Skip to content

Remove‑ADObjectAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Removes explicit Active Directory access rules.

SYNTAX

Rule (Default)

Remove-ADObjectAccessRule -InputObject <PSObject> -AllowedBaseDistinguishedName <String>
 [-Credential <PSCredential>] [-TimeoutSeconds <Int32>] [-PassThru] 
 [-WhatIf] [-Confirm] [<CommonParameters>]

Target

Remove-ADObjectAccessRule [-Server <String>] [-DistinguishedName] <Object[]>
 -AllowedBaseDistinguishedName <String> [-Credential <PSCredential>] -Account <Object[]>
 [-AccessRights <Object>] [-AccessControlType <AccessControlType>]
 [-InheritanceType <WindowsActiveDirectoryInheritance>] [-ObjectType <String>] [-InheritedObjectType <String>]
 [-RemovalMode <String>] [-TimeoutSeconds <Int32>] [-ThrottleLimit <Int32>] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

DESCRIPTION

Removes one exact piped rule by default. Target-based calls can remove an exact rule, subtract a rights mask, or purge every explicit rule for an account. Every mode revalidates server, allowed OU, distinguished name, and object GUID, and preserves unrelated object ACEs.

EXAMPLES

EXAMPLE 1

Get-ADObjectAccessRule -Server dc01.example.test -DistinguishedName $dn -Account $sid | Remove-ADObjectAccessRule -AllowedBaseDistinguishedName $ou -WhatIf

Previews exact removal of the selected directory ACE.

EXAMPLE 2

Remove-ADObjectAccessRule -DistinguishedName $dn -AllowedBaseDistinguishedName $ou -Account $sid -RemovalMode All

Purges every explicit directory ACE for one account inside the allowed OU.

EXAMPLE 3

Remove-ADObjectAccessRule -DistinguishedName $dn -AllowedBaseDistinguishedName $ou -Account $sid -AccessRights WriteProperty -RemovalMode Rights -Confirm:$false

Subtracts write-property from matching explicit ACEs for the account, leaving any other rights on the same ACE in place.

EXAMPLE 4

Remove-ADObjectAccessRule -DistinguishedName $ou -AllowedBaseDistinguishedName $ou -Account $sid -AccessRights ReadProperty -ObjectType 'employeeID' -InheritedObjectType 'user' -InheritanceType Descendents -Confirm:$false

Removes only the employeeID-scoped read-property ACE, leaving a common ReadProperty ACE for the same account untouched.

PARAMETERS

-AccessControlType

Selects whether an allow or deny rule is removed.

Type: AccessControlType
Parameter Sets: Target
Aliases:
Accepted values: Allow, Deny

Required: False
Position: Named
Default value: Allow
Accept pipeline input: False
Accept wildcard characters: False

-AccessRights

The rights used for Exact or Rights removal modes.

Type: Object
Parameter Sets: Target
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Account

One or more account names, SIDs, identity references, or module identities.

Type: Object[]
Parameter Sets: Target
Aliases: IdentityReference, ID

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-AllowedBaseDistinguishedName

The organizational unit that bounds the permitted mutation.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Credential

An optional credential used only for the direct LDAP bind to the rule server.

Type: PSCredential
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-DistinguishedName

One or more distinguished names to modify.

Type: Object[]
Parameter Sets: Target
Aliases: Path

Required: True
Position: 1
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-InheritanceType

Selects the directory inheritance matched by Exact mode.

Type: WindowsActiveDirectoryInheritance
Parameter Sets: Target
Aliases:
Accepted values: None, All, Descendents, SelfAndChildren, Children

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-InheritedObjectType

Selects the inherited object-class GUID scope to match, or the schema class name that identifies it.

Type: String
Parameter Sets: Target
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-InputObject

A path-bound rule returned by Get-ADObjectAccessRule.

Type: PSObject
Parameter Sets: Rule
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByValue)
Accept wildcard characters: False

-ObjectType

Selects the object, property, or extended-right GUID scope to match, or the schema class, attribute, property set, validated write, or extended right name that identifies it.

Type: String
Parameter Sets: Target
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-PassThru

Returns the removed rules after successful persistence.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-RemovalMode

Exact removes only an identical ACE, Rights subtracts matching rights from explicit ACEs with the same object scope, and All purges every explicit ACE for the selected account, including deny rules.

Type: String
Parameter Sets: Target
Aliases:

Required: False
Position: Named
Default value: Exact
Accept pipeline input: False
Accept wildcard characters: False

-Server

The explicit DNS name of the final writable domain controller. When it is omitted, one writable domain controller is located in the current computer's domain and pinned for the whole command.

Type: String
Parameter Sets: Target
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed immutable object targets from 1 through 64.

Type: Int32
Parameter Sets: Target
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-TimeoutSeconds

Sets the LDAP request timeout from 1 through 300 seconds.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: 10
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

WindowsAccessControl.ADObjectAccessRule

System.String

OUTPUTS

None

WindowsAccessControl.ADObjectAccessRule

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally