Skip to content

Remove‑NTFSAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Removes NTFS access rules from files or directories.

SYNTAX

Rule (Default)

Remove-NTFSAccessRule -InputObject <PSObject> [-RemovalMode <String>] [-ThrottleLimit <Int32>] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

Path

Remove-NTFSAccessRule [-Path] <String[]> -Account <String> [-AccessRights <Object>]
 [-AccessControlType <AccessControlType>] [-AppliesTo <String>] [-RemovalMode <String>]
 [-ThrottleLimit <Int32>] [-PassThru] [-WhatIf] [-Confirm]
 [<CommonParameters>]

LiteralPath

Remove-NTFSAccessRule -LiteralPath <String[]> -Account <String> [-AccessRights <Object>]
 [-AccessControlType <AccessControlType>] [-AppliesTo <String>] [-RemovalMode <String>]
 [-ThrottleLimit <Int32>] [-PassThru] [-WhatIf] [-Confirm]
 [<CommonParameters>]

SecurityDescriptor

Remove-NTFSAccessRule -SecurityDescriptor <PSObject> -Account <String> [-AccessRights <Object>]
 [-AccessControlType <AccessControlType>] [-AppliesTo <String>] [-RemovalMode <String>]
 [-ThrottleLimit <Int32>] [-PassThru] [-WhatIf] [-Confirm]
 [<CommonParameters>]

DESCRIPTION

Removes an exact piped rule by default. Path-based calls can remove an exact rule, subtract a rights mask, or purge every access rule for an account. Inherited rules cannot be removed from a child item.

EXAMPLES

EXAMPLE 1

Get-NTFSAccessRule -LiteralPath C:\Data -ExcludeInherited | Remove-NTFSAccessRule

Removes each explicit rule returned for C:\Data.

PARAMETERS

-AccessControlType

Selects whether an allow or deny rule is removed.

Type: AccessControlType
Parameter Sets: Path, LiteralPath, SecurityDescriptor
Aliases:
Accepted values: Allow, Deny

Required: False
Position: Named
Default value: Allow
Accept pipeline input: False
Accept wildcard characters: False

-AccessRights

The rights used for Exact or Rights removal modes. A raw access mask is also accepted as a decimal number or a hexadecimal string, which is how an entry carrying generic rights is removed.

Type: Object
Parameter Sets: Path, LiteralPath, SecurityDescriptor
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Account

The account name or SID whose access rule is removed.

Type: String
Parameter Sets: Path, LiteralPath, SecurityDescriptor
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-AppliesTo

Selects the inheritance and propagation flags matched by Exact mode.

Type: String
Parameter Sets: Path, LiteralPath, SecurityDescriptor
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-InputObject

An access-rule object returned by Get-NTFSAccessRule or New-NTFSAccessRule. Rules returned by Get include their target path.

Type: PSObject
Parameter Sets: Rule
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByValue)
Accept wildcard characters: False

-LiteralPath

One or more filesystem paths used exactly as supplied.

Type: String[]
Parameter Sets: LiteralPath
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-PassThru

Returns the rule object representing the requested removal.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Path

One or more filesystem paths. Wildcards are expanded by the FileSystem provider.

Type: String[]
Parameter Sets: Path
Aliases:

Required: True
Position: 1
Default value: None
Accept pipeline input: False
Accept wildcard characters: True

-RemovalMode

Exact removes only an identical ACE, Rights subtracts matching rights, and All purges every ACE for the selected account.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: Exact
Accept pipeline input: False
Accept wildcard characters: False

-SecurityDescriptor

A WindowsAccessControl.SecurityDescriptor object returned by Get-NTFSItemSecurityDescriptor. When supplied, the removal is staged on the descriptor in memory and the descriptor is returned; nothing is written until Set-NTFSItemSecurityDescriptor persists it.

Type: PSObject
Parameter Sets: SecurityDescriptor
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByValue)
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical paths for path-based calls. One requests deterministic sequential execution. Piped rule objects remain scalar.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

WindowsAccessControl.AccessRule

WindowsAccessControl.SecurityDescriptor

OUTPUTS

None

WindowsAccessControl.AccessRule

WindowsAccessControl.SecurityDescriptor

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally