Skip to content

Backup‑WindowsSecurityDescriptor

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Backs up Windows security descriptor objects to one JSON envelope.

SYNTAX

Backup-WindowsSecurityDescriptor [-InputObject] <PSObject[]> [-DestinationPath] <String> [-Force]
 [[-SigningCertificate] <X509Certificate2>] [-PassThru] [-WhatIf]
 [-Confirm] [<CommonParameters>]

DESCRIPTION

Accepts security descriptors emitted by WindowsAccessControl, normalizes their object-family metadata and section masks, and writes versioned, non-executable JSON records protected by SHA-256 digests. Local object families use record version 1; SMB share and Active Directory records use record version 2 and additionally bind explicit server authority plus immutable target identity. The envelope schema version is the highest record version it contains. The completed envelope atomically replaces its destination.

EXAMPLES

EXAMPLE 1

Get-NTFSItemSecurityDescriptor C:\Data -Sections Access |
    Backup-WindowsSecurityDescriptor -DestinationPath C:\Backup\acl.json

Backs up the selected filesystem DACL in the unified envelope.

PARAMETERS

-DestinationPath

The literal JSON file path written after all input is validated.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: 2
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Force

Allows an existing backup file to be overwritten.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-InputObject

One or more security descriptor objects emitted by WindowsAccessControl.

Type: PSObject[]
Parameter Sets: (All)
Aliases:

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByValue)
Accept wildcard characters: False

-PassThru

Returns each normalized backup record after the file is written.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-SigningCertificate

An RSA X.509 certificate with a private key used to sign each record after ShouldProcess approves the destination write.

Type: X509Certificate2
Parameter Sets: (All)
Aliases:

Required: False
Position: 3
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

WindowsAccessControl.SecurityDescriptor

OUTPUTS

None

WindowsAccessControl.SecurityDescriptorBackupRecord

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally