Skip to content

Add‑ServiceAuditRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Adds audit rules to local services or the Service Control Manager.

SYNTAX

Service (Default)

Add-ServiceAuditRule [-Name] <Object[]> -Account <Object[]> -ServiceRights <WindowsServiceRights>
 [-AuditFlags <AuditFlags>] [-ThrottleLimit <Int32>] [-PassThru] [-WhatIf]
 [-Confirm] [<CommonParameters>]

ServiceControlManager

Add-ServiceAuditRule [-ServiceControlManager] -Account <Object[]>
 -ControlManagerRights <WindowsServiceControlManagerRights> [-AuditFlags <AuditFlags>] [-ThrottleLimit <Int32>]
 [-PassThru] [-WhatIf] [-Confirm] [<CommonParameters>]

DESCRIPTION

Resolves and deduplicates accounts before adding explicit SACL ACEs with typed rights and scoped SeSecurityPrivilege for each target.

EXAMPLES

EXAMPLE 1

Add-ServiceAuditRule -Name BITS -Account Everyone -ServiceRights Start -AuditFlags Failure -WhatIf

Previews adding a failed-start audit rule to BITS.

PARAMETERS

-Account

One or more account names, SIDs, identity references, or module identities.

Type: Object[]
Parameter Sets: (All)
Aliases: IdentityReference, ID

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-AuditFlags

Selects successful access, failed access, or both for auditing.

Type: AuditFlags
Parameter Sets: (All)
Aliases:
Accepted values: None, Success, Failure

Required: False
Position: Named
Default value: Success
Accept pipeline input: False
Accept wildcard characters: False

-ControlManagerRights

Rights audited by each Service Control Manager rule.

Type: WindowsServiceControlManagerRights
Parameter Sets: ServiceControlManager
Aliases:
Accepted values: Connect, CreateService, EnumerateService, Lock, QueryLockStatus, ModifyBootConfig, Delete, ReadControl, WriteDac, WriteOwner, AllAccess, AccessSystemSecurity, GenericAll, GenericExecute, GenericWrite, GenericRead

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Name

One or more local service names, ServiceController objects, or module outputs.

Type: Object[]
Parameter Sets: Service
Aliases: ServiceName

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-PassThru

Returns each stored explicit audit rule after persistence.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-ServiceControlManager

Selects the local Service Control Manager instead of a named service.

Type: SwitchParameter
Parameter Sets: ServiceControlManager
Aliases:

Required: True
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-ServiceRights

Rights audited by each named-service rule.

Type: WindowsServiceRights
Parameter Sets: Service
Aliases:
Accepted values: QueryConfig, ChangeConfig, QueryStatus, EnumerateDependents, Start, Stop, PauseContinue, Interrogate, UserDefinedControl, Delete, ReadControl, WriteDac, WriteOwner, AllAccess, Synchronize, AccessSystemSecurity, GenericAll, GenericExecute, GenericWrite, GenericRead

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical targets. One requests deterministic sequential execution.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

System.ServiceProcess.ServiceController

OUTPUTS

None

WindowsAccessControl.ServiceAuditRule

WindowsAccessControl.ServiceControlManagerAuditRule

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally