PowerShell创建指定结构文件夹并配置特定子文件夹ACL权限的技术问询
PowerShell创建指定结构文件夹并配置特定子文件夹ACL权限的技术问询
我需要根据地址列表创建一系列文件夹,然后在Active Directory中配置权限。
创建主文件夹和子文件夹的部分我已经搞定了,改编了网上找到的代码:创建主文件夹
$FolderNames = Get-Content -Path "E:\Data\addresses.txt" $DirectoryPath = "E:\Data\buildings" ForEach ($FolderName in $FolderNames) { New-Item -ItemType Directory -Path (Join-Path -Path $DirectoryPath -ChildPath $FolderName) }创建子文件夹
$FolderNames = "E:\Data\addresses.txt" New-item "E:\Data\buildings\$env:foldernames\*" -Name "Patrimonium" -ItemType Directory New-item "E:\Data\buildings\$env:foldernames\*" -Name "Social Services" -ItemType Directory New-item "E:\Data\buildings\$env:foldernames\*" -Name "Administration" -ItemType Directory New-item "E:\Data\buildings\$env:foldernames\*" -Name "Patrimonium\subfolder1" -ItemType Directory New-item "E:\Data\buildings\$env:foldernames\*" -Name "Patrimonium\subfolder2" -ItemType Directory New-item "E:\Data\buildings\$env:foldernames\*" -Name "Social Services\subfolder1" -ItemType Directory New-item "E:\Data\buildings\$env:foldernames\*" -Name "Social Services\subfolder2" -ItemType Directory New-item "E:\Data\buildings\$env:foldernames\*" -Name "Administration\subfolder" -ItemType Directory New-item "E:\Data\buildings\$env:foldernames\*" -Name "Administration\subfolder2" -ItemType Directory现在我想实现:对每个名为
Patrimonium、Social Services、Administration的子文件夹禁用权限继承,并给每个文件夹分配对应的安全组权限;而这些文件夹下面的子文件夹需要继承它们的权限。我完全不知道从哪开始,请问这可行吗?
当然可行!我来帮你一步步实现这个需求:
第一步:修正子文件夹创建脚本
你原来的子文件夹创建代码有个小问题——$env:foldernames是系统环境变量,不是你从文本文件读取的文件夹名,没法遍历每个主文件夹。咱们改成循环处理更靠谱:
# 读取主文件夹列表 $FolderNames = Get-Content -Path "E:\Data\addresses.txt" $RootPath = "E:\Data\buildings" # 定义要创建的子文件夹结构(用哈希表关联父文件夹和它的子文件夹) $SubfolderStructure = @{ "Patrimonium" = @("subfolder1", "subfolder2") "Social Services" = @("subfolder1", "subfolder2") "Administration" = @("subfolder", "subfolder2") } # 循环创建每个主文件夹及其子结构 foreach ($FolderName in $FolderNames) { $MainFolderPath = Join-Path -Path $RootPath -ChildPath $FolderName # 确保主文件夹存在(-Force参数如果已存在不会报错) New-Item -ItemType Directory -Path $MainFolderPath -Force | Out-Null # 创建一级子文件夹(Patrimonium等) foreach ($ParentSubfolder in $SubfolderStructure.Keys) { $ParentSubfolderPath = Join-Path -Path $MainFolderPath -ChildPath $ParentSubfolder New-Item -ItemType Directory -Path $ParentSubfolderPath -Force | Out-Null # 创建一级子文件夹下面的二级子文件夹 foreach ($ChildSubfolder in $SubfolderStructure[$ParentSubfolder]) { $ChildSubfolderPath = Join-Path -Path $ParentSubfolderPath -ChildPath $ChildSubfolder New-Item -ItemType Directory -Path $ChildSubfolderPath -Force | Out-Null } } }
这个脚本会根据你定义的结构,自动给每个主文件夹创建对应的所有子文件夹,逻辑更清晰也更健壮。
第二步:配置ACL权限
接下来就是处理权限的部分,核心步骤是:找到目标文件夹、禁用权限继承、添加对应安全组权限、应用修改后的ACL。
假设你的安全组命名规则是:SG-Building-<主文件夹名>-Patrimonium、SG-Building-<主文件夹名>-SocialServices、SG-Building-<主文件夹名>-Administration(你可以根据实际情况调整规则),脚本可以这么写:
# 定义根路径和安全组命名前缀 $RootPath = "E:\Data\buildings" $SecurityGroupPrefix = "SG-Building-" # 找到所有需要配置的一级子文件夹 $TargetFolders = Get-ChildItem -Path $RootPath -Directory | ForEach-Object { Get-ChildItem -Path $_.FullName -Directory | Where-Object { $_.Name -in "Patrimonium", "Social Services", "Administration" } } # 循环处理每个目标文件夹 foreach ($Folder in $TargetFolders) { # 获取当前文件夹的ACL $Acl = Get-Acl -Path $Folder.FullName # 禁用权限继承:第一个参数是是否保留继承的权限,第二个是是否清除 # 如果想完全重置权限,把$true改成$false $Acl.SetAccessRuleProtection($true, $true) # 根据文件夹名生成对应的安全组名称(这里根据你的实际命名规则调整) $BuildingName = $Folder.Parent.Name switch ($Folder.Name) { "Patrimonium" { $GroupName = "$SecurityGroupPrefix$BuildingName-Patrimonium" } "Social Services" { $GroupName = "$SecurityGroupPrefix$BuildingName-SocialServices" } "Administration" { $GroupName = "$SecurityGroupPrefix$BuildingName-Administration" } } # 创建权限规则:这里给安全组分配修改权限,你可以根据需求调整权限类型 # 权限类型可选:FullControl, Modify, ReadAndExecute, ListDirectory, Read, Write等 $AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule( $GroupName, "Modify", "ContainerInherit,ObjectInherit", "None", "Allow" ) # 添加权限规则到ACL $Acl.AddAccessRule($AccessRule) # 把修改后的ACL应用到文件夹 Set-Acl -Path $Folder.FullName -AclObject $Acl Write-Host "已配置权限:$($Folder.FullName) -> 安全组:$GroupName" }
关键说明:
SetAccessRuleProtection($true, $true):第一个$true表示禁用继承,第二个$true表示保留原来继承的权限;如果想完全清空原有权限,改成SetAccessRuleProtection($true, $false)- 权限类型可以根据你的需求调整,比如给只读权限就用
"ReadAndExecute" - 安全组的命名规则一定要和你的AD实际组名匹配,如果规则不一样,直接修改
switch里的$GroupName生成逻辑就行 - 这些一级子文件夹下面的二级子文件夹会自动继承我们设置的权限,不需要额外配置,完全符合你的需求
备注:内容来源于stack exchange,提问作者Marin
相关产品推荐
相关产品推荐

