Skip to content

WindowsAccessControlProcessSecurityDescriptor

raandree edited this page Sep 6, 2026 · 1 revision

Parameters

Parameter Attribute DataType Description Allowed Values
CreationTimeFileTime Key System.Int64 The creation time of the pinned process instance as a file time. It distinguishes the intended process from a later one that reused the identifier.
ProcessId Key System.UInt32 The identifier of the process whose descriptor is managed.
Sections Key WindowsSecurityDescriptorSection The security descriptor sections this resource owns. Only these sections are compared and written. Owner, Group, Access, Audit, All
Sddl Required System.String The desired security descriptor for the selected sections, in SDDL form. Capture it from Get-ProcessSecurityDescriptor.
Reasons Read WindowsAccessControlDscReason[] Returns why the resource is not in the desired state. Not configurable.

Description

Compares the selected sections of the process security descriptor against the desired SDDL and rewrites only those sections. The target is pinned by process identifier and creation time, so a reused identifier fails closed rather than reaching a different process. Process desired state is ephemeral and valid only while that process instance lives.

Home

Commands

DSC resources

Clone this wiki locally