如何:新增或移除存取控制清單項目 (僅限 .NET Framework)

若要在檔案或目錄加入或移除存取控制清單 (ACL) 項目,請從檔案或目錄取得 FileSecurityDirectorySecurity 物件。 修改物件,然後將其套回至檔案或目錄。

在檔案加入或移除 ACL 項目

  1. 呼叫 File.GetAccessControl 方法來取得 FileSecurity 物件,其中包含檔案的目前 ACL 項目。

  2. FileSecurity 步驟 1 中傳回的物件加入或移除 ACL 項目。

  3. 若要套用變更,請將 FileSecurity 物件傳遞至 File.SetAccessControl 方法。

在目錄加入或移除 ACL 項目

  1. 呼叫 Directory.GetAccessControl 方法來取得 DirectorySecurity 物件,其中包含目錄的目前 ACL 項目。

  2. DirectorySecurity 步驟 1 中傳回的物件加入或移除 ACL 項目。

  3. 若要套用變更,請將 DirectorySecurity 物件傳遞至 Directory.SetAccessControl 方法。


您必須使用有效的使用者或群組帳戶,才能執行這個範例。 此範例使用 File 物件。 對 FileInfoDirectoryDirectoryInfo 類別使用相同程序。

using System;
using System.IO;
using System.Security.AccessControl;

namespace FileSystemExample
    class FileExample
        public static void Main()
                string fileName = "test.xml";

                Console.WriteLine("Adding access control entry for "
                    + fileName);

                // Add the access control entry to the file.
                AddFileSecurity(fileName, @"DomainName\AccountName",
                    FileSystemRights.ReadData, AccessControlType.Allow);

                Console.WriteLine("Removing access control entry from "
                    + fileName);

                // Remove the access control entry from the file.
                RemoveFileSecurity(fileName, @"DomainName\AccountName",
                    FileSystemRights.ReadData, AccessControlType.Allow);

            catch (Exception e)

        // Adds an ACL entry on the specified file for the specified account.
        public static void AddFileSecurity(string fileName, string account,
            FileSystemRights rights, AccessControlType controlType)

            // Get a FileSecurity object that represents the
            // current security settings.
            FileSecurity fSecurity = File.GetAccessControl(fileName);

            // Add the FileSystemAccessRule to the security settings.
            fSecurity.AddAccessRule(new FileSystemAccessRule(account,
                rights, controlType));

            // Set the new access settings.
            File.SetAccessControl(fileName, fSecurity);

        // Removes an ACL entry on the specified file for the specified account.
        public static void RemoveFileSecurity(string fileName, string account,
            FileSystemRights rights, AccessControlType controlType)

            // Get a FileSecurity object that represents the
            // current security settings.
            FileSecurity fSecurity = File.GetAccessControl(fileName);

            // Remove the FileSystemAccessRule from the security settings.
            fSecurity.RemoveAccessRule(new FileSystemAccessRule(account,
                rights, controlType));

            // Set the new access settings.
            File.SetAccessControl(fileName, fSecurity);
Imports System.IO
Imports System.Security.AccessControl

Module FileExample

    Sub Main()
            Dim fileName As String = "test.xml"

            Console.WriteLine("Adding access control entry for " & fileName)

            ' Add the access control entry to the file.
            AddFileSecurity(fileName, "DomainName\AccountName", _
                FileSystemRights.ReadData, AccessControlType.Allow)

            Console.WriteLine("Removing access control entry from " & fileName)

            ' Remove the access control entry from the file.
            RemoveFileSecurity(fileName, "DomainName\AccountName", _
                FileSystemRights.ReadData, AccessControlType.Allow)

        Catch e As Exception
        End Try

    End Sub

    ' Adds an ACL entry on the specified file for the specified account.
    Sub AddFileSecurity(ByVal fileName As String, ByVal account As String, _
        ByVal rights As FileSystemRights, ByVal controlType As AccessControlType)

        ' Get a FileSecurity object that represents the 
        ' current security settings.
        Dim fSecurity As FileSecurity = File.GetAccessControl(fileName)

        ' Add the FileSystemAccessRule to the security settings. 
        Dim accessRule As FileSystemAccessRule = _
            New FileSystemAccessRule(account, rights, controlType)


        ' Set the new access settings.
        File.SetAccessControl(fileName, fSecurity)

    End Sub

    ' Removes an ACL entry on the specified file for the specified account.
    Sub RemoveFileSecurity(ByVal fileName As String, ByVal account As String, _
        ByVal rights As FileSystemRights, ByVal controlType As AccessControlType)

        ' Get a FileSecurity object that represents the 
        ' current security settings.
        Dim fSecurity As FileSecurity = File.GetAccessControl(fileName)

        ' Remove the FileSystemAccessRule from the security settings. 
        fSecurity.RemoveAccessRule(New FileSystemAccessRule(account, _
            rights, controlType))

        ' Set the new access settings.
        File.SetAccessControl(fileName, fSecurity)

    End Sub
End Module