Skip to content

Add‑NTFSAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Adds an NTFS access rule to files or directories.

SYNTAX

Path (Default)

Add-NTFSAccessRule [-Path] <String[]> -Account <String[]> -AccessRights <Object>
 [-AccessControlType <AccessControlType>] [-AppliesTo <String>] [-ThrottleLimit <Int32>] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

LiteralPath

Add-NTFSAccessRule -LiteralPath <String[]> -Account <String[]> -AccessRights <Object>
 [-AccessControlType <AccessControlType>] [-AppliesTo <String>] [-ThrottleLimit <Int32>] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

SecurityDescriptor

Add-NTFSAccessRule -SecurityDescriptor <PSObject> -Account <String[]> -AccessRights <Object>
 [-AccessControlType <AccessControlType>] [-AppliesTo <String>] [-ThrottleLimit <Int32>] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

DESCRIPTION

Adds an allow or deny access rule without replacing unrelated rules. Directory rules use Explorer-style AppliesTo values, while file rules apply only to the file unless AppliesTo is explicitly supplied. A junction, a symbolic link, or a volume mount point is written as itself; its destination is not changed.

EXAMPLES

EXAMPLE 1

Get-Item -LiteralPath C:\Data | Add-NTFSAccessRule -Account 'CONTOSO\Analysts' -AccessRights Read

Adds read access for the Analysts group to C:\Data and its children.

EXAMPLE 2

Get-NTFSItemSecurityDescriptor -LiteralPath C:\Data -Sections Access |
    Add-NTFSAccessRule -Account 'CONTOSO\Analysts' -AccessRights Read |
    Set-NTFSItemSecurityDescriptor

Stages a read access rule in memory and persists it with one write.

PARAMETERS

-AccessControlType

Specifies whether the rule allows or denies the selected rights.

Type: AccessControlType
Parameter Sets: (All)
Aliases:
Accepted values: Allow, Deny

Required: False
Position: Named
Default value: Allow
Accept pipeline input: False
Accept wildcard characters: False

-AccessRights

The filesystem rights to add to the access control list. A raw access mask is also accepted as a decimal number or a hexadecimal string, so bits the FileSystemRights enumeration cannot name, such as the generic rights, can be used.

Type: Object
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Account

One or more account names or SIDs to which the access rule applies.

Type: String[]
Parameter Sets: (All)
Aliases: IdentityReference, ID

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-AppliesTo

Specifies how a directory rule applies to the directory and its child files or directories. Files default to ThisFolderOnly.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-LiteralPath

One or more filesystem paths used exactly as supplied. FileSystem objects bind to this parameter through their PSPath property.

Type: String[]
Parameter Sets: LiteralPath
Aliases: PSPath

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-PassThru

Returns the access rule that was persisted. By default, the command does not emit output.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Path

One or more filesystem paths. Wildcards are expanded by the FileSystem provider, and path strings can be supplied through the pipeline.

Type: String[]
Parameter Sets: Path
Aliases: FullName

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: True

-SecurityDescriptor

A WindowsAccessControl.SecurityDescriptor object returned by Get-NTFSItemSecurityDescriptor. When supplied, the access rule is staged on the descriptor in memory and the descriptor is returned; nothing is written until Set-NTFSItemSecurityDescriptor persists it.

Type: PSObject
Parameter Sets: SecurityDescriptor
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByValue)
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical paths. One requests deterministic sequential execution.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

System.IO.FileSystemInfo

WindowsAccessControl.SecurityDescriptor

OUTPUTS

None

WindowsAccessControl.AccessRule

WindowsAccessControl.SecurityDescriptor

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally