Windows 10非管理员账户下U盘被禁用,如何用C#实现U盘访问?
Hey there! Let's work through this problem together—dealing with restricted USB access as a non-admin in Windows 10 is definitely tricky, especially when you can't elevate your app to admin rights. Here are some practical, C#-focused approaches I've used or seen work in similar scenarios:
Windows lets you access disks through their device paths (like \\.\E:) even if file-level permissions are blocked, as long as the user hasn't been explicitly denied access to the device itself. This bypasses standard file system permission checks by interacting directly with the disk's raw sectors.
Here's a code example using P/Invoke to read a raw sector from the U盘:
using System; using System.Runtime.InteropServices; public class RawUsbAccess { [DllImport("kernel32.dll", SetLastError = true, CharSet = CharSet.Unicode)] private static extern IntPtr CreateFile( string lpFileName, uint dwDesiredAccess, uint dwShareMode, IntPtr lpSecurityAttributes, uint dwCreationDisposition, uint dwFlagsAndAttributes, IntPtr hTemplateFile); [DllImport("kernel32.dll", SetLastError = true)] private static extern bool ReadFile( IntPtr hFile, byte[] lpBuffer, uint nNumberOfBytesToRead, out uint lpNumberOfBytesRead, IntPtr lpOverlapped); [DllImport("kernel32.dll", SetLastError = true)] private static extern bool CloseHandle(IntPtr hObject); private const uint GENERIC_READ = 0x80000000; private const uint FILE_SHARE_READ = 0x00000001; private const uint OPEN_EXISTING = 3; public static byte[] ReadSector(string driveLetter, uint sectorSize = 512) { string devicePath = $"\\\\.\\{driveLetter.ToUpper().TrimEnd(':')}:"; IntPtr hDrive = CreateFile( devicePath, GENERIC_READ, FILE_SHARE_READ, IntPtr.Zero, OPEN_EXISTING, 0, IntPtr.Zero); if (hDrive == IntPtr.Zero || hDrive == (IntPtr)(-1)) { throw new System.ComponentModel.Win32Exception(Marshal.GetLastWin32Error()); } byte[] buffer = new byte[sectorSize]; if (!ReadFile(hDrive, buffer, sectorSize, out uint bytesRead, IntPtr.Zero)) { CloseHandle(hDrive); throw new System.ComponentModel.Win32Exception(Marshal.GetLastWin32Error()); } CloseHandle(hDrive); return buffer; } }
Note: This gives you raw sector access, so you'll need to parse the file system (like FAT32/NTFS) yourself if you want to read individual files—it's not as straightforward as using File.ReadAllText, but it bypasses file-level permission blocks.
If you only need basic details about the U盘 (like capacity, file system, or serial number), WMI might work even when file system access is blocked. WMI uses a separate permission model, so your non-admin account may have access to these classes.
Here's a quick example to get removable disk info:
using System.Management; public class UsbWmiInfo { public static void GetRemovableDisks() { var searcher = new ManagementObjectSearcher("SELECT * FROM Win32_LogicalDisk WHERE DriveType=2"); foreach (ManagementObject disk in searcher.Get()) { Console.WriteLine($"Drive Letter: {disk["DeviceID"]}"); Console.WriteLine($"Volume Name: {disk["VolumeName"]}"); Console.WriteLine($"Total Size: {disk["Size"]} bytes"); Console.WriteLine($"Free Space: {disk["FreeSpace"]} bytes"); Console.WriteLine("---"); } } }
If the U盘 is formatted with FAT32, Windows doesn't enforce NTFS-style permissions as strictly. Sometimes, even if group policy blocks access, you can still interact with the file system using basic file I/O calls. Try a quick test:
try { string usbPath = @"E:\"; // Replace with your U盘 letter string[] files = Directory.GetFiles(usbPath); foreach (var file in files) { Console.WriteLine(file); } } catch (UnauthorizedAccessException ex) { Console.WriteLine($"Permission denied: {ex.Message}"); }
If this throws an error, the group policy restriction is probably enforced at a higher level, but it's worth checking since FAT32 has looser security.
In some cases, creating a shadow copy of the U盘 can bypass access restrictions, as the snapshot might inherit different permissions. This requires using P/Invoke to interact with VSS APIs, which is more advanced. Note that the VSS service needs to be running, and your user account may need permissions to create snapshots.
A Quick Caution
All these methods depend on your organization's specific security policies. If the restriction is enforced via a strict group policy (like "Prevent access to drives from My Computer"), some approaches might still fail. Whenever possible, it's best to coordinate with your IT team to adjust permissions for your use case.
内容的提问来源于stack exchange,提问作者Holmsee

