Skip to content

WindowsAccessControlProcessAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

Parameters

Parameter Attribute DataType Description Allowed Values
AccessControlType Key System.Security.AccessControl.AccessControlType Whether the entry is an allow or a deny entry. Allow, Deny
Account Key System.String The principal the rule applies to. An alias is normalized by security identifier, so any spelling that resolves to the same principal matches.
CreationTimeFileTime Key System.Int64 The creation time of the pinned process instance as a file time. It distinguishes the intended process from a later one that reused the identifier.
ProcessId Key System.UInt32 The identifier of the process the rule applies to.
ProcessRights Key WindowsProcessRights The exact process rights the entry grants or denies. Terminate, CreateThread, SetSessionId, VmOperation, VmRead, VmWrite, DuplicateHandle, CreateProcess, SetQuota, SetInformation, QueryInformation, SuspendResume, QueryLimitedInformation, SetLimitedInformation, Delete, ReadControl, WriteDac, WriteOwner, Synchronize, AllAccess, AccessSystemSecurity, GenericAll, GenericExecute, GenericWrite, GenericRead
Ensure Write WindowsAccessControlDscEnsure Whether the exact entry must be present or absent. Defaults to Present. Absent, Present
Reasons Read WindowsAccessControlDscReason[] Returns why the resource is not in the desired state. Not configurable.

Description

The composite key identifies exactly one explicit access control entry on a pinned process instance. The target is pinned by process identifier and creation time, so a reused identifier fails closed rather than reaching a different process. Intended for long-lived process instances; the desired state is valid only while that instance lives.

Home

Commands

DSC resources

Clone this wiki locally