Skip to content

Get‑RegistryKeyAuditRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Gets audit rules from local registry keys.

SYNTAX

Get-RegistryKeyAuditRule [-Path] <Object[]> [-RegistryView <WindowsRegistryView>] [-Account <Object[]>]
 [-ExcludeInherited] [-ExcludeExplicit] [-ThrottleLimit <Int32>] 
 [<CommonParameters>]

DESCRIPTION

Reads registry-key SACLs under a scoped security privilege and emits structured audit rules with account, SID, registry rights, audit flags, inheritance scope, and native ACE.

EXAMPLES

EXAMPLE 1

Get-RegistryKeyAuditRule -Path HKCU:\Software -ExcludeInherited

Gets explicit audit rules from the Software key.

PARAMETERS

-Account

Filters rules by account names, SID strings, or module identity output.

Type: Object[]
Parameter Sets: (All)
Aliases: IdentityReference, ID

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ExcludeExplicit

Excludes explicit rules and returns only inherited registry audit ACEs.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-ExcludeInherited

Excludes inherited rules and returns only explicit registry audit ACEs.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Path

One or more local registry key paths or RegistryKey pipeline objects.

Type: Object[]
Parameter Sets: (All)
Aliases: PSPath

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-RegistryView

Selects the default, 32-bit, or 64-bit registry view explicitly.

Type: WindowsRegistryView
Parameter Sets: (All)
Aliases:
Accepted values: Default, Registry32, Registry64

Required: False
Position: Named
Default value: Default
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical targets. One requests deterministic sequential execution.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

Microsoft.Win32.RegistryKey

OUTPUTS

WindowsAccessControl.RegistryKeyAuditRule

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally