Skip to content

Add‑ScheduledTaskAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Adds typed access rules to contained local registered tasks.

SYNTAX

Add-ScheduledTaskAccessRule [-TaskPath] <Object[]> -TaskName <String> -AllowedRootPath <String>
 -Account <Object[]> -AccessRights <WindowsScheduledTaskRights> [-AccessControlType <AccessControlType>]
 [-ThrottleLimit <Int32>] [-PassThru] [-WhatIf] [-Confirm]
 [<CommonParameters>]

DESCRIPTION

Resolves and deduplicates every account before adding exact task ACEs and persisting each target DACL once. The parent folder must be inside AllowedRootPath, outside the root and Microsoft system tree, and the result must preserve the Task Scheduler service token's access.

EXAMPLES

EXAMPLE 1

Add-ScheduledTaskAccessRule -TaskPath '\Operations' -TaskName 'Cleanup' `
    -AllowedRootPath '\Operations' -Account 'CONTOSO\Operators' `
    -AccessRights ReadAndRun -WhatIf

Previews granting read-and-run access on the contained Cleanup task.

PARAMETERS

-AccessControlType

Adds an Allow rule by default or an explicit Deny rule.

Type: AccessControlType
Parameter Sets: (All)
Aliases:
Accepted values: Allow, Deny

Required: False
Position: Named
Default value: Allow
Accept pipeline input: False
Accept wildcard characters: False

-AccessRights

Registered-task rights to add, such as Read, ReadAndRun, or Modify.

Type: WindowsScheduledTaskRights
Parameter Sets: (All)
Aliases:
Accepted values: ReadTaskDefinition, WriteTaskDefinition, ReadExtendedProperties, WriteExtendedProperties, RunTask, ReadProperties, WriteProperties, Delete, ReadPermissions, ChangePermissions, TakeOwnership, Synchronize, Read, ReadAndRun, Write, Modify, FullControl, GenericAll, GenericExecute, GenericWrite, GenericRead

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Account

One or more account names, SIDs, identity references, or module identities.

Type: Object[]
Parameter Sets: (All)
Aliases: IdentityReference, ID

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-AllowedRootPath

The explicit non-system folder boundary containing every write target.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-PassThru

Returns the stored explicit task access rules after persistence.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-TaskName

The exact leaf name of the registered task in each supplied folder.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-TaskPath

One or more absolute local Task Scheduler parent-folder paths.

Type: Object[]
Parameter Sets: (All)
Aliases:

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical task targets from 1 to 64.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

None

WindowsAccessControl.ScheduledTaskAccessRule

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally