Private/Grant-IslFolderAccess.ps1
|
function Grant-IslFolderAccess { <# .SYNOPSIS Gives an account Modify rights on a folder and everything created in it. .DESCRIPTION The harness runs another account's script from a cache folder and reads that account's output files back from it, so the account needs to read the script copy and write next to it. Uses icacls, which resolves the account name the way the scheduled task will. A separate function so the unit tests can mock the grant for accounts that do not exist. .PARAMETER Path The folder. .PARAMETER Account The account, as the credential names it (isl-user, MACHINE\isl-user or user@domain). .EXAMPLE Grant-IslFolderAccess -Path C:\ProgramData\IntuneScriptLab\Runs\abc -Account isl-user Modify, inherited by files and subfolders, for isl-user. #> [CmdletBinding()] [OutputType([void])] param( [Parameter(Mandatory)] [string]$Path, [Parameter(Mandatory)] [string]$Account ) $output = & icacls.exe $Path /grant "${Account}:(OI)(CI)M" 2>&1 if ($LASTEXITCODE -ne 0) { throw "Could not grant $Account access to ${Path}: $($output -join ' ')" } } |