Skip to content

WindowsAccessControlNtfsAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

Parameters

Parameter Attribute DataType Description Allowed Values
AccessControlType Key System.Security.AccessControl.AccessControlType Whether the entry is an allow or a deny entry. Allow, Deny
AccessRights Key System.Security.AccessControl.FileSystemRights The exact file system rights the entry grants or denies. ReadData, ListDirectory, WriteData, CreateFiles, AppendData, CreateDirectories, ReadExtendedAttributes, WriteExtendedAttributes, ExecuteFile, Traverse, DeleteSubdirectoriesAndFiles, ReadAttributes, WriteAttributes, Write, Delete, ReadPermissions, Read, ReadAndExecute, Modify, ChangePermissions, TakeOwnership, Synchronize, FullControl
Account Key System.String The principal the rule applies to. An alias is normalized by security identifier, so any spelling that resolves to the same principal matches.
AppliesTo Key System.String The inheritance scope of the entry, expressed the way the Windows security editor expresses it. ThisFolderOnly, ThisFolderSubfoldersAndFiles, ThisFolderAndSubfolders, ThisFolderAndFiles, SubfoldersAndFilesOnly, SubfoldersOnly, FilesOnly, ThisFolderSubfoldersAndFilesOneLevel, ThisFolderAndSubfoldersOneLevel, ThisFolderAndFilesOneLevel, SubfoldersAndFilesOnlyOneLevel, SubfoldersOnlyOneLevel, FilesOnlyOneLevel
Path Key System.String The file or directory the rule applies to.
Ensure Write WindowsAccessControlDscEnsure Whether the exact entry must be present or absent. Defaults to Present. Absent, Present
Reasons Read WindowsAccessControlDscReason[] Returns why the resource is not in the desired state. Not configurable.

Description

The composite key identifies exactly one explicit access control entry by path, account, rights, qualifier, and inheritance scope. Absent removes every duplicate of that exact entry without purging unrelated rights or the opposite qualifier. For an allow rule the comparison includes the Synchronize bit that .NET adds when it materializes the entry. Windows can merge entries that share account, qualifier, and scope, so a narrower exact rule cannot coexist with a broader superset entry and will stay noncompliant; model the superset explicitly or manage the whole list with WindowsAccessControlNtfsSecurityDescriptor.

Home

Commands

DSC resources

Clone this wiki locally