Directory.SetAccessControl(String, DirectorySecurity) Directory.SetAccessControl(String, DirectorySecurity) Directory.SetAccessControl(String, DirectorySecurity) Method

定義

DirectorySecurity オブジェクトが示すアクセス制御リスト (ACL: Access Control List) エントリを、指定したディレクトリに適用します。Applies access control list (ACL) entries described by a DirectorySecurity object to the specified directory.

public:
 static void SetAccessControl(System::String ^ path, System::Security::AccessControl::DirectorySecurity ^ directorySecurity);
public static void SetAccessControl (string path, System.Security.AccessControl.DirectorySecurity directorySecurity);
static member SetAccessControl : string * System.Security.AccessControl.DirectorySecurity -> unit

パラメーター

path
String String String

アクセス制御リスト (ACL) エントリの追加先または削除元となるディレクトリ。A directory to add or remove access control list (ACL) entries from.

directorySecurity
DirectorySecurity DirectorySecurity DirectorySecurity

path パラメーターが示すディレクトリに適用する ACL エントリを表す DirectorySecurity オブジェクト。A DirectorySecurity object that describes an ACL entry to apply to the directory described by the path parameter.

例外

directorySecurity パラメーターが null です。The directorySecurity parameter is null.

ディレクトリが見つかりません。The directory could not be found.

path が正しくありません。The path was invalid.

現在のプロセスには、path で指定されたディレクトリへのアクセス権がありません。The current process does not have access to the directory specified by path.

または-or- 現在のプロセスには、ACL エントリを設定するための十分な特権がありません。The current process does not have sufficient privilege to set the ACL entry.

現在のオペレーティング システムは Windows 2000 以降ではありません。The current operating system is not Windows 2000 or later.

次の例では、GetAccessControlSetAccessControlアクセスを追加するメソッドが制御リスト (ACL) エントリと、ディレクトリから ACL エントリを削除します。The following example uses the GetAccessControl and the SetAccessControl methods to add an access control list (ACL) entry and then remove an ACL entry from a directory. この例を実行するには、有効なユーザーまたはグループ アカウントを指定する必要があります。You must supply a valid user or group account to run this example.

using namespace System;
using namespace System::IO;
using namespace System::Security::AccessControl;

// Adds an ACL entry on the specified directory for the
// specified account.
void AddDirectorySecurity(String^ directoryName, String^ account, 
     FileSystemRights rights, AccessControlType controlType)
{
    // Create a new DirectoryInfo object.
    DirectoryInfo^ dInfo = gcnew DirectoryInfo(directoryName);

    // Get a DirectorySecurity object that represents the
    // current security settings.
    DirectorySecurity^ dSecurity = dInfo->GetAccessControl();

    // Add the FileSystemAccessRule to the security settings.
    dSecurity->AddAccessRule( gcnew FileSystemAccessRule(account,
        rights, controlType));

    // Set the new access settings.
    dInfo->SetAccessControl(dSecurity);
}

// Removes an ACL entry on the specified directory for the
// specified account.
void RemoveDirectorySecurity(String^ directoryName, String^ account,
     FileSystemRights rights, AccessControlType controlType)
{
    // Create a new DirectoryInfo object.
    DirectoryInfo^ dInfo = gcnew DirectoryInfo(directoryName);

    // Get a DirectorySecurity object that represents the
    // current security settings.
    DirectorySecurity^ dSecurity = dInfo->GetAccessControl();

    // Add the FileSystemAccessRule to the security settings.
    dSecurity->RemoveAccessRule(gcnew FileSystemAccessRule(account,
        rights, controlType));

    // Set the new access settings.
    dInfo->SetAccessControl(dSecurity);
}    

int main()
{
    String^ directoryName = "TestDirectory";
    String^ accountName = "MYDOMAIN\\MyAccount";
    if (!Directory::Exists(directoryName))
    {
        Console::WriteLine("The directory {0} could not be found.", 
            directoryName);
        return 0;
    }
    try
    {
        Console::WriteLine("Adding access control entry for {0}",
            directoryName);

        // Add the access control entry to the directory.
        AddDirectorySecurity(directoryName, accountName,
            FileSystemRights::ReadData, AccessControlType::Allow);

        Console::WriteLine("Removing access control entry from {0}",
            directoryName);

        // Remove the access control entry from the directory.
        RemoveDirectorySecurity(directoryName, accountName, 
            FileSystemRights::ReadData, AccessControlType::Allow);

        Console::WriteLine("Done.");
    }
    catch (UnauthorizedAccessException^)
    {
        Console::WriteLine("You are not authorised to carry" +
            " out this procedure.");
    }
    catch (System::Security::Principal::
        IdentityNotMappedException^)
    {
        Console::WriteLine("The account {0} could not be found.", accountName);
    }
}

using System;
using System.IO;
using System.Security.AccessControl;

namespace FileSystemExample
{
    class DirectoryExample
    {
        public static void Main()
        {
            try
            {
                string DirectoryName = "TestDirectory";

                Console.WriteLine("Adding access control entry for " + DirectoryName);

                // Add the access control entry to the directory.
                AddDirectorySecurity(DirectoryName, @"MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Removing access control entry from " + DirectoryName);

                // Remove the access control entry from the directory.
                RemoveDirectorySecurity(DirectoryName, @"MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Done.");
            }
            catch (Exception e)
            {
                Console.WriteLine(e);
            }

            Console.ReadLine();
        }

        // Adds an ACL entry on the specified directory for the specified account.
        public static void AddDirectorySecurity(string FileName, string Account, FileSystemRights Rights, AccessControlType ControlType)
        {
            // Create a new DirectoryInfo object.
            DirectoryInfo dInfo = new DirectoryInfo(FileName);

            // Get a DirectorySecurity object that represents the 
            // current security settings.
            DirectorySecurity dSecurity = dInfo.GetAccessControl();

            // Add the FileSystemAccessRule to the security settings. 
            dSecurity.AddAccessRule(new FileSystemAccessRule(Account,
                                                            Rights,
                                                            ControlType));

            // Set the new access settings.
            dInfo.SetAccessControl(dSecurity);

        }

        // Removes an ACL entry on the specified directory for the specified account.
        public static void RemoveDirectorySecurity(string FileName, string Account, FileSystemRights Rights, AccessControlType ControlType)
        {
            // Create a new DirectoryInfo object.
            DirectoryInfo dInfo = new DirectoryInfo(FileName);

            // Get a DirectorySecurity object that represents the 
            // current security settings.
            DirectorySecurity dSecurity = dInfo.GetAccessControl();

            // Add the FileSystemAccessRule to the security settings. 
            dSecurity.RemoveAccessRule(new FileSystemAccessRule(Account,
                                                            Rights,
                                                            ControlType));

            // Set the new access settings.
            dInfo.SetAccessControl(dSecurity);

        }
    }
}

Imports System
Imports System.IO
Imports System.Security.AccessControl



Module DirectoryExample

    Sub Main()
        Try
            Dim DirectoryName As String = "TestDirectory"

            Console.WriteLine("Adding access control entry for " + DirectoryName)

            ' Add the access control entry to the directory.
            AddDirectorySecurity(DirectoryName, "MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Removing access control entry from " + DirectoryName)

            ' Remove the access control entry from the directory.
            RemoveDirectorySecurity(DirectoryName, "MYDOMAIN\MyAccount", FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Done.")
        Catch e As Exception
            Console.WriteLine(e)
        End Try

        Console.ReadLine()

    End Sub


    ' Adds an ACL entry on the specified directory for the specified account.
    Sub AddDirectorySecurity(ByVal FileName As String, ByVal Account As String, ByVal Rights As FileSystemRights, ByVal ControlType As AccessControlType)
        ' Create a new DirectoryInfoobject.
        Dim dInfo As New DirectoryInfo(FileName)

        ' Get a DirectorySecurity object that represents the 
        ' current security settings.
        Dim dSecurity As DirectorySecurity = dInfo.GetAccessControl()

        ' Add the FileSystemAccessRule to the security settings. 
        dSecurity.AddAccessRule(New FileSystemAccessRule(Account, Rights, ControlType))

        ' Set the new access settings.
        dInfo.SetAccessControl(dSecurity)

    End Sub


    ' Removes an ACL entry on the specified directory for the specified account.
    Sub RemoveDirectorySecurity(ByVal FileName As String, ByVal Account As String, ByVal Rights As FileSystemRights, ByVal ControlType As AccessControlType)
        ' Create a new DirectoryInfo object.
        Dim dInfo As New DirectoryInfo(FileName)

        ' Get a DirectorySecurity object that represents the 
        ' current security settings.
        Dim dSecurity As DirectorySecurity = dInfo.GetAccessControl()

        ' Add the FileSystemAccessRule to the security settings. 
        dSecurity.RemoveAccessRule(New FileSystemAccessRule(Account, Rights, ControlType))

        ' Set the new access settings.
        dInfo.SetAccessControl(dSecurity)

    End Sub
End Module

注釈

SetAccessControlメソッドが継承されない ACL リストを表すファイルへのアクセス制御リスト (ACL) エントリを適用します。The SetAccessControl method applies access control list (ACL) entries to a file that represents the noninherited ACL list.

注意事項

ACL に指定された、directorySecurityパラメーターは、ディレクトリの既存の ACL を置き換えます。The ACL specified for the directorySecurity parameter replaces the existing ACL for the directory. 新しいユーザーのアクセス許可を追加するには、使用、GetAccessControlメソッドを既存の ACL を取得し、それを変更します。To add permissions for a new user, use the GetAccessControl method to obtain the existing ACL and modify it.

ACL には、個人やグループがある、または権限がない、特定のファイルまたはディレクトリの特定のアクションをユーザーがについて説明します。An ACL describes individuals and/or groups who have, or do not have, rights to specific actions on the given file or directory. 詳細については、「方法: アクセス制御リスト エントリを追加または削除する」を参照してください。For more information, see How to: Add or Remove Access Control List Entries.

SetAccessControlメソッドにのみが解決しないDirectorySecurityオブジェクトの作成後に変更されたオブジェクト。The SetAccessControl method persists only DirectorySecurity objects that have been modified after object creation. 場合、DirectorySecurityオブジェクトが変更されていない、ファイルに保存されません。If a DirectorySecurity object has not been modified, it will not be persisted to a file. そのため、取得することはできません、 DirectorySecurity 1 つのファイルからオブジェクトし、別のファイルに同じオブジェクトを再適用します。Therefore, it is not possible to retrieve a DirectorySecurity object from one file and reapply the same object to another file.

ACL の情報を別の 1 つのファイルにコピーします。 するTo copy ACL information from one file to another:

  1. 使用して、GetAccessControlを取得するメソッド、DirectorySecurityソース ファイルからのオブジェクト。Use the GetAccessControl method to retrieve the DirectorySecurity object from the source file.

  2. 新規作成DirectorySecurity先のファイル オブジェクト。Create a new DirectorySecurity object for the destination file.

  3. 使用して、GetSecurityDescriptorBinaryFormまたはGetSecurityDescriptorSddlFormメソッドのソースのDirectorySecurityACL の情報を取得するオブジェクト。Use the GetSecurityDescriptorBinaryForm or GetSecurityDescriptorSddlForm method of the source DirectorySecurity object to retrieve the ACL information.

  4. 使用して、SetSecurityDescriptorBinaryFormまたはSetSecurityDescriptorSddlForm、情報をコピーするメソッドは、先には、手順 3. で取得DirectorySecurityオブジェクト。Use the SetSecurityDescriptorBinaryForm or SetSecurityDescriptorSddlForm method to copy the information retrieved in step 3 to the destination DirectorySecurity object.

  5. 設定先DirectorySecurity変換先のファイルを使用するオブジェクト、SetAccessControlメソッド。Set the destination DirectorySecurity object to the destination file using the SetAccessControl method.

NTFS の環境でReadAttributesReadExtendedAttributes場合は、ユーザーがある、ユーザーに付与ListDirectory親フォルダーに対する権限。In NTFS environments, ReadAttributes and ReadExtendedAttributes are granted to the user if the user has ListDirectory rights on the parent folder. 拒否するReadAttributesReadExtendedAttributes、拒否ListDirectory親ディレクトリにします。To deny ReadAttributes and ReadExtendedAttributes, deny ListDirectory on the parent directory.

セキュリティ

FileIOPermission
ディレクトリのアクセス制御リスト (ACL) を列挙する権限。for permission to enumerate access control list (ACL) for a directory. 列挙体に関連付けられている: NoAccessViewAssociated enumerations: NoAccess , View セキュリティ アクション。必要に応じて。Security action: Demand.

適用対象

こちらもご覧ください