Skip to content

Set‑NTFSAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Replaces matching NTFS access rules.

SYNTAX

Path (Default)

Set-NTFSAccessRule [-Path] <String[]> -Account <String> -AccessRights <Object>
 [-AccessControlType <AccessControlType>] [-AppliesTo <String>] [-ThrottleLimit <Int32>] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

LiteralPath

Set-NTFSAccessRule -LiteralPath <String[]> -Account <String> -AccessRights <Object>
 [-AccessControlType <AccessControlType>] [-AppliesTo <String>] [-ThrottleLimit <Int32>] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

SecurityDescriptor

Set-NTFSAccessRule -SecurityDescriptor <PSObject> -Account <String> -AccessRights <Object>
 [-AccessControlType <AccessControlType>] [-AppliesTo <String>] [-ThrottleLimit <Int32>] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

DESCRIPTION

Removes access rules with the same account and allow or deny qualifier, then adds the specified rule. Rules with the opposite qualifier and rules for other accounts are preserved.

EXAMPLES

EXAMPLE 1

Set-NTFSAccessRule -LiteralPath C:\Data -Account 'CONTOSO\Analysts' -AccessRights Modify

Replaces allow rules for the Analysts group with a Modify rule.

EXAMPLE 2

Get-NTFSItemSecurityDescriptor -LiteralPath C:\Data -Sections Access |
    Set-NTFSAccessRule -Account 'CONTOSO\Analysts' -AccessRights Modify |
    Set-NTFSItemSecurityDescriptor

Stages the replacement in memory and persists it with one write.

PARAMETERS

-AccessControlType

Selects the allow or deny qualifier that is replaced.

Type: AccessControlType
Parameter Sets: (All)
Aliases:
Accepted values: Allow, Deny

Required: False
Position: Named
Default value: Allow
Accept pipeline input: False
Accept wildcard characters: False

-AccessRights

The filesystem rights for the replacement access rule. A raw access mask is also accepted as a decimal number or a hexadecimal string, so bits the FileSystemRights enumeration cannot name, such as the generic rights, can be used.

Type: Object
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Account

The account name or SID whose matching access rules are replaced.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-AppliesTo

Specifies how a directory rule applies to the directory and its child files or directories. Files default to ThisFolderOnly.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-LiteralPath

One or more filesystem paths used exactly as supplied. FileSystem objects bind to this parameter through their PSPath property.

Type: String[]
Parameter Sets: LiteralPath
Aliases: PSPath

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-PassThru

Returns the replacement access rule after it is persisted.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Path

One or more filesystem paths. Wildcards are expanded by the FileSystem provider, and path strings can be supplied through the pipeline.

Type: String[]
Parameter Sets: Path
Aliases: FullName

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: True

-SecurityDescriptor

A WindowsAccessControl.SecurityDescriptor object returned by Get-NTFSItemSecurityDescriptor. When supplied, matching rules are replaced on the descriptor in memory and the descriptor is returned; nothing is written until Set-NTFSItemSecurityDescriptor persists it.

Type: PSObject
Parameter Sets: SecurityDescriptor
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByValue)
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical paths. One requests deterministic sequential execution.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

System.IO.FileSystemInfo

WindowsAccessControl.SecurityDescriptor

OUTPUTS

None

WindowsAccessControl.AccessRule

WindowsAccessControl.SecurityDescriptor

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally