Skip to content

Get‑ADObjectCallerEffectiveAccess

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Gets the write access a domain controller computes for the calling identity on Active Directory objects.

SYNTAX

Get-ADObjectCallerEffectiveAccess [-Server <String>] [-DistinguishedName] <Object[]>
 [-Credential <PSCredential>] [-TimeoutSeconds <Int32>] [-ThrottleLimit <Int32>]
 [<CommonParameters>]

DESCRIPTION

Reads the three constructed attributes a domain controller evaluates in the security context of the LDAP bind that requested them: allowedAttributesEffective, allowedChildClassesEffective, and sDRightsEffective. The module computes none of these values; it names the attributes explicitly, because a wildcard attribute request never returns a constructed attribute, and formats what the controller returns.

The result is scoped to the bound identity and to nothing else. There is no Account parameter, because no in-box interface asks a domain controller for another principal's effective access. Supplying Credential changes the bind and therefore changes the answer.

The three attributes are a write-side answer. None of them reports read access, extended rights such as Reset Password, or the right to delete, move, or rename a child object. Use Get-ADObjectAccessRule to see who is granted what.

EXAMPLES

EXAMPLE 1

Get-ADObjectCallerEffectiveAccess -DistinguishedName $dn

Reports which descriptor sections, attributes, and child classes the current identity may write on the selected object.

EXAMPLE 2

(Get-ADObjectCallerEffectiveAccess -DistinguishedName $dn).WritableAttribute

Lists every attribute the domain controller says the caller may write.

EXAMPLE 3

Get-ADObjectCallerEffectiveAccess -Server dc01.example.test `
    -DistinguishedName $dn `
    -Credential (Get-Credential)

Asks the same controller what the supplied identity may write, because the constructed attributes are evaluated for whoever bound the session.

PARAMETERS

-Credential

An optional credential used only for the direct LDAP bind to Server. It selects the identity the domain controller evaluates.

Type: PSCredential
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-DistinguishedName

One or more distinguished names to evaluate.

Type: Object[]
Parameter Sets: (All)
Aliases: Path

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-Server

The explicit DNS name of the domain controller to ask. When it is omitted, one writable domain controller is located in the current computer's domain and pinned for the whole command.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed immutable object targets from 1 through 64.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-TimeoutSeconds

Sets the LDAP request timeout from 1 through 300 seconds.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: 10
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

WindowsAccessControl.ADObjectCallerEffectiveAccess

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally