Skip to content

Add‑SmbShareAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Adds typed access rules to local SMB share DACLs.

SYNTAX

Add-SmbShareAccessRule [-Name] <Object[]> -Account <Object[]> -AccessRights <WindowsSmbShareRights>
 [-AccessControlType <AccessControlType>] [-ThrottleLimit <Int32>] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

DESCRIPTION

Resolves and deduplicates every account before adding exact share ACEs and persists each target DACL once without touching backing NTFS ACLs.

EXAMPLES

EXAMPLE 1

Add-SmbShareAccessRule -Name 'Data$' -Account Everyone -AccessRights Read -WhatIf

Previews adding an Everyone read rule to the local Data share.

PARAMETERS

-AccessControlType

Adds an Allow rule by default or an explicit Deny rule.

Type: AccessControlType
Parameter Sets: (All)
Aliases:
Accepted values: Allow, Deny

Required: False
Position: Named
Default value: Allow
Accept pipeline input: False
Accept wildcard characters: False

-AccessRights

Share rights to add: Read, Change, or Full.

Type: WindowsSmbShareRights
Parameter Sets: (All)
Aliases:
Accepted values: Delete, ReadControl, WriteDac, WriteOwner, Synchronize, Read, Change, Full, AccessSystemSecurity, GenericAll, GenericExecute, GenericWrite, GenericRead

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Account

One or more account names, SIDs, identity references, or module identities.

Type: Object[]
Parameter Sets: (All)
Aliases: IdentityReference, ID

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Name

One or more unqualified local SMB share names.

Type: Object[]
Parameter Sets: (All)
Aliases: ShareName

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-PassThru

Returns the stored explicit share access rules after persistence.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical share targets from 1 through 64.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

None

WindowsAccessControl.SmbShareAccessRule

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally