Skip to content

Add‑TaskFolderAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Adds typed access rules to contained local Task Scheduler folders.

SYNTAX

Add-TaskFolderAccessRule [-Path] <Object[]> -AllowedRootPath <String> -Account <Object[]>
 -AccessRights <WindowsTaskFolderRights> [-AccessControlType <AccessControlType>] [-AppliesTo <String>]
 [-ThrottleLimit <Int32>] [-PassThru] [-WhatIf] [-Confirm]
 [<CommonParameters>]

DESCRIPTION

Resolves and deduplicates every account before adding exact folder ACEs and persisting each target DACL once. The target must be inside AllowedRootPath, outside the root and Microsoft system tree, and the result must preserve the Task Scheduler service token's access.

EXAMPLES

EXAMPLE 1

Add-TaskFolderAccessRule -Path '\Operations' -AllowedRootPath '\Operations' `
    -Account 'CONTOSO\Operators' -AccessRights ReadAndTraverse -WhatIf

Previews adding a contained read-and-traverse rule to the Operations folder.

PARAMETERS

-AccessControlType

Adds an Allow rule by default or an explicit Deny rule.

Type: AccessControlType
Parameter Sets: (All)
Aliases:
Accepted values: Allow, Deny

Required: False
Position: Named
Default value: Allow
Accept pipeline input: False
Accept wildcard characters: False

-AccessRights

Task folder rights to add, such as Read, ReadAndTraverse, or CreateTask.

Type: WindowsTaskFolderRights
Parameter Sets: (All)
Aliases:
Accepted values: ListTasks, CreateTask, CreateSubfolder, ReadExtendedProperties, WriteExtendedProperties, Traverse, DeleteChild, ReadProperties, WriteProperties, Delete, ReadPermissions, ChangePermissions, TakeOwnership, Synchronize, Read, ReadAndTraverse, Write, Modify, FullControl, GenericAll, GenericExecute, GenericWrite, GenericRead

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Account

One or more account names, SIDs, identity references, or module identities.

Type: Object[]
Parameter Sets: (All)
Aliases: IdentityReference, ID

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-AllowedRootPath

The explicit non-system folder boundary containing every write target.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-AppliesTo

Controls whether the ACE applies to this folder, subfolders, or tasks.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: ThisFolderOnly
Accept pipeline input: False
Accept wildcard characters: False

-PassThru

Returns the stored explicit folder access rules after persistence.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Path

One or more absolute local Task Scheduler folder paths.

Type: Object[]
Parameter Sets: (All)
Aliases: TaskPath

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical folder targets from 1 to 64.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

None

WindowsAccessControl.TaskFolderAccessRule

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally