Repository navigation
Restore‑WindowsSecurityDescriptor
Restores Windows security descriptors from a unified JSON backup.
Restore-WindowsSecurityDescriptor [-BackupPath] <String> [-VerificationCertificate <X509Certificate2>]
[-Server <String>] [-AllowedBaseDistinguishedName <String>] [-AllowedRootPath <String>]
[-Credential <PSCredential>] [-TimeoutSeconds <Int32>] [-PassThru]
[-WhatIf] [-Confirm] [<CommonParameters>]
Parses a versioned backup as data, validates every record and SHA-256 digest, resolves every target, and only then restores the selected descriptor sections. Invalid later records fail before the first write. Schema version 2 additionally restores SMB share records on their originating computer and Active Directory records through one pinned writable domain controller inside an explicit allowed organizational unit, matched by immutable object GUID and domain partition. Task Scheduler records restore on their originating computer inside an explicit allowed root path. Certificate private-key records restore on their originating computer, relocate the key by provider, key name, and key scope, and pass through the same fail-closed write gates as every other private-key write.
Restore-WindowsSecurityDescriptor `
-BackupPath C:\Backup\acl.json `
-Confirm:$false
Verifies and restores every record in the unified backup.
The organizational unit that bounds every Active Directory restore. It is required when the backup contains Active Directory records.
Type: String
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: FalseThe non-system task folder that bounds every Task Scheduler restore. It is required when the backup contains Task Scheduler records.
Type: String
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: FalseThe literal path to a unified backup created by Backup-WindowsSecurityDescriptor.
Type: String
Parameter Sets: (All)
Aliases:
Required: True
Position: 1
Default value: None
Accept pipeline input: False
Accept wildcard characters: FalseAn optional credential used only for the direct LDAP bind to Server.
Type: PSCredential
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: FalseReturns each restored security descriptor after persistence.
Type: SwitchParameter
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: FalseThe explicit DNS name of the writable domain controller used for every Active Directory record. When it is omitted, one writable domain controller is located in the current computer's domain and pinned.
Type: String
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: FalseSets the LDAP request timeout from 1 through 300 seconds.
Type: Int32
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: 10
Accept pipeline input: False
Accept wildcard characters: FalseThe RSA X.509 certificate required to verify every signed record.
Type: X509Certificate2
Parameter Sets: (All)
Aliases:
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: FalsePrompts you for confirmation before running the cmdlet.
Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: FalseShows what would happen if the cmdlet runs. The cmdlet is not run.
Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi
Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: FalseThis cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.
- Add-ADObjectAccessRule
- Add-CertificatePrivateKeyAccessRule
- Add-NTFSAccessRule
- Add-NTFSAuditRule
- Add-ProcessAccessRule
- Add-ProcessAuditRule
- Add-RegistryKeyAccessRule
- Add-RegistryKeyAuditRule
- Add-ScheduledTaskAccessRule
- Add-ServiceAccessRule
- Add-ServiceAuditRule
- Add-SmbShareAccessRule
- Add-TaskFolderAccessRule
- Backup-NTFSItemSecurityDescriptor
- Backup-WindowsSecurityDescriptor
- Clear-ADObjectAccessRule
- Clear-NTFSAccessRule
- Clear-NTFSAuditRule
- Clear-ProcessAccessRule
- Clear-ProcessAuditRule
- Clear-RegistryKeyAccessRule
- Clear-RegistryKeyAuditRule
- Clear-ServiceAccessRule
- Clear-ServiceAuditRule
- Copy-NTFSItemSecurityDescriptor
- Disable-NTFSItemInheritance
- Disable-RegistryKeyInheritance
- Disable-WindowsPrivilege
- Edit-NTFSItemSecurityDescriptor
- Edit-RegistryKeySecurityDescriptor
- Enable-NTFSItemInheritance
- Enable-RegistryKeyInheritance
- Enable-WindowsPrivilege
- Get-ADObjectAccessRule
- Get-ADObjectCallerEffectiveAccess
- Get-ADObjectSchemaDefaultAccessRule
- Get-ADObjectSecurityDescriptor
- Get-CertificatePrivateKeyAccessRule
- Get-CertificatePrivateKeySecurityDescriptor
- Get-NTFSAccessRule
- Get-NTFSAuditRule
- Get-NTFSItemEffectiveAccess
- Get-NTFSItemInheritance
- Get-NTFSItemOwner
- Get-NTFSItemSecurityDescriptor
- Get-ProcessAccessRule
- Get-ProcessAuditRule
- Get-ProcessSecurityDescriptor
- Get-RegistryKeyAccessRule
- Get-RegistryKeyAuditRule
- Get-RegistryKeyInheritance
- Get-RegistryKeySecurityDescriptor
- Get-ScheduledTaskAccessRule
- Get-ScheduledTaskSecurityDescriptor
- Get-ServiceAccessRule
- Get-ServiceAuditRule
- Get-ServiceSecurityDescriptor
- Get-SmbShareAccessRule
- Get-SmbShareEffectiveAccess
- Get-SmbShareSecurityDescriptor
- Get-TaskFolderAccessRule
- Get-TaskFolderSecurityDescriptor
- Get-WindowsAccessControlMetric
- Get-WindowsPrivilege
- Invoke-WindowsAccessControl
- New-NTFSAccessRule
- New-NTFSAuditRule
- Remove-ADObjectAccessRule
- Remove-CertificatePrivateKeyAccessRule
- Remove-NTFSAccessRule
- Remove-NTFSAuditRule
- Remove-ProcessAccessRule
- Remove-ProcessAuditRule
- Remove-RegistryKeyAccessRule
- Remove-RegistryKeyAuditRule
- Remove-ScheduledTaskAccessRule
- Remove-ServiceAccessRule
- Remove-ServiceAuditRule
- Remove-SmbShareAccessRule
- Remove-TaskFolderAccessRule
- Resolve-WindowsIdentity
- Restore-NTFSItemSecurityDescriptor
- Restore-WindowsSecurityDescriptor
- Set-ADObjectAccessRule
- Set-ADObjectSecurityDescriptor
- Set-CertificatePrivateKeySecurityDescriptor
- Set-NTFSAccessRule
- Set-NTFSAuditRule
- Set-NTFSItemOwner
- Set-NTFSItemSecurityDescriptor
- Set-ProcessAccessRule
- Set-ProcessAuditRule
- Set-ProcessSecurityDescriptor
- Set-RegistryKeyAccessRule
- Set-RegistryKeyAuditRule
- Set-RegistryKeySecurityDescriptor
- Set-ScheduledTaskSecurityDescriptor
- Set-ServiceAccessRule
- Set-ServiceAuditRule
- Set-ServiceSecurityDescriptor
- Set-SmbShareSecurityDescriptor
- Set-TaskFolderSecurityDescriptor
- Test-CertificatePrivateKeyCriticalBinding
- Test-NTFSItemAcl
- Test-WindowsPrivilege
- WindowsAccessControlADObjectAccessRule
- WindowsAccessControlADObjectSecurityDescriptor
- WindowsAccessControlCertificatePrivateKeyAccessRule
- WindowsAccessControlCertificatePrivateKeySecurityDescriptor
- WindowsAccessControlNtfsAccessRule
- WindowsAccessControlNtfsSecurityDescriptor
- WindowsAccessControlProcessAccessRule
- WindowsAccessControlProcessSecurityDescriptor
- WindowsAccessControlRegistryKeyAccessRule
- WindowsAccessControlRegistryKeySecurityDescriptor
- WindowsAccessControlScheduledTaskAccessRule
- WindowsAccessControlScheduledTaskSecurityDescriptor
- WindowsAccessControlServiceAccessRule
- WindowsAccessControlServiceControlManagerAccessRule
- WindowsAccessControlServiceControlManagerSecurityDescriptor
- WindowsAccessControlServiceSecurityDescriptor
- WindowsAccessControlSmbShareAccessRule
- WindowsAccessControlSmbShareSecurityDescriptor
- WindowsAccessControlTaskFolderAccessRule
- WindowsAccessControlTaskFolderSecurityDescriptor