Recurse -force } Catch { Write-Host $_ + ' - Error' #Write-Log -Message '$_' -Level "Error" -File Break } # 启用CredSSP Write-Host 'Invoking CredSSP on source computer & passing credentials' #Write-Log -Message "Enabling CredSSP on source computer" -File Invoke-Command -ComputerName $SourceComputer -Credential $Credential -ScriptBlock {Enable-WSManCredSSP -Role server -Force} Write-Host 'Invoking CredSSP on destination computer & passing credentials' #Write-Log -Message "Enabling CredSSP on destination computer" -File Invoke-Command -ComputerName $DestinationComputer -Credential $Credential -ScriptBlock {Enable-WSManCredSSP -Role server -Force} Write-Host 'Enabling CredSSP on source computer' Enable-WSManCredSSP -Role client -DelegateComputer $SourceComputer -Force Write-Host 'Enabling CredSSP on destination computer' Enable-WSManCredSSP -Role client -DelegateComputer $DestinationComputer -Force # 启动源端扫描 Write-Host 'Starting startscan on source computer & passing credentials' #Write-Log -Message "Starting startscan on source computer" -File Invoke-Command -ComputerName $SourceComputer -Authentication Credssp -Credential $Credential -Scriptblock { $BSTR = [System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($Using:SecureKey) $Key = [System.Runtime.InteropServices.Marshal]::PtrToStringAuto($BSTR) c:\USMTFiles\scanstate.exe "$Using:SharePath\$Using:Username" /i:c:\usmtfiles\printers.xml /i:c:\usmtfiles\custom.xml /i:c:\usmtfiles\migdocs.xml /i:c:\usmtfiles\migapp.xml /v:13 /ui:$Using:Domain\$Using:UserName /c /localonly /encrypt /key:$Key /listfiles:c:\usmtfiles\listfiles.txt /ue:pcadmin /ue:$Using:Domain\* } -ArgumentList {$UserName,$SharePath,$SecureKey,$SourceComputer,$Domain} # 启动目标端加载 Write-Host 'Starting loanscan on destination computer passing credentials' #Write-Log -Message "Starting loadscan on destination computer" -File Invoke-Command -ComputerName $DestinationComputer -Authentication Credssp -Credential $Credential -Scriptblock { $BSTR = [System.Runtime.InteropServices.Marshal]::SecureStringToBSTR($Using:SecureKey) $Key = [System.Runtime.InteropServices.Marshal]::PtrToStringAuto($BSTR) c:\USMTFiles\loadstate.exe "$Using:SharePath\$Using:Username" /i:c:\usmtfiles\printers.xml /i:c:\usmtfiles\custom.xml /i:c:\usmtfiles\migdocs.xml /i:c:\usmtfiles\migapp.xml /v:13 /ui:$Using:Domain\$Using:username /c /decrypt /key:$Key } -ArgumentList {$UserName,$SharePath,$SecureKey,$DestinationComputer,$Domain} # 删除远程计算机上的USMT文件 Write-Host 'Removing USMT files from source computer' #Write-Log -Message "Removing USMT files from source computer" -File Remove-Item \\$SourceComputer\C$\USMTFiles -Force -Recurse Write-Host 'Removing USMT files from destination computer' #Write-Log -Message "Removing USMT files from destination computer" -File Remove-Item \\$DestinationComputer\C$\USMTFiles -Force -Recurse # 禁用远程计算机的CredSSP Write-Host 'Disabling CredSSP on source computer' #Write-Log -Message "Disabling CredSSP on source computer" -File Invoke-Command -ComputerName $SourceComputer -Credential $Credential -ScriptBlock {Disable-WSManCredSSP -Role server } Write-Host 'Disabling CredSSP on destination computer' #Write-Log -Message "Disabling CredSSP on destination computer" -File Invoke-Command -ComputerName $DestinationComputer -Credential $Credential -ScriptBlock {Disable-WSManCredSSP -Role server } Write-Host 'Disabling CredSSP on client' Disable-WSManCredSSP -Role client } }
需求
希望获得该问题的排查方向和解决建议。
内容的提问来源于stack exchange,提问作者Caleb
相关产品推荐
相关产品推荐

