Skip to content

Get‑ADObjectSchemaDefaultAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Returns the default access rules a schema class applies to new objects.

SYNTAX

Get-ADObjectSchemaDefaultAccessRule [-Server <String>] [-ObjectClass] <String[]> [-Credential <PSCredential>]
 [-TimeoutSeconds <Int32>] [<CommonParameters>]

DESCRIPTION

Reads defaultSecurityDescriptor from one or more classSchema objects and returns the access control entries Active Directory itself applies when it creates an object of that class. The result is the baseline an explicit rule has to be compared against: without it, every default entry looks like operator configuration.

The stored descriptor is SDDL that names domain-relative aliases such as DA and EA. Those are expanded against the SID of the domain the selected controller serves, and against the forest root domain SID where the alias is forest wide, rather than against the calling computer's own domain. A machine that is not domain joined cannot resolve them at all, so the expansion is what makes the read work from any host.

The output is not path bound. It describes a template rather than the current state of any object and therefore cannot be piped into a rule mutator.

EXAMPLES

EXAMPLE 1

Get-ADObjectSchemaDefaultAccessRule -Server dc01.example.test -ObjectClass user

Returns the entries Active Directory applies to every new user object.

EXAMPLE 2

Get-ADObjectAccessRule -Server dc01.example.test -DistinguishedName $dn -ExcludeInherited |
    Where-Object SID -notin (Get-ADObjectSchemaDefaultAccessRule -Server dc01.example.test -ObjectClass user).SID

Narrows explicit entries to the accounts the schema default does not already grant.

PARAMETERS

-Credential

An optional credential used only for the direct LDAP bind to Server.

Type: PSCredential
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ObjectClass

One or more schema class names, given as the lDAPDisplayName or the common name.

Type: String[]
Parameter Sets: (All)
Aliases: Class

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-Server

The explicit DNS name of the domain controller to read. When it is omitted, one writable domain controller is located in the current computer's domain and pinned for the whole command.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-TimeoutSeconds

Sets the LDAP request timeout from 1 through 300 seconds.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: 10
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

WindowsAccessControl.ADSchemaDefaultAccessRule

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally