Skip to content

Test‑NTFSItemAcl

raandree edited this page Sep 6, 2026 · 1 revision

SYNOPSIS

Tests whether NTFS access control lists are canonical.

SYNTAX

Path (Default)

Test-NTFSItemAcl [[-Path] <String[]>] [-Section <String>] [-ThrottleLimit <Int32>] [-PassThru]
 [<CommonParameters>]

LiteralPath

Test-NTFSItemAcl -LiteralPath <String[]> [-Section <String>] [-ThrottleLimit <Int32>] [-PassThru]
 [<CommonParameters>]

DESCRIPTION

Tests the preferred Windows ACE order for the selected DACL, SACL, or both. Returns a Boolean by default or structured details with PassThru.

EXAMPLES

EXAMPLE 1

Test-NTFSItemAcl -LiteralPath C:\Data -Section Access

Returns true when the DACL on C:\Data is in canonical order.

PARAMETERS

-LiteralPath

One or more filesystem paths used exactly as supplied. FileSystem objects bind to this parameter through their PSPath property.

Type: String[]
Parameter Sets: LiteralPath
Aliases: PSPath

Required: True
Position: Named
Default value: None
Accept pipeline input: True (ByPropertyName)
Accept wildcard characters: False

-PassThru

Returns structured canonical-order results instead of a Boolean.

Type: SwitchParameter
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: False
Accept pipeline input: False
Accept wildcard characters: False

-Path

One or more filesystem paths. Wildcards are expanded by the FileSystem provider, and path strings can be supplied through the pipeline.

Type: String[]
Parameter Sets: Path
Aliases: FullName

Required: False
Position: 1
Default value: .
Accept pipeline input: True (ByPropertyName, ByValue)
Accept wildcard characters: True

-Section

Selects whether the DACL, SACL, or both lists are tested.

Type: String
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: Access
Accept pipeline input: False
Accept wildcard characters: False

-ThrottleLimit

Limits concurrently processed canonical paths. One requests deterministic sequential execution.

Type: Int32
Parameter Sets: (All)
Aliases:

Required: False
Position: Named
Default value: [Math]::Max(1, [Math]::Min(8, [Environment]::ProcessorCount))
Accept pipeline input: False
Accept wildcard characters: False

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

System.String

System.IO.FileSystemInfo

OUTPUTS

System.Boolean

WindowsAccessControl.AclTest

NOTES

RELATED LINKS

Home

Commands

DSC resources

Clone this wiki locally