語言

RegistryAccessRule 建構函式

定義

初始化 RegistryAccessRule 類別的新執行個體。

多載

名稱 Description
RegistryAccessRule(IdentityReference, RegistryRights, AccessControlType)

初始化該類別的新實例 RegistryAccessRule ,指定規則適用的使用者或群組、存取權限,以及指定的存取權限是否被允許或拒絕。

RegistryAccessRule(String, RegistryRights, AccessControlType)

初始化該類別的新實例 RegistryAccessRule ,指定規則適用的使用者或群組名稱、存取權限,以及是否允許或拒絕指定的存取權限。

RegistryAccessRule(IdentityReference, RegistryRights, InheritanceFlags, PropagationFlags, AccessControlType)

初始化該類別的新實例 RegistryAccessRule ,指定規則適用的使用者或群組、存取權限、繼承標誌、傳播標誌,以及指定的存取權限是否被允許或拒絕。

RegistryAccessRule(String, RegistryRights, InheritanceFlags, PropagationFlags, AccessControlType)

初始化該類別的新實例 RegistryAccessRule ,指定規則適用的使用者或群組名稱、存取權限、繼承標誌、傳播標誌,以及是否允許或拒絕這些存取權限。

RegistryAccessRule(IdentityReference, RegistryRights, AccessControlType)

來源:
RegistrySecurity.cs

初始化該類別的新實例 RegistryAccessRule ,指定規則適用的使用者或群組、存取權限,以及指定的存取權限是否被允許或拒絕。

public:
 RegistryAccessRule(System::Security::Principal::IdentityReference ^ identity, System::Security::AccessControl::RegistryRights registryRights, System::Security::AccessControl::AccessControlType type);
public RegistryAccessRule(System.Security.Principal.IdentityReference identity, System.Security.AccessControl.RegistryRights registryRights, System.Security.AccessControl.AccessControlType type);
new System.Security.AccessControl.RegistryAccessRule : System.Security.Principal.IdentityReference * System.Security.AccessControl.RegistryRights * System.Security.AccessControl.AccessControlType -> System.Security.AccessControl.RegistryAccessRule
Public Sub New (identity As IdentityReference, registryRights As RegistryRights, type As AccessControlType)

參數

identity
IdentityReference

該規則適用於使用者或群組。 必須是型別SecurityIdentifier,或是可轉換為型別NTAccount的類型SecurityIdentifier。

registryRights
RegistryRights

一個位元組合 RegistryRights 的數值,表示允許或被禁止的權利。

type
AccessControlType

其中一個 AccessControlType 數值是用來表示權利是否被允許或被剝奪。

例外狀況

registryRights 指定一個無效值。

-或-

type 指定一個無效值。

identity 是 null。

-或-

eventRights 為零。

identity既非類型SecurityIdentifier,也非可轉換為類型 NTAccount的類型SecurityIdentifier。

備註

此建構子指定預設傳播與繼承。 也就是說, InheritanceFlags.None 且 PropagationFlags.None。

適用於

RegistryAccessRule(String, RegistryRights, AccessControlType)

來源:
RegistrySecurity.cs

初始化該類別的新實例 RegistryAccessRule ,指定規則適用的使用者或群組名稱、存取權限,以及是否允許或拒絕指定的存取權限。

public:
 RegistryAccessRule(System::String ^ identity, System::Security::AccessControl::RegistryRights registryRights, System::Security::AccessControl::AccessControlType type);
public RegistryAccessRule(string identity, System.Security.AccessControl.RegistryRights registryRights, System.Security.AccessControl.AccessControlType type);
new System.Security.AccessControl.RegistryAccessRule : string * System.Security.AccessControl.RegistryRights * System.Security.AccessControl.AccessControlType -> System.Security.AccessControl.RegistryAccessRule
Public Sub New (identity As String, registryRights As RegistryRights, type As AccessControlType)

參數

identity
String

規則適用的使用者或群組名稱。

registryRights
RegistryRights

一個位元組合 RegistryRights 的數值,表示允許或被禁止的權利。

type
AccessControlType

其中一個 AccessControlType 數值是用來表示權利是否被允許或被剝奪。

例外狀況

registryRights 指定一個無效值。

-或-

type 指定一個無效值。

registryRights 為零。

identity 是 null。

-或-

identity 是一條零長度的字串。

-或-

identity 長度超過512個字元。

範例

以下程式碼範例建立登錄存取規則並將其加入物件 RegistrySecurity ,展示允許與拒絕權利的規則如何保持獨立,而相容的同類規則則被合併。

using System;
using Microsoft.Win32;
using System.Security.AccessControl;
using System.Security.Principal;

public class Example
{
    public static void Main()
    {
        // Create a string representing the current user.
        string user = Environment.UserDomainName + "\\"
            + Environment.UserName;

        // Create a security object that grants no access.
        RegistrySecurity mSec = new RegistrySecurity();

        // Add a rule that grants the current user the 
        // right to read the key.
        RegistryAccessRule rule = new RegistryAccessRule(user, 
            RegistryRights.ReadKey, 
            AccessControlType.Allow);
        mSec.AddAccessRule(rule);

        // Add a rule that denies the current user the 
        // right to change permissions on the Registry.
        rule = new RegistryAccessRule(user, 
            RegistryRights.ChangePermissions, 
            AccessControlType.Deny);
        mSec.AddAccessRule(rule);

        // Display the rules in the security object.
        ShowSecurity(mSec);

        // Add a rule that allows the current user the 
        // right to read permissions on the Registry. This 
        // rule is merged with the existing Allow rule.
        rule = new RegistryAccessRule(user, 
            RegistryRights.WriteKey, 
            AccessControlType.Allow);
        mSec.AddAccessRule(rule);

        ShowSecurity(mSec);
    }

    private static void ShowSecurity(RegistrySecurity security)
    {
        Console.WriteLine("\r\nCurrent access rules:\r\n");

        foreach( RegistryAccessRule ar in 
            security.GetAccessRules(true, true, typeof(NTAccount)) )
        {
            Console.WriteLine("        User: {0}", ar.IdentityReference);
            Console.WriteLine("        Type: {0}", ar.AccessControlType);
            Console.WriteLine("      Rights: {0}", ar.RegistryRights);
            Console.WriteLine();
        }
    }
}

/* This code example produces output similar to following:

Current access rules:

        User: TestDomain\TestUser
        Type: Deny
      Rights: ChangePermissions

        User: TestDomain\TestUser
        Type: Allow
      Rights: ReadKey


Current access rules:

        User: TestDomain\TestUser
        Type: Deny
      Rights: ChangePermissions

        User: TestDomain\TestUser
        Type: Allow
      Rights: SetValue, CreateSubKey, ReadKey
 */
Imports Microsoft.Win32
Imports System.Security.AccessControl
Imports System.Security.Principal

Public Class Example

    Public Shared Sub Main()

        ' Create a string representing the current user.
        Dim user As String = Environment.UserDomainName _ 
            & "\" & Environment.UserName

        ' Create a security object that grants no access.
        Dim mSec As New RegistrySecurity()

        ' Add a rule that grants the current user the 
        ' right to read the key.
        Dim rule As New RegistryAccessRule(user, _
            RegistryRights.ReadKey, _
            AccessControlType.Allow)
        mSec.AddAccessRule(rule)

        ' Add a rule that denies the current user the 
        ' right to change permissions on the Registry.
        rule = New RegistryAccessRule(user, _
            RegistryRights.ChangePermissions, _
            AccessControlType.Deny)
        mSec.AddAccessRule(rule)

        ' Display the rules in the security object.
        ShowSecurity(mSec)

        ' Add a rule that allows the current user the 
        ' right to read permissions on the Registry. This 
        ' rule is merged with the existing Allow rule.
        rule = New RegistryAccessRule(user, _
            RegistryRights.WriteKey, _
            AccessControlType.Allow)
        mSec.AddAccessRule(rule)

        ShowSecurity(mSec)

    End Sub 

    Private Shared Sub ShowSecurity(ByVal security As RegistrySecurity)
        Console.WriteLine(vbCrLf & "Current access rules:" & vbCrLf)

        For Each ar As RegistryAccessRule In _
            security.GetAccessRules(True, True, GetType(NTAccount))

            Console.WriteLine("        User: {0}", ar.IdentityReference)
            Console.WriteLine("        Type: {0}", ar.AccessControlType)
            Console.WriteLine("      Rights: {0}", ar.RegistryRights)
            Console.WriteLine()
        Next

    End Sub
End Class 

'This code example produces output similar to following:
'
'Current access rules:
'
'        User: TestDomain\TestUser
'        Type: Deny
'      Rights: ChangePermissions
'
'        User: TestDomain\TestUser
'        Type: Allow
'      Rights: ReadKey
'
'
'Current access rules:
'
'        User: TestDomain\TestUser
'        Type: Deny
'      Rights: ChangePermissions
'
'        User: TestDomain\TestUser
'        Type: Allow
'      Rights: SetValue, CreateSubKey, ReadKey

備註

此建構子指定預設傳播與繼承。 也就是說, InheritanceFlags.None 且 PropagationFlags.None。

此建構子等同於建立一個 NTAccount 物件,透過傳遞 identity 給 NTAccount.NTAccount(String) 建構者,再將新建立 NTAccount 的物件傳給 RegistryAccessRule(IdentityReference, RegistryRights, AccessControlType) 建構子。

適用於

RegistryAccessRule(IdentityReference, RegistryRights, InheritanceFlags, PropagationFlags, AccessControlType)

來源:
RegistrySecurity.cs

初始化該類別的新實例 RegistryAccessRule ,指定規則適用的使用者或群組、存取權限、繼承標誌、傳播標誌,以及指定的存取權限是否被允許或拒絕。

public:
 RegistryAccessRule(System::Security::Principal::IdentityReference ^ identity, System::Security::AccessControl::RegistryRights registryRights, System::Security::AccessControl::InheritanceFlags inheritanceFlags, System::Security::AccessControl::PropagationFlags propagationFlags, System::Security::AccessControl::AccessControlType type);
public RegistryAccessRule(System.Security.Principal.IdentityReference identity, System.Security.AccessControl.RegistryRights registryRights, System.Security.AccessControl.InheritanceFlags inheritanceFlags, System.Security.AccessControl.PropagationFlags propagationFlags, System.Security.AccessControl.AccessControlType type);
new System.Security.AccessControl.RegistryAccessRule : System.Security.Principal.IdentityReference * System.Security.AccessControl.RegistryRights * System.Security.AccessControl.InheritanceFlags * System.Security.AccessControl.PropagationFlags * System.Security.AccessControl.AccessControlType -> System.Security.AccessControl.RegistryAccessRule
Public Sub New (identity As IdentityReference, registryRights As RegistryRights, inheritanceFlags As InheritanceFlags, propagationFlags As PropagationFlags, type As AccessControlType)

參數

identity
IdentityReference

該規則適用於使用者或群組。 必須是型別SecurityIdentifier,或是可轉換為型別NTAccount的類型SecurityIdentifier。

registryRights
RegistryRights

以位元組合 RegistryRights 的數值,指定允許或禁止的權利。

inheritanceFlags
InheritanceFlags

一個位元組合 InheritanceFlags 的旗標,指定如何從其他物件繼承存取權限。

propagationFlags
PropagationFlags

以位元組合 PropagationFlags 的旗標,指定存取權限如何傳播到其他物件。

type
AccessControlType

AccessControlType其中一個數值是用來指定權利是否被允許或被剝奪的。

例外狀況

registryRights 指定一個無效值。

-或-

type 指定一個無效值。

-或-

inheritanceFlags 指定一個無效值。

-或-

propagationFlags 指定一個無效值。

identity 是 null。

-或-

registryRights 為零。

identity既非類型 SecurityIdentifier,也不是可轉換為類型 NTAccount的類型SecurityIdentifier。

備註

所有登錄檔金鑰都是容器,所以對登錄檔金鑰來說唯一有意義的繼承標誌就是旗標 InheritanceFlags.ContainerInherit 。 若未指定此標誌,則忽略傳播標誌,僅影響直接鍵。 若旗幟存在,規則會如下表所示傳播。 表格假設有一個子鍵 S,子鍵為 CS,子鍵為 GS。 也就是說,孫子子鍵的路徑是 S\CS\GS。

傳播旗幟 S 計算機科學 (if "CS" stands for "Computer Science") GS
None X X X
NoPropagateInherit X X
InheritOnly X X
NoPropagateInherit、InheritOnly X

孫子鍵的模式支配所有由孫子鍵包含的子鍵。

例如,若ContainerInherit標記為 ,inheritanceFlagsInheritOnly且傳播標誌為 ,propagationFlags此規則不適用於直接子鍵,但適用於其所有直接子子鍵及其包含的所有子鍵。

Note

雖然你可以指定 InheritanceFlags.ObjectInherit 的 inheritanceFlags旗標,但這樣做沒有意義。 為了存取控制的目的,子金鑰中的名稱/值對並非獨立物件。 名稱/值對的存取權由子鍵的權限控制。 此外,由於所有子鍵都是容器(即可以包含其他子鍵),因此不會受到 ObjectInherit 旗標的影響。 最後,指定 ObjectInherit 旗幟會不必要地增加規則維護的複雜性,因為它干擾了原本相容規則的組合。

適用於

RegistryAccessRule(String, RegistryRights, InheritanceFlags, PropagationFlags, AccessControlType)

來源:
RegistrySecurity.cs

初始化該類別的新實例 RegistryAccessRule ,指定規則適用的使用者或群組名稱、存取權限、繼承標誌、傳播標誌,以及是否允許或拒絕這些存取權限。

public:
 RegistryAccessRule(System::String ^ identity, System::Security::AccessControl::RegistryRights registryRights, System::Security::AccessControl::InheritanceFlags inheritanceFlags, System::Security::AccessControl::PropagationFlags propagationFlags, System::Security::AccessControl::AccessControlType type);
public RegistryAccessRule(string identity, System.Security.AccessControl.RegistryRights registryRights, System.Security.AccessControl.InheritanceFlags inheritanceFlags, System.Security.AccessControl.PropagationFlags propagationFlags, System.Security.AccessControl.AccessControlType type);
new System.Security.AccessControl.RegistryAccessRule : string * System.Security.AccessControl.RegistryRights * System.Security.AccessControl.InheritanceFlags * System.Security.AccessControl.PropagationFlags * System.Security.AccessControl.AccessControlType -> System.Security.AccessControl.RegistryAccessRule
Public Sub New (identity As String, registryRights As RegistryRights, inheritanceFlags As InheritanceFlags, propagationFlags As PropagationFlags, type As AccessControlType)

參數

identity
String

規則適用的使用者或群組名稱。

registryRights
RegistryRights

一個位元組合 RegistryRights 的數值,表示允許或被禁止的權利。

inheritanceFlags
InheritanceFlags

一個位元組合 InheritanceFlags 的旗標,指定如何從其他物件繼承存取權限。

propagationFlags
PropagationFlags

以位元組合 PropagationFlags 的旗標,指定存取權限如何傳播到其他物件。

type
AccessControlType

AccessControlType其中一個數值是用來指定權利是否被允許或被剝奪的。

例外狀況

registryRights 指定一個無效值。

-或-

type 指定一個無效值。

-或-

inheritanceFlags 指定一個無效值。

-或-

propagationFlags 指定一個無效值。

eventRights 為零。

identity 是 null。

-或-

identity 是一條零長度的字串。

-或-

identity 長度超過512個字元。

範例

以下程式碼範例展示了帶有繼承與傳播的存取規則。 範例中建立一個 RegistrySecurity 物件,然後建立並加入兩條帶有旗幟的 ContainerInherit 規則。 第一條規則沒有傳播標誌,而第二條規則則有 NoPropagateInherit 和 InheritOnly。

程式會在物件中顯示規則 RegistrySecurity ,然後利用 RegistrySecurity 物件建立子鍵。 程式會建立一個子子鍵和一個孫子子鍵,然後顯示每個子鍵的規則。 最後,程式會刪除測試金鑰。


using System;
using System.Security.AccessControl;
using System.Security.Principal;
using System.Security;
using Microsoft.Win32;

public class Example
{
    public static void Main()
    {
        const string TestKey = "TestKey3927";
        RegistryKey cu = Registry.CurrentUser;

        string user = Environment.UserDomainName + 
            "\\" + Environment.UserName;

        // Create a security object that grants no access.
        RegistrySecurity mSec = new RegistrySecurity();

        // Add a rule that grants the current user the right
        // to read and enumerate the name/value pairs in a key, 
        // to read its access and audit rules, to enumerate
        // its subkeys, to create subkeys, and to delete the key. 
        // The rule is inherited by all contained subkeys.
        //
        RegistryAccessRule rule = new RegistryAccessRule(user, 
           RegistryRights.ReadKey | RegistryRights.WriteKey 
               | RegistryRights.Delete, 
           InheritanceFlags.ContainerInherit, 
           PropagationFlags.None, 
           AccessControlType.Allow
        );
        mSec.AddAccessRule(rule);

        // Add a rule that allows the current user the right
        // right to set the name/value pairs in a key. 
        // This rule is inherited by contained subkeys, but
        // propagation flags limit it to immediate child 
        // subkeys.
        rule = new RegistryAccessRule(user, 
            RegistryRights.ChangePermissions, 
            InheritanceFlags.ContainerInherit, 
            PropagationFlags.InheritOnly | 
                PropagationFlags.NoPropagateInherit, 
            AccessControlType.Allow);
        mSec.AddAccessRule(rule);

        // Display the rules in the security object.
        ShowSecurity(mSec);

        // Create the test key using the security object.
        //
        RegistryKey rk = cu.CreateSubKey(TestKey, 
            RegistryKeyPermissionCheck.ReadWriteSubTree, mSec);

        // Create a child subkey and a grandchild subkey, 
        // without security.
        RegistryKey rkChild = rk.CreateSubKey("ChildKey", 
            RegistryKeyPermissionCheck.ReadWriteSubTree);
        RegistryKey rkGrandChild = 
            rkChild.CreateSubKey("GrandChildKey", 
                RegistryKeyPermissionCheck.ReadWriteSubTree);

        Show(rk);
        Show(rkChild);
        Show(rkGrandChild);

        rkGrandChild.Close();
        rkChild.Close();
        rk.Close();

        cu.DeleteSubKeyTree(TestKey);
    }

    private static void Show(RegistryKey rk)
    {
        Console.WriteLine(rk.Name);
        ShowSecurity(rk.GetAccessControl());
    }

    private static void ShowSecurity(RegistrySecurity security)
    {
        Console.WriteLine("\r\nCurrent access rules:\r\n");

        foreach( RegistryAccessRule ar in security.GetAccessRules(true, true, typeof(NTAccount)) )
        {

            Console.WriteLine("        User: {0}", ar.IdentityReference);
            Console.WriteLine("        Type: {0}", ar.AccessControlType);
            Console.WriteLine("      Rights: {0}", ar.RegistryRights);
            Console.WriteLine(" Inheritance: {0}", ar.InheritanceFlags);
            Console.WriteLine(" Propagation: {0}", ar.PropagationFlags);
            Console.WriteLine("   Inherited? {0}", ar.IsInherited);
            Console.WriteLine();
        }
    }
}

/* This code example produces output similar to following:

Current access rules:

        User: TestDomain\TestUser
        Type: Allow
      Rights: SetValue, CreateSubKey, Delete, ReadKey
 Inheritance: ContainerInherit
 Propagation: None
   Inherited? False

        User: TestDomain\TestUser
        Type: Allow
      Rights: ChangePermissions
 Inheritance: ContainerInherit
 Propagation: NoPropagateInherit, InheritOnly
   Inherited? False

HKEY_CURRENT_USER\TestKey3927

Current access rules:

        User: TestDomain\TestUser
        Type: Allow
      Rights: SetValue, CreateSubKey, Delete, ReadKey
 Inheritance: ContainerInherit
 Propagation: None
   Inherited? False

        User: TestDomain\TestUser
        Type: Allow
      Rights: ChangePermissions
 Inheritance: ContainerInherit
 Propagation: NoPropagateInherit, InheritOnly
   Inherited? False

HKEY_CURRENT_USER\TestKey3927\ChildKey

Current access rules:

        User: TestDomain\TestUser
        Type: Allow
      Rights: SetValue, CreateSubKey, Delete, ReadKey
 Inheritance: ContainerInherit
 Propagation: None
   Inherited? True

        User: TestDomain\TestUser
        Type: Allow
      Rights: ChangePermissions
 Inheritance: None
 Propagation: None
   Inherited? True

HKEY_CURRENT_USER\TestKey3927\ChildKey\GrandChildKey

Current access rules:

        User: TestDomain\TestUser
        Type: Allow
      Rights: SetValue, CreateSubKey, Delete, ReadKey
 Inheritance: ContainerInherit
 Propagation: None
   Inherited? True
 */
Option Explicit
Imports System.Security.AccessControl
Imports System.Security.Principal
Imports System.Security
Imports Microsoft.Win32

Public Class Example

    Public Shared Sub Main()

        Const TestKey As String = "TestKey3927"
        Dim cu As RegistryKey = Registry.CurrentUser

        Dim user As String = Environment.UserDomainName _ 
            & "\" & Environment.UserName

        ' Create a security object that grants no access.
        Dim mSec As New RegistrySecurity()

        ' Add a rule that grants the current user the right
        ' to read and enumerate the name/value pairs in a key, 
        ' to read its access and audit rules, to enumerate
        ' its subkeys, to create subkeys, and to delete the key. 
        ' The rule is inherited by all contained subkeys.
        '
        Dim rule As New RegistryAccessRule(user, _
            RegistryRights.ReadKey Or RegistryRights.WriteKey _
                Or RegistryRights.Delete, _
            InheritanceFlags.ContainerInherit, _
            PropagationFlags.None, _
            AccessControlType.Allow)
        mSec.AddAccessRule(rule)

        ' Add a rule that allows the current user the right
        ' right to set the name/value pairs in a key. 
        ' This rule is inherited by contained subkeys, but
        ' propagation flags limit it to immediate child 
        ' subkeys.
        rule = New RegistryAccessRule(user, _
            RegistryRights.ChangePermissions, _
            InheritanceFlags.ContainerInherit, _
            PropagationFlags.InheritOnly Or PropagationFlags.NoPropagateInherit, _
            AccessControlType.Allow)
        mSec.AddAccessRule(rule)

        ' Display the rules in the security object.
        ShowSecurity(mSec)

        ' Create the test key using the security object.
        '
        Dim rk As RegistryKey = cu.CreateSubKey(TestKey, _
            RegistryKeyPermissionCheck.ReadWriteSubTree, _
            mSec)

        ' Create a child subkey and a grandchild subkey, 
        ' without security.
        Dim rkChild As RegistryKey= rk.CreateSubKey("ChildKey", _
            RegistryKeyPermissionCheck.ReadWriteSubTree)
        Dim rkGrandChild As RegistryKey = _
            rkChild.CreateSubKey("GrandChildKey", _
                RegistryKeyPermissionCheck.ReadWriteSubTree)

        Show(rk)
        Show(rkChild)
        Show(rkGrandChild)

        rkGrandChild.Close()
        rkChild.Close()
        rk.Close()

        cu.DeleteSubKeyTree(TestKey)
    End Sub 

    Private Shared Sub Show(ByVal rk As RegistryKey)
        Console.WriteLine(rk.Name)            
        ShowSecurity(rk.GetAccessControl())
    End Sub

    Private Shared Sub ShowSecurity(ByVal security As RegistrySecurity)
        Console.WriteLine(vbCrLf & "Current access rules:" & vbCrLf)

        For Each ar As RegistryAccessRule In _
            security.GetAccessRules(True, True, GetType(NTAccount))

            Console.WriteLine("        User: {0}", ar.IdentityReference)
            Console.WriteLine("        Type: {0}", ar.AccessControlType)
            Console.WriteLine("      Rights: {0}", ar.RegistryRights)
            Console.WriteLine(" Inheritance: {0}", ar.InheritanceFlags)
            Console.WriteLine(" Propagation: {0}", ar.PropagationFlags)
            Console.WriteLine("   Inherited? {0}", ar.IsInherited)
            Console.WriteLine()
        Next

    End Sub
End Class 

'This code example produces output similar to following:
'
'Current access rules:
'
'        User: TestDomain\TestUser
'        Type: Allow
'      Rights: SetValue, CreateSubKey, Delete, ReadKey
' Inheritance: ContainerInherit
' Propagation: None
'   Inherited? False
'
'        User: TestDomain\TestUser
'        Type: Allow
'      Rights: ChangePermissions
' Inheritance: ContainerInherit
' Propagation: NoPropagateInherit, InheritOnly
'   Inherited? False
'
'HKEY_CURRENT_USER\TestKey3927
'
'Current access rules:
'
'        User: TestDomain\TestUser
'        Type: Allow
'      Rights: SetValue, CreateSubKey, Delete, ReadKey
' Inheritance: ContainerInherit
' Propagation: None
'   Inherited? False
'
'        User: TestDomain\TestUser
'        Type: Allow
'      Rights: ChangePermissions
' Inheritance: ContainerInherit
' Propagation: NoPropagateInherit, InheritOnly
'   Inherited? False
'
'HKEY_CURRENT_USER\TestKey3927\ChildKey
'
'Current access rules:
'
'        User: TestDomain\TestUser
'        Type: Allow
'      Rights: SetValue, CreateSubKey, Delete, ReadKey
' Inheritance: ContainerInherit
' Propagation: None
'   Inherited? True
'
'        User: TestDomain\TestUser
'        Type: Allow
'      Rights: ChangePermissions
' Inheritance: None
' Propagation: None
'   Inherited? True
'
'HKEY_CURRENT_USER\TestKey3927\ChildKey\GrandChildKey
'
'Current access rules:
'
'        User: TestDomain\TestUser
'        Type: Allow
'      Rights: SetValue, CreateSubKey, Delete, ReadKey
' Inheritance: ContainerInherit
' Propagation: None
'   Inherited? True

備註

所有登錄檔金鑰都是容器,所以對登錄檔金鑰來說唯一有意義的繼承標誌就是旗標 InheritanceFlags.ContainerInherit 。 若未指定此標誌,則忽略傳播標誌,僅影響直接鍵。 若旗幟存在,規則會如下表所示傳播。 表格假設有一個子鍵 S,子鍵為 CS,子鍵為 GS。 也就是說,孫子子鍵的路徑是 S\CS\GS。

傳播旗幟 S 計算機科學 (if "CS" stands for "Computer Science") GS
None X X X
NoPropagateInherit X X
InheritOnly X X
NoPropagateInherit、InheritOnly X

孫子鍵的模式支配所有由孫子鍵包含的子鍵。

例如,若ContainerInherit標記為 ,inheritanceFlagsInheritOnly且傳播標誌為 ,propagationFlags此規則不適用於直接子鍵,但適用於其所有直接子子鍵及其包含的所有子鍵。

Note

雖然你可以指定 InheritanceFlags.ObjectInherit 的 inheritanceFlags旗標,但這樣做沒有意義。 為了存取控制的目的,子金鑰中的名稱/值對並非獨立物件。 名稱/值對的存取權由子鍵的權限控制。 此外,由於所有子鍵都是容器(即可以包含其他子鍵),因此不會受到 ObjectInherit 旗標的影響。 最後,指定 ObjectInherit 旗幟會不必要地增加規則維護的複雜性,因為它干擾了原本相容規則的組合。

此建構子等同於建立一個 NTAccount 物件,透過傳遞 identity 給 NTAccount.NTAccount(String) 建構者,再將新建立 NTAccount 的物件傳給 RegistryAccessRule(IdentityReference, RegistryRights, InheritanceFlags, PropagationFlags, AccessControlType) 建構子。

適用於