Skip to content

WindowsAccessControlADObjectAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

Parameters

Parameter Attribute DataType Description Allowed Values
AccessControlType Key System.Security.AccessControl.AccessControlType Whether the entry is an allow or a deny entry. Allow, Deny
AccessRights Key WindowsActiveDirectoryRights The exact directory rights the entry grants or denies. CreateChild, DeleteChild, ListChildren, Self, ReadProperty, WriteProperty, DeleteTree, ListObject, ExtendedRight, Delete, ReadControl, GenericExecute, GenericWrite, GenericRead, WriteDacl, WriteOwner, GenericAll, Synchronize, AccessSystemSecurity
Account Key System.String The principal the rule applies to. An alias is normalized by security identifier, so any spelling that resolves to the same principal matches.
DistinguishedName Key System.String The distinguished name of the directory object the rule applies to.
InheritanceType Key WindowsActiveDirectoryInheritance How the entry is inherited by objects below the target. None, All, Descendents, SelfAndChildren, Children
InheritedObjectType Key System.String The schema GUID of the child class the entry is inherited by, or empty for no scope. The same GUID rule applies.
ObjectType Key System.String The schema GUID the right is scoped to, or empty for no object scope. Anything else must be a real GUID, so a typo can never widen the managed entry to the whole object.
AllowedBaseDistinguishedName Required System.String The subtree the configuration is allowed to write under. A target outside it is refused before anything is written.
Ensure Write WindowsAccessControlDscEnsure Whether the exact entry must be present or absent. Defaults to Present. Absent, Present
Server Write System.String The domain controller to bind over signed and sealed LDAP. When empty, a writable controller is discovered.
TimeoutSeconds Write System.Int32 The directory operation timeout in seconds.
Reasons Read WindowsAccessControlDscReason[] Returns why the resource is not in the desired state. Not configurable.

Description

The composite key identifies exactly one explicit access control entry on a directory object, including the object type and inherited object type that scope a delegated right to one schema class or attribute set. The resource takes no credential, so the Local Configuration Manager binds LDAP as the node's own identity. Every write is confined to AllowedBaseDistinguishedName.

Home

Commands

DSC resources

Clone this wiki locally