Skip to content

WindowsAccessControlADObjectSecurityDescriptor

raandree edited this page Sep 6, 2026 · 1 revision

Parameters

Parameter Attribute DataType Description Allowed Values
DistinguishedName Key System.String The distinguished name of the directory object whose DACL is managed.
Sections Key WindowsSecurityDescriptorSection The security descriptor sections this resource owns. Only the access section is supported for a directory object. Owner, Group, Access, Audit, All
AllowedBaseDistinguishedName Required System.String The subtree the configuration is allowed to write under. A target outside it is refused before anything is written.
Sddl Required System.String The desired DACL in SDDL form. Capture it from Get-ADObjectSecurityDescriptor.
ObjectGuid Write System.String The immutable identity of the intended object. A distinguished name can be reused after a delete and recreate, so when this is set and the name now resolves to a different object the resource fails closed.
Server Write System.String The domain controller to bind over signed and sealed LDAP. When empty, a writable controller is discovered. Pin it when two writes must be serialized, because a security descriptor is one replicated attribute and the losing write is discarded whole.
TimeoutSeconds Write System.Int32 The directory operation timeout in seconds.
Reasons Read WindowsAccessControlDscReason[] Returns why the resource is not in the desired state. Not configurable.

Description

Compares the directory object's access control list against the desired SDDL and rewrites it. The resource takes no credential, so the Local Configuration Manager binds LDAP as the node's own identity and a compiled configuration never carries directory credentials. Every write is confined to AllowedBaseDistinguishedName, so a configuration states its own containment boundary.

Home

Commands

DSC resources

Clone this wiki locally