Skip to content

Clear‑ADObjectAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Removes explicit access rules from bounded Active Directory object DACLs.

SYNTAX

Clear-ADObjectAccessRule [-Server <String>] [-DistinguishedName] <Object[]>
 -AllowedBaseDistinguishedName <String> [-Credential <PSCredential>] [-Account <Object[]>]
 [-TimeoutSeconds <Int32>] [-ThrottleLimit <Int32>] [-PassThru] [-WhatIf]
 [-Confirm] [<CommonParameters>]

DESCRIPTION

Removes every explicit ACE from the selected object DACLs, or only the explicit ACEs of the selected accounts, and leaves inherited ACEs untouched. Both allow and deny rules are removed, so removing a deny can increase effective access; the command warns when that happens. The write is rejected when the result would leave no principal able to manage the object.

EXAMPLES

EXAMPLE 1

Clear-ADObjectAccessRule -Server dc01.example.test -DistinguishedName $dn -AllowedBaseDistinguishedName $ou -Account $sid -WhatIf

Previews removing every explicit ACE for one account inside the allowed OU.

EXAMPLE 2

Clear-ADObjectAccessRule -DistinguishedName $dn -AllowedBaseDistinguishedName $ou -WhatIf

Previews removing every explicit ACE from the object, including ACEs for accounts not named in this command. Inherited ACEs and the guard against leaving no principal able to manage the object still apply.

EXAMPLE 3

Clear-ADObjectAccessRule -DistinguishedName $dn -AllowedBaseDistinguishedName $ou -Account 'CONTOSO\FormerContractors', 'CONTOSO\Legacy' -Confirm:$false -PassThru

Removes every explicit ACE for two accounts and returns what was removed, including any deny rule.

PARAMETERS

-Account

Restricts removal to these account names, SIDs, identity references, or module identities. All explicit rules are removed when it is omitted.

Type: Object[]
Parameter Sets: (All)
Aliases: IdentityReference, ID

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-AllowedBaseDistinguishedName

The organizational unit that bounds every permitted mutation.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Credential

An optional credential used only for the direct LDAP bind to Server.

Type: PSCredential
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-DistinguishedName

One or more distinguished names to modify.

Type: Object[]
Parameter Sets: (All)
Aliases: Path

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-PassThru

Returns the removed explicit access rules after persistence.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Server

The explicit DNS name of the final writable domain controller. When it is omitted, one writable domain controller is located in the current computer's domain and pinned for the whole command.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed immutable object targets from 1 through 64.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-TimeoutSeconds

Sets the LDAP request timeout from 1 through 300 seconds.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: 10
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

None

WindowsAccessControl.ADObjectAccessRule

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally