Skip to content

New‑NTFSAuditRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Creates a reusable NTFS audit rule.

SYNTAX

New-NTFSAuditRule [-Account] <String[]> [-AccessRights] <Object> [-AuditFlags] <AuditFlags>
 [[-AppliesTo] <String>] [<CommonParameters>]

DESCRIPTION

Creates an in-memory audit rule with an account, rights, success or failure flags, and an Explorer-style inheritance scope.

EXAMPLES

EXAMPLE 1

New-NTFSAuditRule -Account 'CONTOSO\Analysts' -AccessRights Write -AuditFlags Failure

Creates a rule that audits failed write attempts by the Analysts group.

PARAMETERS

-AccessRights

The filesystem rights represented by the new audit rule. A raw access mask is also accepted as a decimal number or a hexadecimal string, so bits the FileSystemRights enumeration cannot name, such as the generic rights, can be used.

Type: Object
Parameter Sets: (All)
Aliases:

Required: True
Position: 2
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Account

The account name or SID to which the new audit rule applies.

Type: String[]
Parameter Sets: (All)
Aliases:

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByValue)
Accept wildcard characters: False

-AppliesTo

Specifies how the rule applies to a directory and its child files or directories using names that correspond to Windows Explorer.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: 4
Default value: ThisFolderSubfoldersAndFiles
Accept pipeline input: False
Accept wildcard characters: False

-AuditFlags

Specifies whether successful access, failed access, or both are audited.

Type: AuditFlags
Parameter Sets: (All)
Aliases:
Accepted values: None, Success, Failure

Required: True
Position: 3
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

WindowsAccessControl.AuditRule

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally