You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

修改Net Share共享权限:移除Everyone、添加Authenticated Users并实现继承

PowerShell 共享权限配置脚本优化方案

实现的需求

  • 扩展共享排除规则,覆盖「Remote Admin」「Default share」「Remote IPC」「Printer Drivers」类共享
  • 新增NTFS权限配置逻辑,解决子文件夹无法继承父项权限的问题

修改后完整脚本

$ScriptBlock = {
    "Executing on {0}" -f $env:COMPUTERNAME
    # 扩展排除列表:管理员共享、IPC共享、盘符默认共享、打印驱动共享
    $ExclusionList = 'ADMIN\$','IPC\$','[A-Z]\$','PRINT\$' -join '|'
    # 仅筛选文件类型共享,自动排除IPC、打印机、设备类共享
    $Shares = Get-SmbShare | 
        Where-Object {$_.ShareType -eq 0} |
        Where-Object -Property Name -notmatch $ExclusionList | 
        Where-Object -Property Path -notmatch '^\w:\\$' 
    "Analyzing these shares...."
    $Shares
    foreach ($Share in $Shares) {    
        $Everyone = Get-SmbShareAccess $Share.Name | Where-Object -Property AccountName -eq 'Everyone'
        if ($Everyone) {  
            # 修改SMB共享权限
            Revoke-SmbShareAccess $Share.Name -AccountName 'Everyone' -Force
            Grant-SmbShareAccess $Share.Name -AccountName 'Authenticated Users' -AccessRight FullControl -Force
            "Share {0} has been updated." -f $Share.Name 

            # 配置对应本地路径的NTFS权限,启用继承规则
            if (Test-Path -Path $Share.Path) {
                $acl = Get-Acl -Path $Share.Path
                # 检查是否已存在符合要求的权限,避免重复添加
                $existingRule = $acl.Access | Where-Object {
                    $_.IdentityReference.Value -eq 'Authenticated Users' -and
                    $_.FileSystemRights -eq 'FullControl' -and
                    $_.InheritanceFlags -eq 'ContainerInherit, ObjectInherit' -and
                    $_.PropagationFlags -eq 'None' -and
                    $_.AccessControlType -eq 'Allow'
                }
                if (-not $existingRule) {
                    $accessRule = New-Object System.Security.AccessControl.FileSystemAccessRule(
                        'Authenticated Users',
                        'FullControl',
                        'ContainerInherit, ObjectInherit',
                        'None',
                        'Allow'
                    )
                    $acl.AddAccessRule($accessRule)
                    Set-Acl -Path $Share.Path -AclObject $acl
                    "NTFS permissions for path $($Share.Path) updated, subfolders will inherit the rule automatically."
                }
            }
        }
    }
    "Complete"
}
    
$ComputerList = Get-Content "C:\users\a-lchandrakanthredd\Desktop\Test\Servers.txt"
        
Invoke-Command -ComputerName $ComputerList -ScriptBlock $ScriptBlock

关键修改说明

  1. 共享排除规则优化
    • 排除列表新增盘符默认共享(如C$/D$)、打印驱动共享PRINT$,覆盖要求的所有排除场景
    • 新增ShareType过滤,仅处理文件类型共享,自动排除IPC、打印机、设备类无效共享
  2. 权限继承问题修复
    • 新增NTFS权限配置逻辑,SMB共享权限修改完成后同步修改对应本地路径的NTFS权限
    • 权限规则启用ContainerInherit和ObjectInherit继承标记,确保子文件、子文件夹自动继承父项权限
    • 新增权限存在性校验,避免重复添加规则导致的权限冗余

内容的提问来源于stack exchange,提问作者nikon D3400

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.09.26 08:36:01