Skip to content

Set‑ADObjectAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Replaces typed access rules in bounded Active Directory object DACLs.

SYNTAX

Set-ADObjectAccessRule [-Server <String>] [-DistinguishedName] <Object[]>
 -AllowedBaseDistinguishedName <String> [-Credential <PSCredential>] -Account <Object[]> -AccessRights <Object>
 [-AccessControlType <AccessControlType>] [-InheritanceType <WindowsActiveDirectoryInheritance>]
 [-ObjectType <String>] [-InheritedObjectType <String>] [-TimeoutSeconds <Int32>] [-ThrottleLimit <Int32>]
 [-PassThru] [-WhatIf] [-Confirm] [<CommonParameters>]

DESCRIPTION

Prevalidates identities and a disposable OU boundary, replaces every explicit ACE that shares the same account, qualifier, and object GUIDs with one new ACE, and revalidates object GUID before LDAP write. ACEs with a different object scope are preserved rather than flattened.

EXAMPLES

EXAMPLE 1

Set-ADObjectAccessRule -Server dc01.example.test -DistinguishedName $dn -AllowedBaseDistinguishedName $ou -Account $sid -AccessRights ReadProperty -WhatIf

Previews replacing every explicit common ACE for the account inside the allowed OU.

EXAMPLE 2

Set-ADObjectAccessRule -DistinguishedName $dn -AllowedBaseDistinguishedName $ou -Account 'CONTOSO\Analysts', 'CONTOSO\Auditors' -AccessRights 'ReadProperty, WriteProperty' -Confirm:$false

Replaces the common ACE for two groups with the same replacement rights.

EXAMPLE 3

Set-ADObjectAccessRule -DistinguishedName $ou -AllowedBaseDistinguishedName $ou -Account $sid -AccessRights ReadProperty -ObjectType 'employeeID' -InheritanceType Descendents -InheritedObjectType 'user' -Confirm:$false

Replaces every explicit employeeID-scoped ACE for the account with a single read-only ACE, leaving ACEs scoped to other attributes and any common ACE for the same account untouched.

EXAMPLE 4

Set-ADObjectAccessRule -DistinguishedName $dn -AllowedBaseDistinguishedName $ou -Account 'CONTOSO\Contractors' -AccessRights WriteProperty -AccessControlType Deny -Confirm:$false -PassThru

Replaces the contractors group's explicit deny ACE so it denies only write-property, and returns the stored rule.

PARAMETERS

-AccessControlType

Replaces Allow rules by default or explicit Deny rules.

Type: AccessControlType
Parameter Sets: (All)
Aliases:
Accepted values: Allow, Deny

Required: False
Position: Named
Default value: Allow
Accept pipeline input: False
Accept wildcard characters: False

-AccessRights

Active Directory rights that replace the current rights.

Type: Object
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Account

One or more account names, SIDs, identity references, or module identities.

Type: Object[]
Parameter Sets: (All)
Aliases: IdentityReference, ID

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-AllowedBaseDistinguishedName

The organizational unit that bounds every permitted mutation.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Credential

An optional credential used only for the direct LDAP bind to Server.

Type: PSCredential
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-DistinguishedName

One or more distinguished names to modify.

Type: Object[]
Parameter Sets: (All)
Aliases: Path

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-InheritanceType

Controls directory inheritance for the replacement ACE.

Type: WindowsActiveDirectoryInheritance
Parameter Sets: (All)
Aliases:
Accepted values: None, All, Descendents, SelfAndChildren, Children

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-InheritedObjectType

Optionally scopes inherited application to an object-class GUID or to the schema class name that identifies it.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ObjectType

Optionally scopes the ACE to an object, property, or extended-right GUID, or to the schema class, attribute, property set, validated write, or extended right name that identifies it.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-PassThru

Returns the stored explicit access rule after persistence.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Server

The explicit DNS name of the final writable domain controller. When it is omitted, one writable domain controller is located in the current computer's domain and pinned for the whole command.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed immutable object targets from 1 through 64.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-TimeoutSeconds

Sets the LDAP request timeout from 1 through 300 seconds.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: 10
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

None

WindowsAccessControl.ADObjectAccessRule

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally