Skip to content

Backup‑NTFSItemSecurityDescriptor

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Backs up NTFS security descriptors to JSON.

SYNTAX

Path (Default)

Backup-NTFSItemSecurityDescriptor [-Path] <String[]> -DestinationPath <String>
 [-Sections <AccessControlSections>] [-ThrottleLimit <Int32>] [-Force] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

LiteralPath

Backup-NTFSItemSecurityDescriptor -LiteralPath <String[]> -DestinationPath <String>
 [-Sections <AccessControlSections>] [-ThrottleLimit <Int32>] [-Force] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

DESCRIPTION

Writes a versioned, non-executable JSON document containing each item path, item type, selected section bitmask, and SDDL descriptor.

EXAMPLES

EXAMPLE 1

Get-ChildItem C:\Data | Backup-NTFSItemSecurityDescriptor -DestinationPath C:\Backup\permissions.json

Backs up owner, group, and DACL sections for each child item.

PARAMETERS

-DestinationPath

The literal JSON file path written after all pipeline items are collected.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Force

Allows an existing backup file to be overwritten. Without Force, the command refuses to replace an existing file.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-LiteralPath

One or more filesystem paths used exactly as supplied. FileSystem objects bind to this parameter through their PSPath property.

Type: String[]
Parameter Sets: LiteralPath
Aliases: PSPath

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-PassThru

Returns each backup record after the JSON document is written.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Path

One or more filesystem paths. Wildcards are expanded by the FileSystem provider, and path strings can be supplied through the pipeline.

Type: String[]
Parameter Sets: Path
Aliases: FullName

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: True

-Sections

Selects the descriptor sections stored in each backup record.

Type: AccessControlSections
Parameter Sets: (All)
Aliases:
Accepted values: None, Audit, Access, Owner, Group, All

Required: False
Position: Named
Default value: Access, Owner, Group
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently read canonical paths. One requests deterministic sequential execution. The destination is still written exactly once.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

System.IO.FileSystemInfo

OUTPUTS

None

WindowsAccessControl.SecurityDescriptorBackupRecord

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally