Skip to content

Remove‑RegistryKeyAuditRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Removes an exact audit rule from a local registry key.

SYNTAX

Rule (Default)

Remove-RegistryKeyAuditRule -InputObject <PSObject> [-PassThru] [-WhatIf]
 [-Confirm] [<CommonParameters>]

SecurityDescriptor

Remove-RegistryKeyAuditRule -SecurityDescriptor <PSObject> -Rule <PSObject> [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

DESCRIPTION

Accepts a path-bound registry audit rule from the pipeline, removes the matching explicit SACL ACE only, and preserves every unrelated ACE.

EXAMPLES

EXAMPLE 1

Get-RegistryKeyAuditRule HKCU:\Software -ExcludeInherited | Remove-RegistryKeyAuditRule -WhatIf

Previews exact removal of each explicit pipeline audit rule.

PARAMETERS

-InputObject

A path-bound rule returned by Get-RegistryKeyAuditRule.

Type: PSObject
Parameter Sets: Rule
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByValue)
Accept wildcard characters: False

-PassThru

Returns the removed rule after successful persistence.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Rule

The rule returned by Get-RegistryKeyAuditRule whose exact ACE is removed from the supplied descriptor.

Type: PSObject
Parameter Sets: SecurityDescriptor
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-SecurityDescriptor

A WindowsAccessControl.RegistryKeySecurityDescriptor object returned by Get-RegistryKeySecurityDescriptor with the Audit section loaded. When supplied, the removal is staged on the descriptor in memory and the descriptor is returned; nothing is written until Set-RegistryKeySecurityDescriptor persists it.

Type: PSObject
Parameter Sets: SecurityDescriptor
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByValue)
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

WindowsAccessControl.RegistryKeyAuditRule

WindowsAccessControl.RegistryKeySecurityDescriptor

OUTPUTS

None

WindowsAccessControl.RegistryKeyAuditRule

WindowsAccessControl.RegistryKeySecurityDescriptor

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally