語言

WindowsPrincipal.IsInRole 方法

定義

判斷目前的主體是否屬於指定的 Windows 使用者群組。

多載

名稱 Description
IsInRole(Int32)

判斷目前主體是否屬於指定相對識別碼(RID)的 Windows 使用者群組。

IsInRole(SecurityIdentifier)

判斷目前的主體是否屬於具有指定安全識別碼(SID)的 Windows 使用者群組。

IsInRole(WindowsBuiltInRole)

判斷目前主體是否屬於指定的WindowsBuiltInRole 的Windows使用者群組。

IsInRole(String)

判斷目前的主體是否屬於指定名稱的 Windows 使用者群組。

備註

此方法有四種過載方式。 為了效能考量,強烈建議使用 IsInRole(SecurityIdentifier) 過載。

IsInRole(Int32)

判斷目前主體是否屬於指定相對識別碼(RID)的 Windows 使用者群組。

public:
 virtual bool IsInRole(int rid);
public virtual bool IsInRole(int rid);
override this.IsInRole : int -> bool
abstract member IsInRole : int -> bool
override this.IsInRole : int -> bool
Public Overridable Function IsInRole (rid As Integer) As Boolean

參數

rid
Int32

這是 Windows 使用者群組的 RID,用來檢查主體的成員狀態。

傳回

true 若現任負責人是指定Windows使用者群組成員,即特定角色;否則為 false。

範例

以下程式碼範例展示了這些 IsInRole 方法的使用方法。 列 WindowsBuiltInRole 舉作為識別內建角色的 RID 來源。 RID用來決定現任校長的角色。

public:
   static void DemonstrateWindowsBuiltInRoleEnum()
   {
      AppDomain^ myDomain = Thread::GetDomain();

      myDomain->SetPrincipalPolicy( PrincipalPolicy::WindowsPrincipal );
      WindowsPrincipal^ myPrincipal = dynamic_cast<WindowsPrincipal^>(Thread::CurrentPrincipal);

      Console::WriteLine( "{0} belongs to: ", myPrincipal->Identity->Name );

      Array^ wbirFields = Enum::GetValues( WindowsBuiltInRole::typeid );

      for each ( Object^ roleName in wbirFields )
      {
         try
         {
            Console::WriteLine( "{0}? {1}.", roleName,
               myPrincipal->IsInRole(  *dynamic_cast<WindowsBuiltInRole^>(roleName) ) );
         }
         catch ( Exception^ ) 
         {
            Console::WriteLine( "{0}: Could not obtain role for this RID.",
               roleName );
         }
      }
   }
using System;
using System.Threading;
using System.Security.Permissions;
using System.Security.Principal;

class SecurityPrincipalDemo
{
    public static void DemonstrateWindowsBuiltInRoleEnum()
    {
        AppDomain myDomain = Thread.GetDomain();

        myDomain.SetPrincipalPolicy(PrincipalPolicy.WindowsPrincipal);
        WindowsPrincipal myPrincipal = (WindowsPrincipal)Thread.CurrentPrincipal;
        Console.WriteLine("{0} belongs to: ", myPrincipal.Identity.Name.ToString());
        Array wbirFields = Enum.GetValues(typeof(WindowsBuiltInRole));
        foreach (object roleName in wbirFields)
        {
            try
            {
                // Cast the role name to a RID represented by the WindowsBuildInRole value.
                Console.WriteLine("{0}? {1}.", roleName,
                    myPrincipal.IsInRole((WindowsBuiltInRole)roleName));
                Console.WriteLine("The RID for this role is: " + ((int)roleName).ToString());
            }
            catch (Exception)
            {
                Console.WriteLine("{0}: Could not obtain role for this RID.",
                    roleName);
            }
        }
        // Get the role using the string value of the role.
        Console.WriteLine("{0}? {1}.", "Administrators",
            myPrincipal.IsInRole("BUILTIN\\" + "Administrators"));
        Console.WriteLine("{0}? {1}.", "Users",
            myPrincipal.IsInRole("BUILTIN\\" + "Users"));
        // Get the role using the WindowsBuiltInRole enumeration value.
        Console.WriteLine("{0}? {1}.", WindowsBuiltInRole.Administrator,
           myPrincipal.IsInRole(WindowsBuiltInRole.Administrator));
        // Get the role using the WellKnownSidType.
        SecurityIdentifier sid = new SecurityIdentifier(WellKnownSidType.BuiltinAdministratorsSid, null);
        Console.WriteLine("WellKnownSidType BuiltinAdministratorsSid  {0}? {1}.", sid.Value, myPrincipal.IsInRole(sid));
    }

    public static void Main()
    {
        DemonstrateWindowsBuiltInRoleEnum();
    }
}
Imports System.Threading
Imports System.Security.Permissions
Imports System.Security.Principal

Class SecurityPrincipalDemo

    Public Shared Sub DemonstrateWindowsBuiltInRoleEnum()
        Dim myDomain As AppDomain = Thread.GetDomain()

        myDomain.SetPrincipalPolicy(PrincipalPolicy.WindowsPrincipal)
        Dim myPrincipal As WindowsPrincipal = CType(Thread.CurrentPrincipal, WindowsPrincipal)
        Console.WriteLine("{0} belongs to: ", myPrincipal.Identity.Name.ToString())
        Dim wbirFields As Array = [Enum].GetValues(GetType(WindowsBuiltInRole))
        Dim roleName As Object
        For Each roleName In wbirFields
            Try
                ' Cast the role name to a RID represented by the WindowsBuildInRole value.
                Console.WriteLine("{0}? {1}.", roleName, myPrincipal.IsInRole(CType(roleName, WindowsBuiltInRole)))
                Console.WriteLine("The RID for this role is: " + Fix(roleName).ToString())

            Catch
                Console.WriteLine("{0}: Could not obtain role for this RID.", roleName)
            End Try
        Next roleName
        ' Get the role using the string value of the role.
        Console.WriteLine("{0}? {1}.", "Administrators", myPrincipal.IsInRole("BUILTIN\" + "Administrators"))
        Console.WriteLine("{0}? {1}.", "Users", myPrincipal.IsInRole("BUILTIN\" + "Users"))
        ' Get the role using the WindowsBuiltInRole enumeration value.
        Console.WriteLine("{0}? {1}.", WindowsBuiltInRole.Administrator, myPrincipal.IsInRole(WindowsBuiltInRole.Administrator))
        ' Get the role using the WellKnownSidType.
        Dim sid As New SecurityIdentifier(WellKnownSidType.BuiltinAdministratorsSid, Nothing)
        Console.WriteLine("WellKnownSidType BuiltinAdministratorsSid  {0}? {1}.", sid.Value, myPrincipal.IsInRole(sid))

    End Sub

    Public Shared Sub Main()
        DemonstrateWindowsBuiltInRoleEnum()

    End Sub
End Class

備註

在測試新建立的角色資訊(如新使用者或新群組)時,務必登出再登入,以強制角色資訊在網域內傳播。 如果不這麼做,測試可能會 IsInRole 回到 false。

出於效能考量,建議以 IsInRole(SecurityIdentifier) 過載作為決定使用者角色的首選過載值。

Note

在 Windows Vista 中,用戶帳戶控制 (UAC) 會決定用戶的許可權。 如果你是內建管理員群組的成員,你會被分配兩個執行時存取權杖:一個標準使用者存取權杖和一個管理員存取權杖。 根據預設,您處於標準使用者角色。 當你嘗試執行需要管理員權限的任務時,可以透過同意對話框動態提升你的角色。 執行該 IsInRole 方法的程式碼不會顯示同意對話框。 如果你處於標準使用者角色,即使你在內建管理員群組,程式碼也會回傳 false。 你可以在執行程式碼前,透過右鍵點擊應用程式圖示並表示你想以管理員身份執行,提升你的權限。

相對識別碼(RID)是 Windows 使用者群組安全識別碼(SID)的組成部分,並被支援以防止跨平台在地化問題。 許多使用者帳號、本地群組和全域群組的預設 RID 值在所有 Windows 版本中都是固定的。

例如,BUILTIN\Administrators 角色的 RID 是 0x220。 若現任負責人是管理員,使用0x220作為方法的輸入參數 IsInRole ,則會 true 被回傳。

以下表格列出預設的RID值。

內建使用者 擺脫
網域名稱\管理員 0x1F4
網域名稱\訪客 0x1F5
內建的全域群組 擺脫
網域名稱\網域管理員 0x200
網域名稱\網域使用者 0x201
網域名稱\網域訪客 0x202
內建的地方群組 擺脫
BUILTIN\Administrators 0x220
內建\使用者 0x221
內建\賓客 0x222
BUILTIN\Account Operators 0x224
BUILTIN\Server 運算元 0x225
內建\列印運算元 0x226
內建\備用運算元 0x227
內建\複製器 0x228

適用於

IsInRole(SecurityIdentifier)

判斷目前的主體是否屬於具有指定安全識別碼(SID)的 Windows 使用者群組。

public:
 virtual bool IsInRole(System::Security::Principal::SecurityIdentifier ^ sid);
public virtual bool IsInRole(System.Security.Principal.SecurityIdentifier sid);
[System.Runtime.InteropServices.ComVisible(false)]
public virtual bool IsInRole(System.Security.Principal.SecurityIdentifier sid);
override this.IsInRole : System.Security.Principal.SecurityIdentifier -> bool
[<System.Runtime.InteropServices.ComVisible(false)>]
abstract member IsInRole : System.Security.Principal.SecurityIdentifier -> bool
override this.IsInRole : System.Security.Principal.SecurityIdentifier -> bool
[<System.Runtime.InteropServices.ComVisible(false)>]
override this.IsInRole : System.Security.Principal.SecurityIdentifier -> bool
Public Overridable Function IsInRole (sid As SecurityIdentifier) As Boolean

參數

sid
SecurityIdentifier

一個 SecurityIdentifier,唯一識別Windows使用者群組。

傳回

true 若現任負責人是指定Windows使用者群組成員;否則為 false。

屬性

例外狀況

sid 是 null。

Windows 回傳了 Win32 錯誤。

範例

以下程式碼範例示範了此 WindowsPrincipal.IsInRole(SecurityIdentifier) 方法的使用。 BuiltinAdministratorsSid列舉值用來判斷現任負責人是否為管理人員。 完整程式碼範例請參見方法。WindowsPrincipal.IsInRole(Int32)

// Get the role using the WellKnownSidType.
SecurityIdentifier sid = new SecurityIdentifier(WellKnownSidType.BuiltinAdministratorsSid, null);
Console.WriteLine("WellKnownSidType BuiltinAdministratorsSid  {0}? {1}.", sid.Value, myPrincipal.IsInRole(sid));
    ' Get the role using the WellKnownSidType.
    Dim sid As New SecurityIdentifier(WellKnownSidType.BuiltinAdministratorsSid, Nothing)
    Console.WriteLine("WellKnownSidType BuiltinAdministratorsSid  {0}? {1}.", sid.Value, myPrincipal.IsInRole(sid))

End Sub

備註

SecurityIdentifier 唯一識別 Windows 上的使用者或群組。 在測試新建立的角色資訊(如新使用者或新群組)時,務必登出再登入,以強制角色資訊在網域內傳播。 如果不這麼做,測試可能會 IsInRole 回到 false。

Note

在 Windows Vista 中,用戶帳戶控制 (UAC) 會決定用戶的許可權。 如果你是內建管理員群組的成員,你會被分配兩個執行時存取權杖:一個標準使用者存取權杖和一個管理員存取權杖。 根據預設,您處於標準使用者角色。 當你嘗試執行需要管理員權限的任務時,可以透過同意對話框動態提升你的角色。 執行該 IsInRole 方法的程式碼不會顯示同意對話框。 如果你處於標準使用者角色,即使你在內建管理員群組,程式碼也會回傳 false。 你可以在執行程式碼前,透過右鍵點擊應用程式圖示並表示你想以管理員身份執行,提升你的權限。

出於效能考量,這是決定使用者角色的首選超載方式。

適用於

IsInRole(WindowsBuiltInRole)

判斷目前主體是否屬於指定的WindowsBuiltInRole 的Windows使用者群組。

public:
 virtual bool IsInRole(System::Security::Principal::WindowsBuiltInRole role);
public virtual bool IsInRole(System.Security.Principal.WindowsBuiltInRole role);
override this.IsInRole : System.Security.Principal.WindowsBuiltInRole -> bool
abstract member IsInRole : System.Security.Principal.WindowsBuiltInRole -> bool
override this.IsInRole : System.Security.Principal.WindowsBuiltInRole -> bool
Public Overridable Function IsInRole (role As WindowsBuiltInRole) As Boolean

參數

role
WindowsBuiltInRole

這是其中一項 WindowsBuiltInRole 價值。

傳回

true 若現任負責人是指定Windows使用者群組成員;否則為 false。

例外狀況

role 不是一個有效的 WindowsBuiltInRole 值。

範例

以下範例使用 WindowsBuiltInRole 列舉來判斷當前主體是否為 Administrator。 完整程式碼範例請參見方法。WindowsPrincipal.IsInRole(Int32)

// Get the role using the WindowsBuiltInRole enumeration value.
Console.WriteLine("{0}? {1}.", WindowsBuiltInRole.Administrator,
   myPrincipal.IsInRole(WindowsBuiltInRole.Administrator));
' Get the role using the WindowsBuiltInRole enumeration value.
Console.WriteLine("{0}? {1}.", WindowsBuiltInRole.Administrator, myPrincipal.IsInRole(WindowsBuiltInRole.Administrator))

備註

在測試新建立的角色資訊(如新使用者或新群組)時,務必登出再登入,以強制角色資訊在網域內傳播。 如果不這麼做,測試可能會 IsInRole 回到 false。

出於效能考量,建議以 IsInRole(SecurityIdentifier) 過載作為決定使用者角色的首選過載值。

Note

在 Windows Vista 中,用戶帳戶控制 (UAC) 會決定用戶的許可權。 如果你是內建管理員群組的成員,你會被分配兩個執行時存取權杖:一個標準使用者存取權杖和一個管理員存取權杖。 根據預設,您處於標準使用者角色。 當你嘗試執行需要管理員權限的任務時,可以透過同意對話框動態提升你的角色。 執行該 IsInRole 方法的程式碼不會顯示同意對話框。 如果你處於標準使用者角色,即使你在內建管理員群組,程式碼也會回傳 false。 你可以在執行程式碼前,透過右鍵點擊應用程式圖示並表示你想以管理員身份執行,提升你的權限。

適用於

IsInRole(String)

判斷目前的主體是否屬於指定名稱的 Windows 使用者群組。

public:
 override bool IsInRole(System::String ^ role);
public:
 virtual bool IsInRole(System::String ^ role);
public override bool IsInRole(string role);
public virtual bool IsInRole(string role);
override this.IsInRole : string -> bool
abstract member IsInRole : string -> bool
override this.IsInRole : string -> bool
Public Overrides Function IsInRole (role As String) As Boolean
Public Overridable Function IsInRole (role As String) As Boolean

參數

role
String

用來檢查會員資格的 Windows 使用者群組名稱。

傳回

true 若現任負責人是指定Windows使用者群組成員;否則為 false。

實作

範例

以下程式碼範例示範了此 WindowsPrincipal.IsInRole(String) 方法的使用。

字串 BUILTIN\Administrators 和 BUILTIN\Users 用來判斷當前主體是管理員還是使用者。 完整程式碼範例請參見方法。WindowsPrincipal.IsInRole(Int32)

// Get the role using the string value of the role.
Console.WriteLine("{0}? {1}.", "Administrators",
    myPrincipal.IsInRole("BUILTIN\\" + "Administrators"));
Console.WriteLine("{0}? {1}.", "Users",
    myPrincipal.IsInRole("BUILTIN\\" + "Users"));
' Get the role using the string value of the role.
Console.WriteLine("{0}? {1}.", "Administrators", myPrincipal.IsInRole("BUILTIN\" + "Administrators"))
Console.WriteLine("{0}? {1}.", "Users", myPrincipal.IsInRole("BUILTIN\" + "Users"))

備註

在測試新建立的角色資訊(如新使用者或新群組)時,務必登出再登入,以強制角色資訊在網域內傳播。 如果不這麼做,測試可能會 IsInRole 回到 false。

出於效能考量,建議以 IsInRole(SecurityIdentifier) 過載作為決定使用者角色的首選過載值。

Note

在 Windows Vista 中,用戶帳戶控制 (UAC) 會決定用戶的許可權。 如果你是內建管理員群組的成員,你會被分配兩個執行時存取權杖:一個標準使用者存取權杖和一個管理員存取權杖。 根據預設,您處於標準使用者角色。 當你嘗試執行需要管理員權限的任務時,可以透過同意對話框動態提升你的角色。 執行該 IsInRole 方法的程式碼不會顯示同意對話框。 如果你處於標準使用者角色,即使你在內建管理員群組,程式碼也會回傳 false。 你可以在執行程式碼前,透過右鍵點擊應用程式圖示並表示你想以管理員身份執行,提升你的權限。

對於內建角色,字 role 串應該是「BUILTIN\RoleNameHere」的形式。 例如,為了測試 Windows 管理員角色的成員資格,代表該角色的字串應為「BUILTIN\Administrators」。 請注意,反斜線可能需要跳脫。 下表列出了內建的角色。

Note

BUILTIN 角色在字串格式中的拼寫與列舉中使用的拼寫 WindowsBuiltInRole 不同。 例如,列舉中管理員的拼法是「Administrator」,而非「Administrators」。 使用此超載時,請使用下表中該角色的拼寫。

內建的地方群組
BUILTIN\Administrators
內建\使用者
內建\賓客
BUILTIN\Account Operators
BUILTIN\Server 運算元
內建\列印運算元
內建\備用運算元
內建\複製器

對於機器特定角色,字 role 串應該是「MachineName\RoleNameHere」的形式。

對於特定領域的角色,字 role 串應為「DomainName\RoleNameHere」的形式;例如, "SomeDomain\Domain Users「 。

Note

在 .NET Framework 1.0 版本中,role 參數為大小寫區分。 在 .NET Framework 1.1 及之後版本中,role 參數不區分大小寫。

另請參閱

適用於