WindowsPrincipal.IsInRole 方法
定義
重要
部分資訊涉及發行前產品,在發行之前可能會有大幅修改。 Microsoft 對此處提供的資訊,不做任何明確或隱含的瑕疵擔保。
判斷目前的主體是否屬於指定的 Windows 使用者群組。
多載
| 名稱 | Description |
|---|---|
| IsInRole(Int32) |
判斷目前主體是否屬於指定相對識別碼(RID)的 Windows 使用者群組。 |
| IsInRole(SecurityIdentifier) |
判斷目前的主體是否屬於具有指定安全識別碼(SID)的 Windows 使用者群組。 |
| IsInRole(WindowsBuiltInRole) |
判斷目前主體是否屬於指定的WindowsBuiltInRole 的Windows使用者群組。 |
| IsInRole(String) |
判斷目前的主體是否屬於指定名稱的 Windows 使用者群組。 |
備註
此方法有四種過載方式。 為了效能考量,強烈建議使用 IsInRole(SecurityIdentifier) 過載。
IsInRole(Int32)
判斷目前主體是否屬於指定相對識別碼(RID)的 Windows 使用者群組。
public:
virtual bool IsInRole(int rid);
public virtual bool IsInRole(int rid);
override this.IsInRole : int -> bool
abstract member IsInRole : int -> bool
override this.IsInRole : int -> bool
Public Overridable Function IsInRole (rid As Integer) As Boolean
參數
- rid
- Int32
這是 Windows 使用者群組的 RID,用來檢查主體的成員狀態。
傳回
true 若現任負責人是指定Windows使用者群組成員,即特定角色;否則為 false。
範例
以下程式碼範例展示了這些 IsInRole 方法的使用方法。 列 WindowsBuiltInRole 舉作為識別內建角色的 RID 來源。 RID用來決定現任校長的角色。
public:
static void DemonstrateWindowsBuiltInRoleEnum()
{
AppDomain^ myDomain = Thread::GetDomain();
myDomain->SetPrincipalPolicy( PrincipalPolicy::WindowsPrincipal );
WindowsPrincipal^ myPrincipal = dynamic_cast<WindowsPrincipal^>(Thread::CurrentPrincipal);
Console::WriteLine( "{0} belongs to: ", myPrincipal->Identity->Name );
Array^ wbirFields = Enum::GetValues( WindowsBuiltInRole::typeid );
for each ( Object^ roleName in wbirFields )
{
try
{
Console::WriteLine( "{0}? {1}.", roleName,
myPrincipal->IsInRole( *dynamic_cast<WindowsBuiltInRole^>(roleName) ) );
}
catch ( Exception^ )
{
Console::WriteLine( "{0}: Could not obtain role for this RID.",
roleName );
}
}
}
using System;
using System.Threading;
using System.Security.Permissions;
using System.Security.Principal;
class SecurityPrincipalDemo
{
public static void DemonstrateWindowsBuiltInRoleEnum()
{
AppDomain myDomain = Thread.GetDomain();
myDomain.SetPrincipalPolicy(PrincipalPolicy.WindowsPrincipal);
WindowsPrincipal myPrincipal = (WindowsPrincipal)Thread.CurrentPrincipal;
Console.WriteLine("{0} belongs to: ", myPrincipal.Identity.Name.ToString());
Array wbirFields = Enum.GetValues(typeof(WindowsBuiltInRole));
foreach (object roleName in wbirFields)
{
try
{
// Cast the role name to a RID represented by the WindowsBuildInRole value.
Console.WriteLine("{0}? {1}.", roleName,
myPrincipal.IsInRole((WindowsBuiltInRole)roleName));
Console.WriteLine("The RID for this role is: " + ((int)roleName).ToString());
}
catch (Exception)
{
Console.WriteLine("{0}: Could not obtain role for this RID.",
roleName);
}
}
// Get the role using the string value of the role.
Console.WriteLine("{0}? {1}.", "Administrators",
myPrincipal.IsInRole("BUILTIN\\" + "Administrators"));
Console.WriteLine("{0}? {1}.", "Users",
myPrincipal.IsInRole("BUILTIN\\" + "Users"));
// Get the role using the WindowsBuiltInRole enumeration value.
Console.WriteLine("{0}? {1}.", WindowsBuiltInRole.Administrator,
myPrincipal.IsInRole(WindowsBuiltInRole.Administrator));
// Get the role using the WellKnownSidType.
SecurityIdentifier sid = new SecurityIdentifier(WellKnownSidType.BuiltinAdministratorsSid, null);
Console.WriteLine("WellKnownSidType BuiltinAdministratorsSid {0}? {1}.", sid.Value, myPrincipal.IsInRole(sid));
}
public static void Main()
{
DemonstrateWindowsBuiltInRoleEnum();
}
}
Imports System.Threading
Imports System.Security.Permissions
Imports System.Security.Principal
Class SecurityPrincipalDemo
Public Shared Sub DemonstrateWindowsBuiltInRoleEnum()
Dim myDomain As AppDomain = Thread.GetDomain()
myDomain.SetPrincipalPolicy(PrincipalPolicy.WindowsPrincipal)
Dim myPrincipal As WindowsPrincipal = CType(Thread.CurrentPrincipal, WindowsPrincipal)
Console.WriteLine("{0} belongs to: ", myPrincipal.Identity.Name.ToString())
Dim wbirFields As Array = [Enum].GetValues(GetType(WindowsBuiltInRole))
Dim roleName As Object
For Each roleName In wbirFields
Try
' Cast the role name to a RID represented by the WindowsBuildInRole value.
Console.WriteLine("{0}? {1}.", roleName, myPrincipal.IsInRole(CType(roleName, WindowsBuiltInRole)))
Console.WriteLine("The RID for this role is: " + Fix(roleName).ToString())
Catch
Console.WriteLine("{0}: Could not obtain role for this RID.", roleName)
End Try
Next roleName
' Get the role using the string value of the role.
Console.WriteLine("{0}? {1}.", "Administrators", myPrincipal.IsInRole("BUILTIN\" + "Administrators"))
Console.WriteLine("{0}? {1}.", "Users", myPrincipal.IsInRole("BUILTIN\" + "Users"))
' Get the role using the WindowsBuiltInRole enumeration value.
Console.WriteLine("{0}? {1}.", WindowsBuiltInRole.Administrator, myPrincipal.IsInRole(WindowsBuiltInRole.Administrator))
' Get the role using the WellKnownSidType.
Dim sid As New SecurityIdentifier(WellKnownSidType.BuiltinAdministratorsSid, Nothing)
Console.WriteLine("WellKnownSidType BuiltinAdministratorsSid {0}? {1}.", sid.Value, myPrincipal.IsInRole(sid))
End Sub
Public Shared Sub Main()
DemonstrateWindowsBuiltInRoleEnum()
End Sub
End Class
備註
在測試新建立的角色資訊(如新使用者或新群組)時,務必登出再登入,以強制角色資訊在網域內傳播。 如果不這麼做,測試可能會 IsInRole 回到 false。
出於效能考量,建議以 IsInRole(SecurityIdentifier) 過載作為決定使用者角色的首選過載值。
Note
在 Windows Vista 中,用戶帳戶控制 (UAC) 會決定用戶的許可權。 如果你是內建管理員群組的成員,你會被分配兩個執行時存取權杖:一個標準使用者存取權杖和一個管理員存取權杖。 根據預設,您處於標準使用者角色。 當你嘗試執行需要管理員權限的任務時,可以透過同意對話框動態提升你的角色。 執行該 IsInRole 方法的程式碼不會顯示同意對話框。 如果你處於標準使用者角色,即使你在內建管理員群組,程式碼也會回傳 false。 你可以在執行程式碼前,透過右鍵點擊應用程式圖示並表示你想以管理員身份執行,提升你的權限。
相對識別碼(RID)是 Windows 使用者群組安全識別碼(SID)的組成部分,並被支援以防止跨平台在地化問題。 許多使用者帳號、本地群組和全域群組的預設 RID 值在所有 Windows 版本中都是固定的。
例如,BUILTIN\Administrators 角色的 RID 是 0x220。 若現任負責人是管理員,使用0x220作為方法的輸入參數 IsInRole ,則會 true 被回傳。
以下表格列出預設的RID值。
| 內建使用者 | 擺脫 |
|---|---|
| 網域名稱\管理員 | 0x1F4 |
| 網域名稱\訪客 | 0x1F5 |
| 內建的全域群組 | 擺脫 |
|---|---|
| 網域名稱\網域管理員 | 0x200 |
| 網域名稱\網域使用者 | 0x201 |
| 網域名稱\網域訪客 | 0x202 |
| 內建的地方群組 | 擺脫 |
|---|---|
| BUILTIN\Administrators | 0x220 |
| 內建\使用者 | 0x221 |
| 內建\賓客 | 0x222 |
| BUILTIN\Account Operators | 0x224 |
| BUILTIN\Server 運算元 | 0x225 |
| 內建\列印運算元 | 0x226 |
| 內建\備用運算元 | 0x227 |
| 內建\複製器 | 0x228 |
適用於
IsInRole(SecurityIdentifier)
判斷目前的主體是否屬於具有指定安全識別碼(SID)的 Windows 使用者群組。
public:
virtual bool IsInRole(System::Security::Principal::SecurityIdentifier ^ sid);
public virtual bool IsInRole(System.Security.Principal.SecurityIdentifier sid);
[System.Runtime.InteropServices.ComVisible(false)]
public virtual bool IsInRole(System.Security.Principal.SecurityIdentifier sid);
override this.IsInRole : System.Security.Principal.SecurityIdentifier -> bool
[<System.Runtime.InteropServices.ComVisible(false)>]
abstract member IsInRole : System.Security.Principal.SecurityIdentifier -> bool
override this.IsInRole : System.Security.Principal.SecurityIdentifier -> bool
[<System.Runtime.InteropServices.ComVisible(false)>]
override this.IsInRole : System.Security.Principal.SecurityIdentifier -> bool
Public Overridable Function IsInRole (sid As SecurityIdentifier) As Boolean
參數
一個 SecurityIdentifier,唯一識別Windows使用者群組。
傳回
true 若現任負責人是指定Windows使用者群組成員;否則為 false。
- 屬性
例外狀況
sid 是 null。
Windows 回傳了 Win32 錯誤。
範例
以下程式碼範例示範了此 WindowsPrincipal.IsInRole(SecurityIdentifier) 方法的使用。 BuiltinAdministratorsSid列舉值用來判斷現任負責人是否為管理人員。 完整程式碼範例請參見方法。WindowsPrincipal.IsInRole(Int32)
// Get the role using the WellKnownSidType.
SecurityIdentifier sid = new SecurityIdentifier(WellKnownSidType.BuiltinAdministratorsSid, null);
Console.WriteLine("WellKnownSidType BuiltinAdministratorsSid {0}? {1}.", sid.Value, myPrincipal.IsInRole(sid));
' Get the role using the WellKnownSidType.
Dim sid As New SecurityIdentifier(WellKnownSidType.BuiltinAdministratorsSid, Nothing)
Console.WriteLine("WellKnownSidType BuiltinAdministratorsSid {0}? {1}.", sid.Value, myPrincipal.IsInRole(sid))
End Sub
備註
SecurityIdentifier 唯一識別 Windows 上的使用者或群組。 在測試新建立的角色資訊(如新使用者或新群組)時,務必登出再登入,以強制角色資訊在網域內傳播。 如果不這麼做,測試可能會 IsInRole 回到 false。
Note
在 Windows Vista 中,用戶帳戶控制 (UAC) 會決定用戶的許可權。 如果你是內建管理員群組的成員,你會被分配兩個執行時存取權杖:一個標準使用者存取權杖和一個管理員存取權杖。 根據預設,您處於標準使用者角色。 當你嘗試執行需要管理員權限的任務時,可以透過同意對話框動態提升你的角色。 執行該 IsInRole 方法的程式碼不會顯示同意對話框。 如果你處於標準使用者角色,即使你在內建管理員群組,程式碼也會回傳 false。 你可以在執行程式碼前,透過右鍵點擊應用程式圖示並表示你想以管理員身份執行,提升你的權限。
出於效能考量,這是決定使用者角色的首選超載方式。
適用於
IsInRole(WindowsBuiltInRole)
判斷目前主體是否屬於指定的WindowsBuiltInRole 的Windows使用者群組。
public:
virtual bool IsInRole(System::Security::Principal::WindowsBuiltInRole role);
public virtual bool IsInRole(System.Security.Principal.WindowsBuiltInRole role);
override this.IsInRole : System.Security.Principal.WindowsBuiltInRole -> bool
abstract member IsInRole : System.Security.Principal.WindowsBuiltInRole -> bool
override this.IsInRole : System.Security.Principal.WindowsBuiltInRole -> bool
Public Overridable Function IsInRole (role As WindowsBuiltInRole) As Boolean
參數
- role
- WindowsBuiltInRole
這是其中一項 WindowsBuiltInRole 價值。
傳回
true 若現任負責人是指定Windows使用者群組成員;否則為 false。
例外狀況
role 不是一個有效的 WindowsBuiltInRole 值。
範例
以下範例使用 WindowsBuiltInRole 列舉來判斷當前主體是否為 Administrator。 完整程式碼範例請參見方法。WindowsPrincipal.IsInRole(Int32)
// Get the role using the WindowsBuiltInRole enumeration value.
Console.WriteLine("{0}? {1}.", WindowsBuiltInRole.Administrator,
myPrincipal.IsInRole(WindowsBuiltInRole.Administrator));
' Get the role using the WindowsBuiltInRole enumeration value.
Console.WriteLine("{0}? {1}.", WindowsBuiltInRole.Administrator, myPrincipal.IsInRole(WindowsBuiltInRole.Administrator))
備註
在測試新建立的角色資訊(如新使用者或新群組)時,務必登出再登入,以強制角色資訊在網域內傳播。 如果不這麼做,測試可能會 IsInRole 回到 false。
出於效能考量,建議以 IsInRole(SecurityIdentifier) 過載作為決定使用者角色的首選過載值。
Note
在 Windows Vista 中,用戶帳戶控制 (UAC) 會決定用戶的許可權。 如果你是內建管理員群組的成員,你會被分配兩個執行時存取權杖:一個標準使用者存取權杖和一個管理員存取權杖。 根據預設,您處於標準使用者角色。 當你嘗試執行需要管理員權限的任務時,可以透過同意對話框動態提升你的角色。 執行該 IsInRole 方法的程式碼不會顯示同意對話框。 如果你處於標準使用者角色,即使你在內建管理員群組,程式碼也會回傳 false。 你可以在執行程式碼前,透過右鍵點擊應用程式圖示並表示你想以管理員身份執行,提升你的權限。
適用於
IsInRole(String)
判斷目前的主體是否屬於指定名稱的 Windows 使用者群組。
public:
override bool IsInRole(System::String ^ role);
public:
virtual bool IsInRole(System::String ^ role);
public override bool IsInRole(string role);
public virtual bool IsInRole(string role);
override this.IsInRole : string -> bool
abstract member IsInRole : string -> bool
override this.IsInRole : string -> bool
Public Overrides Function IsInRole (role As String) As Boolean
Public Overridable Function IsInRole (role As String) As Boolean
參數
- role
- String
用來檢查會員資格的 Windows 使用者群組名稱。
傳回
true 若現任負責人是指定Windows使用者群組成員;否則為 false。
實作
範例
以下程式碼範例示範了此 WindowsPrincipal.IsInRole(String) 方法的使用。
字串 BUILTIN\Administrators 和 BUILTIN\Users 用來判斷當前主體是管理員還是使用者。 完整程式碼範例請參見方法。WindowsPrincipal.IsInRole(Int32)
// Get the role using the string value of the role.
Console.WriteLine("{0}? {1}.", "Administrators",
myPrincipal.IsInRole("BUILTIN\\" + "Administrators"));
Console.WriteLine("{0}? {1}.", "Users",
myPrincipal.IsInRole("BUILTIN\\" + "Users"));
' Get the role using the string value of the role.
Console.WriteLine("{0}? {1}.", "Administrators", myPrincipal.IsInRole("BUILTIN\" + "Administrators"))
Console.WriteLine("{0}? {1}.", "Users", myPrincipal.IsInRole("BUILTIN\" + "Users"))
備註
在測試新建立的角色資訊(如新使用者或新群組)時,務必登出再登入,以強制角色資訊在網域內傳播。 如果不這麼做,測試可能會 IsInRole 回到 false。
出於效能考量,建議以 IsInRole(SecurityIdentifier) 過載作為決定使用者角色的首選過載值。
Note
在 Windows Vista 中,用戶帳戶控制 (UAC) 會決定用戶的許可權。 如果你是內建管理員群組的成員,你會被分配兩個執行時存取權杖:一個標準使用者存取權杖和一個管理員存取權杖。 根據預設,您處於標準使用者角色。 當你嘗試執行需要管理員權限的任務時,可以透過同意對話框動態提升你的角色。 執行該 IsInRole 方法的程式碼不會顯示同意對話框。 如果你處於標準使用者角色,即使你在內建管理員群組,程式碼也會回傳 false。 你可以在執行程式碼前,透過右鍵點擊應用程式圖示並表示你想以管理員身份執行,提升你的權限。
對於內建角色,字 role 串應該是「BUILTIN\RoleNameHere」的形式。 例如,為了測試 Windows 管理員角色的成員資格,代表該角色的字串應為「BUILTIN\Administrators」。 請注意,反斜線可能需要跳脫。 下表列出了內建的角色。
Note
BUILTIN 角色在字串格式中的拼寫與列舉中使用的拼寫 WindowsBuiltInRole 不同。 例如,列舉中管理員的拼法是「Administrator」,而非「Administrators」。 使用此超載時,請使用下表中該角色的拼寫。
| 內建的地方群組 |
|---|
| BUILTIN\Administrators |
| 內建\使用者 |
| 內建\賓客 |
| BUILTIN\Account Operators |
| BUILTIN\Server 運算元 |
| 內建\列印運算元 |
| 內建\備用運算元 |
| 內建\複製器 |
對於機器特定角色,字 role 串應該是「MachineName\RoleNameHere」的形式。
對於特定領域的角色,字 role 串應為「DomainName\RoleNameHere」的形式;例如, "SomeDomain\Domain Users「 。
Note
在 .NET Framework 1.0 版本中,role 參數為大小寫區分。 在 .NET Framework 1.1 及之後版本中,role 參數不區分大小寫。