Skip to content

Get‑ADObjectAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Gets typed access rules from Active Directory object DACLs.

SYNTAX

Get-ADObjectAccessRule [-Server <String>] [-DistinguishedName] <Object[]> [-Credential <PSCredential>]
 [-Account <Object[]>] [-ExcludeInherited] [-ExcludeExplicit] [-ExcludeSchemaDefault] [-TimeoutSeconds <Int32>]
 [-ThrottleLimit <Int32>] [<CommonParameters>]

DESCRIPTION

Reads object DACLs over signed and sealed LDAP and preserves common or object-specific ACE masks, inheritance, GUIDs, and immutable targets. Inherited rules expose InheritedFrom with the ancestor object that holds the originating explicit ACE, and object GUIDs are additionally reported as resolved schema, property-set, or extended-right names.

EXAMPLES

EXAMPLE 1

Get-ADObjectAccessRule -Server dc01.example.test -DistinguishedName $dn -Account Everyone

Gets Everyone access rules from the selected directory object.

EXAMPLE 2

Get-ADObjectAccessRule -DistinguishedName $dn -ExcludeExplicit

Gets inherited rules, with their source object and resolved GUID names, through an automatically located writable domain controller.

EXAMPLE 3

Get-ADObjectAccessRule -DistinguishedName $dn -ExcludeInherited -ExcludeSchemaDefault

Gets the explicit rules the object's class default does not already grant, which is the delegation an operator configured.

PARAMETERS

-Account

Filters results by account names, SIDs, identity references, or module identities.

Type: Object[]
Parameter Sets: (All)
Aliases: IdentityReference, ID

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Credential

An optional credential used only for the direct LDAP bind to Server.

Type: PSCredential
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-DistinguishedName

One or more distinguished names to query.

Type: Object[]
Parameter Sets: (All)
Aliases: Path

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-ExcludeExplicit

Excludes explicit access rules.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-ExcludeInherited

Excludes inherited access rules.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-ExcludeSchemaDefault

Excludes every explicit rule that the target's structural class already grants through its defaultSecurityDescriptor, leaving the entries an operator added. A rule is excluded only when a template entry equals it on account, access mask, access control type, inheritance, and both object type GUIDs; anything the comparison cannot decide is reported. Inherited rules, and the entries a template placeholder such as CREATOR OWNER became, are never excluded.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Server

The explicit DNS name of the final writable domain controller. When it is omitted, one writable domain controller is located in the current computer's domain and pinned for the whole command.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed immutable object targets from 1 through 64.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-TimeoutSeconds

Sets the LDAP request timeout from 1 through 300 seconds.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: 10
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

WindowsAccessControl.ADObjectAccessRule

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally