Skip to content

Get‑ADObjectSecurityDescriptor

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Gets DACL descriptors from Active Directory objects through an explicit DC.

SYNTAX

Get-ADObjectSecurityDescriptor [-Server <String>] [-DistinguishedName] <Object[]> [-Credential <PSCredential>]
 [-TimeoutSeconds <Int32>] [-ThrottleLimit <Int32>] [<CommonParameters>]

DESCRIPTION

Uses direct LDAP Negotiate authentication with signing and sealing to read one or more domain-partition object DACLs plus immutable object GUIDs.

EXAMPLES

EXAMPLE 1

Get-ADObjectSecurityDescriptor -Server dc01.example.test -DistinguishedName 'OU=Apps,DC=example,DC=test'

Gets the Apps OU DACL through a signed and sealed LDAP connection.

PARAMETERS

-Credential

An optional credential used only for the direct LDAP bind to Server.

Type: PSCredential
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-DistinguishedName

One or more distinguished names in the selected domain partition.

Type: Object[]
Parameter Sets: (All)
Aliases: Path

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-Server

The explicit DNS name of the final writable domain controller. When it is omitted, one writable domain controller is located in the current computer's domain and pinned for the whole command.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed immutable object targets from 1 through 64.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-TimeoutSeconds

Sets the LDAP request timeout from 1 through 300 seconds.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: 10
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

WindowsAccessControl.ADObjectSecurityDescriptor

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally