Skip to content

Set‑RegistryKeySecurityDescriptor

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Sets selected security descriptor sections on local registry keys.

SYNTAX

SecurityDescriptor (Default)

Set-RegistryKeySecurityDescriptor -SecurityDescriptor <PSObject> [-RequireUnchanged] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

Sddl

Set-RegistryKeySecurityDescriptor [-Path] <Object[]> -Sddl <String> [-RegistryView <WindowsRegistryView>]
 [-Sections <WindowsSecurityDescriptorSection>] [-ThrottleLimit <Int32>] [-PassThru]
 [-WhatIf] [-Confirm] [<CommonParameters>]

DESCRIPTION

Parses SDDL as data and persists only the selected owner, group, DACL, or SACL sections to local registry keys while honoring PowerShell confirmation and preview semantics.

EXAMPLES

EXAMPLE 1

Set-RegistryKeySecurityDescriptor -Path HKCU:\Software -Sddl 'D:(A;;KR;;;WD)' -Sections Access -WhatIf

Previews replacing only the Software key DACL.

EXAMPLE 2

Get-RegistryKeySecurityDescriptor -Path HKCU:\Software -Sections Access |
    Add-RegistryKeyAccessRule -Account Everyone -AccessRights ReadKey |
    Set-RegistryKeySecurityDescriptor

Stages a read rule in memory and persists the DACL with one write.

PARAMETERS

-PassThru

Returns the updated selected descriptor sections after persistence.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Path

One or more local registry key paths or RegistryKey objects supplied directly or through the pipeline.

Type: Object[]
Parameter Sets: Sddl
Aliases: PSPath

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-RegistryView

Selects the default, 32-bit, or 64-bit registry view explicitly.

Type: WindowsRegistryView
Parameter Sets: Sddl
Aliases:
Accepted values: Default, Registry32, Registry64

Required: False
Position: Named
Default value: Default
Accept pipeline input: False
Accept wildcard characters: False

-RequireUnchanged

Rejects the write when the selected sections of the live key no longer match the ConcurrencyToken recorded when the descriptor was read. The default is last-writer-wins.

Type: SwitchParameter
Parameter Sets: SecurityDescriptor
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Sddl

A structurally valid SDDL document containing every selected section.

Type: String
Parameter Sets: Sddl
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-Sections

Selects the descriptor sections to persist from the SDDL document.

Type: WindowsSecurityDescriptorSection
Parameter Sets: Sddl
Aliases:
Accepted values: Owner, Group, Access, Audit, All

Required: False
Position: Named
Default value: All
Accept pipeline input: False
Accept wildcard characters: False

-SecurityDescriptor

A WindowsAccessControl.RegistryKeySecurityDescriptor object returned by Get-RegistryKeySecurityDescriptor, optionally after in-memory edits. Its recorded target, registry view, and selected sections are used.

Type: PSObject
Parameter Sets: SecurityDescriptor
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByValue)
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical targets. One requests deterministic sequential execution.

Type: Int32
Parameter Sets: Sddl
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

Microsoft.Win32.RegistryKey

WindowsAccessControl.RegistryKeySecurityDescriptor

OUTPUTS

None

WindowsAccessControl.RegistryKeySecurityDescriptor

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally