Skip to content

WindowsAccessControlCertificatePrivateKeyAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

Parameters

Parameter Attribute DataType Description Allowed Values
AccessControlType Key System.Security.AccessControl.AccessControlType Whether the entry is an allow or a deny entry. Allow, Deny
AccessRights Key WindowsCryptoKeyRights The exact crypto key rights the entry grants or denies. ReadData, WriteData, AppendData, ReadExtendedAttributes, WriteExtendedAttributes, Execute, ReadAttributes, WriteAttributes, Delete, ReadPermissions, ChangePermissions, TakeOwnership, Synchronize, Read, ReadAndExecute, Write, FullControl, GenericAll, GenericExecute, GenericWrite, GenericRead
Account Key System.String The principal the rule applies to. An alias is normalized by security identifier, so any spelling that resolves to the same principal matches.
KeyName Key System.String The exact persisted CNG key name the rule applies to.
KeyScope Key System.String Selects the machine or current-user key store. Machine, User
ProviderName Key System.String The exact expected CNG provider. This increment accepts only Microsoft Software Key Storage Provider.
Ensure Write WindowsAccessControlDscEnsure Whether the exact entry must be present or absent. Defaults to Present. Absent, Present
Reasons Read WindowsAccessControlDscReason[] Returns why the resource is not in the desired state. Not configurable.

Description

The composite key identifies exactly one explicit access control entry on a persisted CNG certificate private key. The key is addressed by provider, key name, and scope rather than by certificate thumbprint, because a renewal that reuses the key changes the thumbprint. Private key material is never exported or serialized.

Home

Commands

DSC resources

Clone this wiki locally