Skip to content

WindowsAccessControlNtfsSecurityDescriptor

raandree edited this page Sep 6, 2026 · 1 revision

Parameters

Parameter Attribute DataType Description Allowed Values
Path Key System.String The file or directory whose security descriptor is managed.
Sections Key WindowsSecurityDescriptorSection The security descriptor sections this resource owns. Only these sections are compared and written. Owner, Group, Access, Audit, All
Sddl Required System.String The desired security descriptor for the selected sections, in SDDL form. Capture it from Get-NTFSItemSecurityDescriptor. Prefer a protected DACL so parent inheritance cannot add entries after convergence.
Reasons Read WindowsAccessControlDscReason[] Returns why the resource is not in the desired state. Not configurable.

Description

Compares the selected sections of the NTFS security descriptor at Path against the desired SDDL and rewrites only those sections. Every section the resource does not select is left untouched. System-maintained AUTO_INHERITED flags are ignored during comparison, while protection flags and every access control entry stay exact.

Home

Commands

DSC resources

Clone this wiki locally