Directory.SetAccessControl(String, DirectorySecurity) Directory.SetAccessControl(String, DirectorySecurity) Directory.SetAccessControl(String, DirectorySecurity) Method

Definition

Wendet von einem DirectorySecurity-Objekt beschriebene Einträge von Zugriffssteuerungslisten auf das angegebene Verzeichnis an.Applies access control list (ACL) entries described by a DirectorySecurity object to the specified directory.

public:
 static void SetAccessControl(System::String ^ path, System::Security::AccessControl::DirectorySecurity ^ directorySecurity);
public static void SetAccessControl (string path, System.Security.AccessControl.DirectorySecurity directorySecurity);
static member SetAccessControl : string * System.Security.AccessControl.DirectorySecurity -> unit

Parameter

path
String String String

Ein Verzeichnis, dem Einträge von Zugriffssteuerungslisten hinzugefügt oder aus diesem entfernt werden sollen.A directory to add or remove access control list (ACL) entries from.

directorySecurity
DirectorySecurity DirectorySecurity DirectorySecurity

Ein DirectorySecurity-Objekt, das einen Eintrag in einer Zugriffssteuerungsliste beschreibt, der auf das vom path-Parameter beschriebene Verzeichnis angewendet werden soll.A DirectorySecurity object that describes an ACL entry to apply to the directory described by the path parameter.

Ausnahmen

Der directorySecurity-Parameter ist null.The directorySecurity parameter is null.

Das Verzeichnis wurde nicht gefunden.The directory could not be found.

Der path war ungültig.The path was invalid.

Der aktuelle Prozess hat keinen Zugriff auf das durch path angegebene Verzeichnis.The current process does not have access to the directory specified by path.

- oder - -or- Der aktuelle Prozess verfügt nicht über ausreichende Berechtigungen zum Festlegen des ACL-Eintrags.The current process does not have sufficient privilege to set the ACL entry.

Das aktuelle Betriebssystem ist nicht Windows 2000 oder höher.The current operating system is not Windows 2000 or later.

Beispiele

Im folgenden Beispiel wird die GetAccessControl -Methode SetAccessControl und die-Methode verwendet, um einen Eintrag in einer Zugriffs Steuerungs Liste (ACL) hinzuzufügen und anschließend einen ACL-Eintrag aus einem Verzeichnis zu entfernen.The following example uses the GetAccessControl and the SetAccessControl methods to add an access control list (ACL) entry and then remove an ACL entry from a directory. Sie müssen ein gültiges Benutzer- oder Gruppenkonto angeben, um dieses Beispiel auszuführen.You must supply a valid user or group account to run this example.

using namespace System;
using namespace System::IO;
using namespace System::Security::AccessControl;

// Adds an ACL entry on the specified directory for the
// specified account.
void AddDirectorySecurity(String^ directoryName, String^ account, 
     FileSystemRights rights, AccessControlType controlType)
{
    // Create a new DirectoryInfo object.
    DirectoryInfo^ dInfo = gcnew DirectoryInfo(directoryName);

    // Get a DirectorySecurity object that represents the
    // current security settings.
    DirectorySecurity^ dSecurity = dInfo->GetAccessControl();

    // Add the FileSystemAccessRule to the security settings.
    dSecurity->AddAccessRule( gcnew FileSystemAccessRule(account,
        rights, controlType));

    // Set the new access settings.
    dInfo->SetAccessControl(dSecurity);
}

// Removes an ACL entry on the specified directory for the
// specified account.
void RemoveDirectorySecurity(String^ directoryName, String^ account,
     FileSystemRights rights, AccessControlType controlType)
{
    // Create a new DirectoryInfo object.
    DirectoryInfo^ dInfo = gcnew DirectoryInfo(directoryName);

    // Get a DirectorySecurity object that represents the
    // current security settings.
    DirectorySecurity^ dSecurity = dInfo->GetAccessControl();

    // Add the FileSystemAccessRule to the security settings.
    dSecurity->RemoveAccessRule(gcnew FileSystemAccessRule(account,
        rights, controlType));

    // Set the new access settings.
    dInfo->SetAccessControl(dSecurity);
}    

int main()
{
    String^ directoryName = "TestDirectory";
    String^ accountName = "MYDOMAIN\\MyAccount";
    if (!Directory::Exists(directoryName))
    {
        Console::WriteLine("The directory {0} could not be found.", 
            directoryName);
        return 0;
    }
    try
    {
        Console::WriteLine("Adding access control entry for {0}",
            directoryName);

        // Add the access control entry to the directory.
        AddDirectorySecurity(directoryName, accountName,
            FileSystemRights::ReadData, AccessControlType::Allow);

        Console::WriteLine("Removing access control entry from {0}",
            directoryName);

        // Remove the access control entry from the directory.
        RemoveDirectorySecurity(directoryName, accountName, 
            FileSystemRights::ReadData, AccessControlType::Allow);

        Console::WriteLine("Done.");
    }
    catch (UnauthorizedAccessException^)
    {
        Console::WriteLine("You are not authorised to carry" +
            " out this procedure.");
    }
    catch (System::Security::Principal::
        IdentityNotMappedException^)
    {
        Console::WriteLine("The account {0} could not be found.", accountName);
    }
}

using System;
using System.IO;
using System.Security.AccessControl;

namespace FileSystemExample
{
    class DirectoryExample
    {
        public static void Main()
        {
            try
            {
                string DirectoryName = "TestDirectory";

                Console.WriteLine("Adding access control entry for " + DirectoryName);

                // Add the access control entry to the directory.
                AddDirectorySecurity(DirectoryName, @"MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Removing access control entry from " + DirectoryName);

                // Remove the access control entry from the directory.
                RemoveDirectorySecurity(DirectoryName, @"MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Done.");
            }
            catch (Exception e)
            {
                Console.WriteLine(e);
            }

            Console.ReadLine();
        }

        // Adds an ACL entry on the specified directory for the specified account.
        public static void AddDirectorySecurity(string FileName, string Account, FileSystemRights Rights, AccessControlType ControlType)
        {
            // Create a new DirectoryInfo object.
            DirectoryInfo dInfo = new DirectoryInfo(FileName);

            // Get a DirectorySecurity object that represents the 
            // current security settings.
            DirectorySecurity dSecurity = dInfo.GetAccessControl();

            // Add the FileSystemAccessRule to the security settings. 
            dSecurity.AddAccessRule(new FileSystemAccessRule(Account,
                                                            Rights,
                                                            ControlType));

            // Set the new access settings.
            dInfo.SetAccessControl(dSecurity);

        }

        // Removes an ACL entry on the specified directory for the specified account.
        public static void RemoveDirectorySecurity(string FileName, string Account, FileSystemRights Rights, AccessControlType ControlType)
        {
            // Create a new DirectoryInfo object.
            DirectoryInfo dInfo = new DirectoryInfo(FileName);

            // Get a DirectorySecurity object that represents the 
            // current security settings.
            DirectorySecurity dSecurity = dInfo.GetAccessControl();

            // Add the FileSystemAccessRule to the security settings. 
            dSecurity.RemoveAccessRule(new FileSystemAccessRule(Account,
                                                            Rights,
                                                            ControlType));

            // Set the new access settings.
            dInfo.SetAccessControl(dSecurity);

        }
    }
}

Imports System.IO
Imports System.Security.AccessControl



Module DirectoryExample

    Sub Main()
        Try
            Dim DirectoryName As String = "TestDirectory"

            Console.WriteLine("Adding access control entry for " + DirectoryName)

            ' Add the access control entry to the directory.
            AddDirectorySecurity(DirectoryName, "MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Removing access control entry from " + DirectoryName)

            ' Remove the access control entry from the directory.
            RemoveDirectorySecurity(DirectoryName, "MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Done.")
        Catch e As Exception
            Console.WriteLine(e)
        End Try

        Console.ReadLine()

    End Sub


    ' Adds an ACL entry on the specified directory for the specified account.
    Sub AddDirectorySecurity(ByVal FileName As String, ByVal Account As String, ByVal Rights As FileSystemRights, ByVal ControlType As AccessControlType)
        ' Create a new DirectoryInfoobject.
        Dim dInfo As New DirectoryInfo(FileName)

        ' Get a DirectorySecurity object that represents the 
        ' current security settings.
        Dim dSecurity As DirectorySecurity = dInfo.GetAccessControl()

        ' Add the FileSystemAccessRule to the security settings. 
        dSecurity.AddAccessRule(New FileSystemAccessRule(Account, Rights, ControlType))

        ' Set the new access settings.
        dInfo.SetAccessControl(dSecurity)

    End Sub


    ' Removes an ACL entry on the specified directory for the specified account.
    Sub RemoveDirectorySecurity(ByVal FileName As String, ByVal Account As String, ByVal Rights As FileSystemRights, ByVal ControlType As AccessControlType)
        ' Create a new DirectoryInfo object.
        Dim dInfo As New DirectoryInfo(FileName)

        ' Get a DirectorySecurity object that represents the 
        ' current security settings.
        Dim dSecurity As DirectorySecurity = dInfo.GetAccessControl()

        ' Add the FileSystemAccessRule to the security settings. 
        dSecurity.RemoveAccessRule(New FileSystemAccessRule(Account, Rights, ControlType))

        ' Set the new access settings.
        dInfo.SetAccessControl(dSecurity)

    End Sub
End Module

Hinweise

Die SetAccessControl -Methode wendet Einträge in der Zugriffs Steuerungs Liste (ACL) auf eine Datei an, die die nicht geerbte ACL-Liste darstellt.The SetAccessControl method applies access control list (ACL) entries to a file that represents the noninherited ACL list.

Achtung

Die für den directorySecurity -Parameter angegebene ACL ersetzt die vorhandene ACL für das Verzeichnis.The ACL specified for the directorySecurity parameter replaces the existing ACL for the directory. Um Berechtigungen für einen neuen Benutzer hinzuzufügen, verwenden GetAccessControl Sie die-Methode, um die vorhandene ACL abzurufen und zu ändern.To add permissions for a new user, use the GetAccessControl method to obtain the existing ACL and modify it.

Eine ACL beschreibt Personen und/oder Gruppen, die über Rechte für bestimmte Aktionen in der angegebenen Datei oder dem angegebenen Verzeichnis verfügen oder diese nicht besitzen.An ACL describes individuals and/or groups who have, or do not have, rights to specific actions on the given file or directory. Weitere Informationen finden Sie unter Gewusst wie: Hinzufügen oder Entfernen von Zugriffssteuerungslisten-Einträgen.For more information, see How to: Add or Remove Access Control List Entries.

Die SetAccessControl -Methode speichert DirectorySecurity nur Objekte, die nach der Objekt Erstellung geändert wurden.The SetAccessControl method persists only DirectorySecurity objects that have been modified after object creation. Wenn ein DirectorySecurity -Objekt nicht geändert wurde, wird es nicht in einer Datei persistent gespeichert.If a DirectorySecurity object has not been modified, it will not be persisted to a file. Aus diesem Grund ist es nicht möglich, ein DirectorySecurity -Objekt aus einer Datei abzurufen und das gleiche Objekt erneut auf eine andere Datei anzuwenden.Therefore, it is not possible to retrieve a DirectorySecurity object from one file and reapply the same object to another file.

So kopieren Sie ACL-Informationen aus einer Datei in eine andere:To copy ACL information from one file to another:

  1. Verwenden Sie GetAccessControl die-Methode, DirectorySecurity um das-Objekt aus der Quelldatei abzurufen.Use the GetAccessControl method to retrieve the DirectorySecurity object from the source file.

  2. Erstellen Sie ein DirectorySecurity neues-Objekt für die Zieldatei.Create a new DirectorySecurity object for the destination file.

  3. Verwenden Sie GetSecurityDescriptorBinaryForm die GetSecurityDescriptorSddlForm -Methode oder die DirectorySecurity -Methode des-Quell Objekts, um die ACL-Informationen abzurufen.Use the GetSecurityDescriptorBinaryForm or GetSecurityDescriptorSddlForm method of the source DirectorySecurity object to retrieve the ACL information.

  4. Verwenden Sie SetSecurityDescriptorBinaryForm die SetSecurityDescriptorSddlForm -oder-Methode, um die in Schritt 3 abgerufenen DirectorySecurity Informationen in das Zielobjekt zu kopieren.Use the SetSecurityDescriptorBinaryForm or SetSecurityDescriptorSddlForm method to copy the information retrieved in step 3 to the destination DirectorySecurity object.

  5. Legen Sie das DirectorySecurity Zielobjekt mithilfe der SetAccessControl -Methode auf die Zieldatei fest.Set the destination DirectorySecurity object to the destination file using the SetAccessControl method.

In NTFS-Umgebungen ReadAttributes werden ReadExtendedAttributes und dem Benutzer gewährt, wenn der Benutzer über ListDirectory Rechte für den übergeordneten Ordner verfügt.In NTFS environments, ReadAttributes and ReadExtendedAttributes are granted to the user if the user has ListDirectory rights on the parent folder. ReadAttributes Um und ReadExtendedAttributesabzulehnen, verweigern ListDirectory Sie das übergeordnete Verzeichnis.To deny ReadAttributes and ReadExtendedAttributes, deny ListDirectory on the parent directory.

Sicherheit

FileIOPermission
, um die Zugriffs Steuerungs Liste (ACL) für ein Verzeichnis aufzuzählen.for permission to enumerate access control list (ACL) for a directory. Zugehörige Enumerationen NoAccess :,ViewAssociated enumerations: NoAccess , View Sicherheitsaktion: Lange.Security action: Demand.

Gilt für:

Siehe auch