You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

PowerShell创建指定结构文件夹并配置特定子文件夹ACL权限的技术问询

PowerShell创建指定结构文件夹并配置特定子文件夹ACL权限的技术问询

我需要根据地址列表创建一系列文件夹,然后在Active Directory中配置权限。
创建主文件夹和子文件夹的部分我已经搞定了,改编了网上找到的代码:

创建主文件夹

$FolderNames = Get-Content -Path "E:\Data\addresses.txt"
$DirectoryPath = "E:\Data\buildings"

ForEach ($FolderName in $FolderNames)
{
    New-Item -ItemType Directory -Path (Join-Path -Path $DirectoryPath -ChildPath $FolderName)
}

创建子文件夹

$FolderNames = "E:\Data\addresses.txt"
New-item "E:\Data\buildings\$env:foldernames\*" -Name "Patrimonium" -ItemType Directory
New-item "E:\Data\buildings\$env:foldernames\*" -Name "Social Services" -ItemType Directory
New-item "E:\Data\buildings\$env:foldernames\*" -Name "Administration" -ItemType Directory
New-item "E:\Data\buildings\$env:foldernames\*" -Name "Patrimonium\subfolder1" -ItemType Directory
New-item "E:\Data\buildings\$env:foldernames\*" -Name "Patrimonium\subfolder2" -ItemType Directory
New-item "E:\Data\buildings\$env:foldernames\*" -Name "Social Services\subfolder1" -ItemType Directory
New-item "E:\Data\buildings\$env:foldernames\*" -Name "Social Services\subfolder2" -ItemType Directory
New-item "E:\Data\buildings\$env:foldernames\*" -Name "Administration\subfolder" -ItemType Directory
New-item "E:\Data\buildings\$env:foldernames\*" -Name "Administration\subfolder2" -ItemType Directory

现在我想实现:对每个名为Patrimonium、Social Services、Administration的子文件夹禁用权限继承,并给每个文件夹分配对应的安全组权限;而这些文件夹下面的子文件夹需要继承它们的权限。我完全不知道从哪开始,请问这可行吗?


当然可行!我来帮你一步步实现这个需求:

第一步:修正子文件夹创建脚本

你原来的子文件夹创建代码有个小问题——$env:foldernames是系统环境变量,不是你从文本文件读取的文件夹名,没法遍历每个主文件夹。咱们改成循环处理更靠谱:

# 读取主文件夹列表
$FolderNames = Get-Content -Path "E:\Data\addresses.txt"
$RootPath = "E:\Data\buildings"

# 定义要创建的子文件夹结构(用哈希表关联父文件夹和它的子文件夹)
$SubfolderStructure = @{
    "Patrimonium"        = @("subfolder1", "subfolder2")
    "Social Services"    = @("subfolder1", "subfolder2")
    "Administration"     = @("subfolder", "subfolder2")
}

# 循环创建每个主文件夹及其子结构
foreach ($FolderName in $FolderNames) {
    $MainFolderPath = Join-Path -Path $RootPath -ChildPath $FolderName
    # 确保主文件夹存在(-Force参数如果已存在不会报错)
    New-Item -ItemType Directory -Path $MainFolderPath -Force | Out-Null

    # 创建一级子文件夹(Patrimonium等)
    foreach ($ParentSubfolder in $SubfolderStructure.Keys) {
        $ParentSubfolderPath = Join-Path -Path $MainFolderPath -ChildPath $ParentSubfolder
        New-Item -ItemType Directory -Path $ParentSubfolderPath -Force | Out-Null

        # 创建一级子文件夹下面的二级子文件夹
        foreach ($ChildSubfolder in $SubfolderStructure[$ParentSubfolder]) {
            $ChildSubfolderPath = Join-Path -Path $ParentSubfolderPath -ChildPath $ChildSubfolder
            New-Item -ItemType Directory -Path $ChildSubfolderPath -Force | Out-Null
        }
    }
}

这个脚本会根据你定义的结构,自动给每个主文件夹创建对应的所有子文件夹,逻辑更清晰也更健壮。

第二步:配置ACL权限

接下来就是处理权限的部分,核心步骤是:找到目标文件夹、禁用权限继承、添加对应安全组权限、应用修改后的ACL。

假设你的安全组命名规则是:SG-Building-<主文件夹名>-Patrimonium、SG-Building-<主文件夹名>-SocialServices、SG-Building-<主文件夹名>-Administration(你可以根据实际情况调整规则),脚本可以这么写:

# 定义根路径和安全组命名前缀
$RootPath = "E:\Data\buildings"
$SecurityGroupPrefix = "SG-Building-"

# 找到所有需要配置的一级子文件夹
$TargetFolders = Get-ChildItem -Path $RootPath -Directory | ForEach-Object {
    Get-ChildItem -Path $_.FullName -Directory | Where-Object {
        $_.Name -in "Patrimonium", "Social Services", "Administration"
    }
}

# 循环处理每个目标文件夹
foreach ($Folder in $TargetFolders) {
    # 获取当前文件夹的ACL
    $Acl = Get-Acl -Path $Folder.FullName

    # 禁用权限继承:第一个参数是是否保留继承的权限,第二个是是否清除
    # 如果想完全重置权限,把$true改成$false
    $Acl.SetAccessRuleProtection($true, $true)

    # 根据文件夹名生成对应的安全组名称(这里根据你的实际命名规则调整)
    $BuildingName = $Folder.Parent.Name
    switch ($Folder.Name) {
        "Patrimonium" { $GroupName = "$SecurityGroupPrefix$BuildingName-Patrimonium" }
        "Social Services" { $GroupName = "$SecurityGroupPrefix$BuildingName-SocialServices" }
        "Administration" { $GroupName = "$SecurityGroupPrefix$BuildingName-Administration" }
    }

    # 创建权限规则:这里给安全组分配修改权限,你可以根据需求调整权限类型
    # 权限类型可选:FullControl, Modify, ReadAndExecute, ListDirectory, Read, Write等
    $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule(
        $GroupName,
        "Modify",
        "ContainerInherit,ObjectInherit",
        "None",
        "Allow"
    )

    # 添加权限规则到ACL
    $Acl.AddAccessRule($AccessRule)

    # 把修改后的ACL应用到文件夹
    Set-Acl -Path $Folder.FullName -AclObject $Acl

    Write-Host "已配置权限:$($Folder.FullName) -> 安全组:$GroupName"
}

关键说明:

  • SetAccessRuleProtection($true, $true):第一个$true表示禁用继承,第二个$true表示保留原来继承的权限;如果想完全清空原有权限,改成SetAccessRuleProtection($true, $false)
  • 权限类型可以根据你的需求调整,比如给只读权限就用"ReadAndExecute"
  • 安全组的命名规则一定要和你的AD实际组名匹配,如果规则不一样,直接修改switch里的$GroupName生成逻辑就行
  • 这些一级子文件夹下面的二级子文件夹会自动继承我们设置的权限,不需要额外配置,完全符合你的需求

备注:内容来源于stack exchange,提问作者Marin

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.04.21 09:54:33