You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

使用icacls为AD命名的200个用户文件夹分配指定共享权限

Batch Configure Folder Permissions with icacls for AD User-Named Folders

Got it, let's walk through how to automate this permission setup using icacls and PowerShell — it's straightforward once you map the folder names to AD users and groups. Here's a step-by-step solution tailored to your scenario:

Prerequisites First

Before diving in, make sure you have:

  • Local admin rights on the machine where the folders are stored (you need this to modify NTFS permissions)
  • Confirmed that folder names exactly match AD user account names (e.g., if the folder is John Doe, that should be the user's display name or samAccountName in AD — double-check this to avoid permission errors)
  • The AD groups IT Security Group and Copier already created and populated

PowerShell Script for Batch Permission Setup

This script loops through every user folder in your base path, resets permissions (optional), and applies the required access rights to the matching user and two groups:

# Set your base folder path where user folders are stored
$basePath = "C:\project\Users"

# Grab all subfolders in the base path
$userFolders = Get-ChildItem -Path $basePath -Directory

# Loop through each folder to configure permissions
foreach ($folder in $userFolders) {
    $userName = $folder.Name
    $fullFolderPath = $folder.FullName

    # Optional: Reset permissions to default inherited settings (cleans up existing explicit permissions)
    icacls "$fullFolderPath" /reset /T /Q

    # Grant full control to the matching AD user (adjust permission code if needed)
    icacls "$fullFolderPath" /grant "$userName:(OI)(CI)F" /Q

    # Grant Read/Write access to IT Security Group
    icacls "$fullFolderPath" /grant "IT Security Group:(OI)(CI)RW" /Q

    # Grant Read-Only access to Copier group
    icacls "$fullFolderPath" /grant "Copier:(OI)(CI)R" /Q

    # Print progress to console
    Write-Host "Successfully configured permissions for: $fullFolderPath"
}

What Each icacls Flag Does

Let's break down the key parts so you can adjust them to your needs:

  • /reset: Wipes explicit permissions and reverts to inherited ones (remove this line if you want to keep existing permissions alongside new ones)
  • /T: Applies the permission change recursively to all subfolders and files inside the user's folder
  • /Q: Runs in quiet mode (suppresses success messages — remove it if you want to see every permission change logged)
  • (OI)(CI): These two flags ensure permissions apply to:
    • Object Inherit: All files created in the folder
    • Container Inherit: All subfolders created in the folder
  • Permission codes (adjust based on your actual needs):
    • F: Full Control
    • RW: Read & Write
    • R: Read Only
    • M: Modify
    • RX: Read & Execute

Critical Things to Check

  • Folder Name vs AD User: If your folders use display names (like John Doe) but AD uses samAccountNames (like jdoe), you'll need to add a step to map display names to samAccountNames. For example, use the ActiveDirectory module's Get-ADUser cmdlet to look up the correct user account name from the folder name.
  • Test on a Single Folder: Always run the icacls commands manually on one test folder first to verify permissions are applied correctly before running the full batch script.
  • Inheritance Settings: If you skip the /reset step, make sure existing inherited permissions don't conflict with the new explicit permissions you're adding.

内容的提问来源于stack exchange,提问作者hotdog_spaceship

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 08:20:02