Skip to content

Get‑RegistryKeyAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Gets access rules from local registry keys.

SYNTAX

Get-RegistryKeyAccessRule [-Path] <Object[]> [-RegistryView <WindowsRegistryView>] [-Account <Object[]>]
 [-ExcludeInherited] [-ExcludeExplicit] [-ThrottleLimit <Int32>] 
 [<CommonParameters>]

DESCRIPTION

Reads registry-key DACLs and emits structured allow or deny rules with account, SID, typed registry rights, inheritance scope, and native ACE. Inherited rules expose InheritedFrom with the ancestor key reported by the Windows inheritance-source API. It is empty for explicit rules, for inherited rules whose source Windows cannot identify, and for the Registry32 and Registry64 views, which Windows does not support.

EXAMPLES

EXAMPLE 1

Get-RegistryKeyAccessRule -Path HKCU:\Software -ExcludeInherited

Gets explicit access rules from the Software key.

PARAMETERS

-Account

Filters rules by account names, SID strings, or module identity output.

Type: Object[]
Parameter Sets: (All)
Aliases: IdentityReference, ID

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ExcludeExplicit

Excludes explicit rules and returns only inherited registry ACEs.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-ExcludeInherited

Excludes inherited rules and returns only explicit registry ACEs.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Path

One or more local registry key paths or RegistryKey pipeline objects.

Type: Object[]
Parameter Sets: (All)
Aliases: PSPath

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-RegistryView

Selects the default, 32-bit, or 64-bit registry view explicitly.

Type: WindowsRegistryView
Parameter Sets: (All)
Aliases:
Accepted values: Default, Registry32, Registry64

Required: False
Position: Named
Default value: Default
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical targets. One requests deterministic sequential execution.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

Microsoft.Win32.RegistryKey

OUTPUTS

WindowsAccessControl.RegistryKeyAccessRule

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally