Skip to content

Set‑ADObjectSecurityDescriptor

raandree edited this page Sep 7, 2026 · 2 revisions

SYNOPSIS

Sets DACL descriptors on bounded Active Directory objects.

SYNTAX

Set-ADObjectSecurityDescriptor [-Server <String>] [-DistinguishedName] <Object[]>
 -AllowedBaseDistinguishedName <String> -Sddl <String> [-ExpectedObjectGuid <Guid>]
 [-Credential <PSCredential>] [-TimeoutSeconds <Int32>] [-ThrottleLimit <Int32>] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

DESCRIPTION

Validates SDDL, immutable object identity, protected-target rules, and an explicit allowed OU before replacing only the target DACL over LDAP.

EXAMPLES

EXAMPLE 1

Set-ADObjectSecurityDescriptor -Server dc01.example.test -DistinguishedName $dn -AllowedBaseDistinguishedName $ou -Sddl $sddl -WhatIf

Previews replacing only the selected object's DACL.

PARAMETERS

-AllowedBaseDistinguishedName

The organizational unit that bounds every permitted mutation.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Credential

An optional credential used only for the direct LDAP bind to Server.

Type: PSCredential
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-DistinguishedName

One or more distinguished names to modify.

Type: Object[]
Parameter Sets: (All)
Aliases: Path

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-ExpectedObjectGuid

Requires the target to retain this immutable object GUID. Restore uses this value to reject a distinguished name reused after preparation.

Type: Guid
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [guid]::Empty
Accept pipeline input: False
Accept wildcard characters: False

-PassThru

Returns the stored DACL descriptor after persistence.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Sddl

A structurally valid SDDL document containing a non-null DACL.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Server

The explicit DNS name of the final writable domain controller. When it is omitted, one writable domain controller is located in the current computer's domain and pinned for the whole command.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed immutable object targets from 1 through 64.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-TimeoutSeconds

Sets the LDAP request timeout from 1 through 300 seconds.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: 10
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

None

WindowsAccessControl.ADObjectSecurityDescriptor

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally