Skip to content

Set‑ScheduledTaskSecurityDescriptor

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Sets DACL descriptors on contained local registered tasks.

SYNTAX

Set-ScheduledTaskSecurityDescriptor [-TaskPath] <Object[]> -TaskName <String> -AllowedRootPath <String>
 -Sddl <String> [-ThrottleLimit <Int32>] [-PassThru] [-WhatIf] [-Confirm]
 [<CommonParameters>]

DESCRIPTION

Persists only the DACL through the local Task Scheduler COM API with TASK_DONT_ADD_PRINCIPAL_ACE. The target must be inside AllowedRootPath, and the candidate must preserve every current SYSTEM ACE. The Task Scheduler service reorders ACEs, so ACE order is neither preserved nor verified; do not rely on this command to canonicalize a non-canonical DACL.

EXAMPLES

EXAMPLE 1

Set-ScheduledTaskSecurityDescriptor -TaskPath '\Operations' `
    -TaskName 'Cleanup' -AllowedRootPath '\Operations' `
    -Sddl $sddl -WhatIf

Previews a contained local task DACL write.

PARAMETERS

-AllowedRootPath

The explicit non-system folder boundary containing every write target.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-PassThru

Returns the verified DACL descriptor after persistence.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Sddl

A valid SDDL document containing a non-null DACL.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-TaskName

The exact leaf name of the registered task in each supplied folder.

Type: String
Parameter Sets: (All)
Aliases:

Required: True
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-TaskPath

One or more absolute local Task Scheduler parent-folder paths.

Type: Object[]
Parameter Sets: (All)
Aliases:

Required: True
Position: 1
Default value: None
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical task targets from 1 to 64.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

-Confirm

Prompts you for confirmation before running the cmdlet.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: cf

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

-WhatIf

Shows what would happen if the cmdlet runs. The cmdlet is not run.

Type: SwitchParameter
Parameter Sets: (All)
Aliases: wi

Required: False
Position: Named
Default value: None
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

OUTPUTS

None

WindowsAccessControl.ScheduledTaskSecurityDescriptor

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally