使用icacls为AD命名的200个用户文件夹分配指定共享权限
Batch Configure Folder Permissions with icacls for AD User-Named Folders
Got it, let's walk through how to automate this permission setup using icacls and PowerShell — it's straightforward once you map the folder names to AD users and groups. Here's a step-by-step solution tailored to your scenario:
Prerequisites First
Before diving in, make sure you have:
- Local admin rights on the machine where the folders are stored (you need this to modify NTFS permissions)
- Confirmed that folder names exactly match AD user account names (e.g., if the folder is
John Doe, that should be the user's display name or samAccountName in AD — double-check this to avoid permission errors) - The AD groups
IT Security GroupandCopieralready created and populated
PowerShell Script for Batch Permission Setup
This script loops through every user folder in your base path, resets permissions (optional), and applies the required access rights to the matching user and two groups:
# Set your base folder path where user folders are stored $basePath = "C:\project\Users" # Grab all subfolders in the base path $userFolders = Get-ChildItem -Path $basePath -Directory # Loop through each folder to configure permissions foreach ($folder in $userFolders) { $userName = $folder.Name $fullFolderPath = $folder.FullName # Optional: Reset permissions to default inherited settings (cleans up existing explicit permissions) icacls "$fullFolderPath" /reset /T /Q # Grant full control to the matching AD user (adjust permission code if needed) icacls "$fullFolderPath" /grant "$userName:(OI)(CI)F" /Q # Grant Read/Write access to IT Security Group icacls "$fullFolderPath" /grant "IT Security Group:(OI)(CI)RW" /Q # Grant Read-Only access to Copier group icacls "$fullFolderPath" /grant "Copier:(OI)(CI)R" /Q # Print progress to console Write-Host "Successfully configured permissions for: $fullFolderPath" }
What Each icacls Flag Does
Let's break down the key parts so you can adjust them to your needs:
/reset: Wipes explicit permissions and reverts to inherited ones (remove this line if you want to keep existing permissions alongside new ones)/T: Applies the permission change recursively to all subfolders and files inside the user's folder/Q: Runs in quiet mode (suppresses success messages — remove it if you want to see every permission change logged)(OI)(CI): These two flags ensure permissions apply to:- Object Inherit: All files created in the folder
- Container Inherit: All subfolders created in the folder
- Permission codes (adjust based on your actual needs):
F: Full ControlRW: Read & WriteR: Read OnlyM: ModifyRX: Read & Execute
Critical Things to Check
- Folder Name vs AD User: If your folders use display names (like
John Doe) but AD uses samAccountNames (likejdoe), you'll need to add a step to map display names to samAccountNames. For example, use theActiveDirectorymodule'sGet-ADUsercmdlet to look up the correct user account name from the folder name. - Test on a Single Folder: Always run the icacls commands manually on one test folder first to verify permissions are applied correctly before running the full batch script.
- Inheritance Settings: If you skip the
/resetstep, make sure existing inherited permissions don't conflict with the new explicit permissions you're adding.
内容的提问来源于stack exchange,提问作者hotdog_spaceship
相关产品推荐
相关产品推荐

