如何使用icacls.exe为指定域用户设置文件夹特殊权限?
Hey there! If you need to configure granular, special permissions for a domain user on a specific folder, icacls.exe is your go-to tool. Let's break this down step by step, with concrete examples you can tweak to match your exact needs.
First, Quick Key Concepts to Know
Before diving into commands, let's get clear on the syntax pieces that matter most:
- Domain User Format: Always use
DOMAIN\Username(swap in your actual domain and user account name). - Target Folder: Use the full absolute path (e.g.,
C:\CompanyDocs\MarketingCampaigns). - Permission Flags: These define how permissions inherit and what specific rights are granted. Common ones include:
(OI): Object Inherit – Applies permissions to files created later in the folder/subfolders.(CI): Container Inherit – Applies permissions to subfolders created later.(IO): Inherit Only – Permissions only apply to child objects/folders, not the parent folder itself.(NP): No Propagate Inherit – Child objects won't pass these permissions to their own children.- Right Codes:
R(read),W(write),D(delete),RX(read & execute),F(full control),RC(read permissions),WDAC(modify permissions), etc.
Step 1: Clear Existing Permissions (If Needed)
If you want to start fresh and remove any existing permissions for the domain user on the folder (and all subfolders/files), run this elevated command:
icacls "C:\CompanyDocs\MarketingCampaigns" /remove "DOMAIN\JohnDoe" /T
/T: Recursively applies changes to all subfolders and files under the target.
Step 2: Assign Special Permissions (Examples)
Here are common scenarios – adjust the permission flags and rights to match your specific requirements:
Example 1: Read & Execute on Folder + All Subfolders/Files
Give the user read and execute access to the main folder, every subfolder, and all files (with inheritance):
icacls "C:\CompanyDocs\MarketingCampaigns" /grant "DOMAIN\JohnDoe":(OI)(CI)RX /T
Example 2: Write to Files Only (Not the Parent Folder)
Let the user modify existing files and write new files in the folder, but not make changes to the folder itself (like renaming it):
icacls "C:\CompanyDocs\MarketingCampaigns" /grant "DOMAIN\JohnDoe":(OI)(IO)W /T
(IO)ensures the permission doesn't apply to the parent folder, only its file children.
Example 3: Delete Subfolders & Files (But Not the Main Folder)
Allow the user to delete any subfolders or files inside the target, but prevent them from deleting the main folder itself:
icacls "C:\CompanyDocs\MarketingCampaigns" /grant "DOMAIN\JohnDoe":(CI)(IO)D /T
(CI)(IO)restricts the delete right to subfolders (containers) and files, not the parent.
Example 4: Full Control with Limited Propagation
Give the user full control over the main folder and its immediate children, but stop those children from passing the permission to their own subfolders/files:
icacls "C:\CompanyDocs\MarketingCampaigns" /grant "DOMAIN\JohnDoe":(OI)(CI)(NP)F /T
(NP)blocks permission propagation to grandchild objects.
Step 3: Verify Permissions Are Correct
Always double-check that the permissions applied as expected with this command:
icacls "C:\CompanyDocs\MarketingCampaigns"
This will list all permissions assigned to the folder – you should see your domain user with the exact special permissions you set.
Quick Troubleshooting Tips
- Run as Admin:
icacls.exerequires elevated privileges to modify permissions, so make sure you open Command Prompt as Administrator. - Check Spelling: A typo in the domain or username will break the command – double-check those values.
- Symbolic Links: If working with a symlink, add
/Lto apply permissions to the link itself instead of the target it points to.
内容的提问来源于stack exchange,提问作者Tak

