【问题标题】:Powershell : Get-ACL and get permissions for specific user on a remote folderPowershell:获取ACL并获取远程文件夹上特定用户的权限
【发布时间】:2017-08-26 00:22:48
【问题描述】:
Get-ACL \\machine_name\folder1 | Format-List *

为我提供以下内容,包括用户的访问权限(在 AccessToString 中)

**AccessToString          : NT AUTHORITY\Authenticated Users Allow  AppendData
                          NT AUTHORITY\Authenticated Users Allow  -536805376
                          NT AUTHORITY\SYSTEM Allow  FullControl
                          BUILTIN\Administrators Allow  FullControl
                          BUILTIN\Users Allow  ReadAndExecute, Synchronize**
AuditToString           :
AccessRightType         : System.Security.AccessControl.FileSystemRights
AccessRuleType          : System.Security.AccessControl.FileSystemAccessRule
AuditRuleType           : System.Security.AccessControl.FileSystemAuditRule
AreAccessRulesProtected : True
AreAuditRulesProtected  : False
AreAccessRulesCanonical : True
AreAuditRulesCanonical  : True

但下面给了我空白:

Get-ACL \\machine_name\folder1| Format-List * | select AccessToString

最后,我想在 AccessToString 中获取特定给定用户的条目,例如仅获得“BUILTIN\Administrators. 将不胜感激。

【问题讨论】:

  • 删除| Format-List *
  • 只提供部分数据: -------------- "NT AUTHORITY\Authenticated Users Allow AppendData..." 另外 - 我如何获得特定用户的权限?
  • Get-ACL . |Select -Expand AccessToString
  • 非常感谢。那 -expand 确实给出了列表。如何在该列表中搜索特定用户以获取该用户的所有访问权限?

标签: powershell


【解决方案1】:

首先,绝不能将任何 Format-* cmdlet 的输出通过管道传输到其他 cmdlet。为什么?因为 Format-* cmdlet 的输出不是您在管道上使用的对象。它们是用于在屏幕上形成信息的专用对象。

如果我们使用命令Get-Acl c:\ | Format-List * | Get-Member,我们将看到这五种 .NET 类型中有五个对象从 Format-List cmdlet 传递到 Get-Member cmdlet:

  • Microsoft.PowerShell.Commands.Internal.Format.FormatStartData
  • Microsoft.PowerShell.Commands.Internal.Format.GroupStartData
  • Microsoft.PowerShell.Commands.Internal.Format.FormatEntryData
  • Microsoft.PowerShell.Commands.Internal.Format.GroupEndData
  • Microsoft.PowerShell.Commands.Internal.Format.FormatEndData

这些对象的存在只是为了让 Format-List 能够很好地显示。此外,Get-Member 不会显示这些对象中的任何一个具有任何 AccessToString 属性。

AccessToString 属性只是一个代表 ACL 的文本块。这不适合过滤,而是应该做的是深入Access 属性并过滤其IdentityReference 属性上的访问控制条目(ACE)。

你会有更好的运气:

Get-Acl c:\ | Select-Object -ExpandProperty Access | 
  Where-Object identityreference -eq "BUILTIN\Administrators"

【讨论】:

    猜你喜欢
    • 2019-09-07
    • 1970-01-01
    • 2016-04-14
    • 1970-01-01
    • 2023-04-02
    • 1970-01-01
    • 2019-09-08
    • 2016-11-02
    • 2016-12-01
    相关资源
    最近更新 更多