You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何读取Configuration Manager Remote Control权限弹窗文本或通过VBS终止SCCM会话

读取SCCM远程控制请求弹窗文本的实现方法

VBS原生的AppActivate仅能判断目标窗口是否存在,无法直接读取窗口内文本,你可以通过调用Win32 API实现该需求:

  • 核心逻辑是通过user32.dll的EnumWindows枚举顶层窗口,匹配SCCM权限请求弹窗的窗口标题/类名后,调用GetWindowTextW读取窗口文本内容。VBS无法直接调用系统API,你可以通过内嵌HTA对象的方式实现API调用,无需额外安装第三方组件,示例代码如下:
Set objHTA = CreateObject("htmlfile")
Set objWindow = objHTA.parentWindow
' 注册所需Win32 API
objWindow.execScript "Declare Function GetWindowTextW Lib ""user32"" (ByVal hWnd As Long, ByVal lpString As String, ByVal cch As Long) As Long", "VBScript"
objWindow.execScript "Declare Function EnumWindows Lib ""user32"" (ByVal lpEnumFunc As Long, ByVal lParam As Long) As Long", "VBScript"

' 枚举窗口匹配SCCM权限请求弹窗
Function EnumWindowsProc(hwnd, lParam)
    Dim title: title = Space(255)
    Call objWindow.GetWindowTextW(hwnd, title, Len(title))
    title = Replace(title, Chr(0), "")
    ' 可根据实际SCCM版本调整匹配关键词
    If InStr(title, "Configuration Manager Remote Control") > 0 Or InStr(title, "配置管理器远程控制") > 0 Then
        WScript.Echo "弹窗内容:" & title
        ' 如需读取弹窗内子控件文本,可额外调用GetDlgItem+GetWindowTextW实现
        EnumWindowsProc = 0
    Else
        EnumWindowsProc = 1
    End If
End Function

如果你的SCCM版本更新频繁,弹窗结构变化概率较高,该方案的兼容性会受影响,更推荐你使用备选的先放行再校验的方案。

VBS安全终止SCCM远程会话的实现方法

你的备选方案完全可行,SessionState注册表路径是SCCM客户端官方存储会话信息的位置,校验逻辑稳定可靠,终止会话可选择以下两种安全方案:

方案1:重启SCCM远程控制服务(兼容性最高)

直接停止并重启CmRcService服务即可切断当前会话,且服务重启后不影响后续正常的远程控制请求,不会残留异常状态,示例代码如下:

Const HKEY_LOCAL_MACHINE = &H80000002
strRegPath = "SOFTWARE\Microsoft\SMS\Client\Client Components\Remote Control\SessionState"
strValueName = "Viewer Name"
' 自定义白名单列表
arrWhiteList = Array("admin01", "admin02", "it_support01")

' 读取注册表值,64位系统运行32位WScript时需额外处理注册表重定向
Set objReg = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\default:StdRegProv")
objReg.GetStringValue HKEY_LOCAL_MACHINE, strRegPath, strValueName, strViewerName

' 白名单校验
blnAllowed = False
For Each name In arrWhiteList
    If LCase(Trim(name)) = LCase(Trim(strViewerName)) Then
        blnAllowed = True
        Exit For
    End If
Next

' 不在白名单则终止会话
If Not blnAllowed Then
    Set objWMIService = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\cimv2")
    Set colServices = objWMIService.ExecQuery("Select * from Win32_Service Where Name='CmRcService'")
    For Each objService In colServices
        objService.StopService()
        WScript.Sleep 2000
        objService.StartService()
    Next
End If

方案2:调用SCCM内置WMI方法终止会话(更优雅)

你可以通过ROOT\CCM\ClientSDK命名空间下的远程会话类直接结束当前会话,不需要重启服务,示例代码如下:

Set objWMIService = GetObject("winmgmts:{impersonationLevel=impersonate}!\\.\root\ccm\clientsdk")
Set colSessions = objWMIService.ExecQuery("Select * from CCM_RemoteTools_Session")
For Each objSession In colSessions
    If LCase(Trim(objSession.ViewerName)) = LCase(Trim(strViewerName)) Then
        objSession.Terminate()
    End If
Next

内容的提问来源于stack exchange,提问作者green onion

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.10.02 08:57:04