Skip to content

Get‑SmbShareEffectiveAccess

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Gets bounded share-only effective access for local SMB shares.

SYNTAX

Get-SmbShareEffectiveAccess [-Name] <Object[]> [-Account <String>] [-AccessRights <WindowsSmbShareRights>]
 [-ThrottleLimit <Int32>] [<CommonParameters>]

DESCRIPTION

Evaluates a local SMB share DACL through Windows Authz using a SID-derived context. The result excludes the backing NTFS DACL and can omit logon-specific groups. It is not a remote or combined access claim.

EXAMPLES

EXAMPLE 1

Get-SmbShareEffectiveAccess -Name 'Data$' `
    -Account 'CONTOSO\Analysts' `
    -AccessRights Read

Evaluates the local Data share DACL only for the Analysts SID context.

PARAMETERS

-AccessRights

Optional share rights to test against the granted mask. IsAllowed is null when no requested rights are supplied.

Type: WindowsSmbShareRights
Parameter Sets: (All)
Aliases:
Accepted values: Delete, ReadControl, WriteDac, WriteOwner, Synchronize, Read, Change, Full, AccessSystemSecurity, GenericAll, GenericExecute, GenericWrite, GenericRead

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Account

The account name or SID evaluated by Authz. The current process identity is used when this parameter is omitted.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Name

One or more unqualified ordinary local SMB share names.

Type: Object[]
Parameter Sets: (All)
Aliases: ShareName

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical share targets from 1 to 64.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

WindowsAccessControl.SmbShareEffectiveAccess

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally