无gpedit时,如何通过PowerShell修改Allow Remote Shell Access状态?
Got it, since you can't use gpedit.msc and are running into problems importing the GroupPolicy module, working directly with the Windows Registry via PowerShell is your best bet. The "Allow Remote Shell Access" Group Policy setting maps directly to a registry key, so editing this key will give you the same outcome as using the graphical group policy editor.
Here's how to do it:
First, note that the relevant registry path is HKLM:\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service, and the DWORD value AllowRemoteShellAccess controls the setting:
1= Enabled0= Disabled
Enable "Allow Remote Shell Access"
Run this PowerShell script as Administrator:
# Create the registry path if it doesn't exist if (-not (Test-Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service")) { New-Item -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service" -Force | Out-Null } # Set the value to enable remote shell access Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service" -Name "AllowRemoteShellAccess" -Value 1 -Type DWORD -Force # Restart the WinRM service to apply changes immediately Restart-Service WinRM -Force
Disable "Allow Remote Shell Access"
To turn it off, simply change the value to 0 and restart the service:
Set-ItemProperty -Path "HKLM:\SOFTWARE\Policies\Microsoft\Windows\WinRM\Service" -Name "AllowRemoteShellAccess" -Value 0 -Type DWORD -Force Restart-Service WinRM -Force
A quick note on the GroupPolicy module issue:
If you're getting errors when running Import-Module GroupPolicy, it's almost certainly because you're using a Windows Home edition. Home editions don't include the Group Policy tools (including the module and gpedit.msc) by default, which is why the registry workaround is necessary here.
内容的提问来源于stack exchange,提问作者asur

