Skip to content

WindowsAccessControlRegistryKeySecurityDescriptor

raandree edited this page Sep 6, 2026 · 1 revision

Parameters

Parameter Attribute DataType Description Allowed Values
Path Key System.String The registry key whose security descriptor is managed.
RegistryView Key WindowsRegistryView The registry view the key is opened in. It is part of the key identity. Default, Registry32, Registry64
Sections Key WindowsSecurityDescriptorSection The security descriptor sections this resource owns. Only these sections are compared and written. Owner, Group, Access, Audit, All
Sddl Required System.String The desired security descriptor for the selected sections, in SDDL form. Capture it from Get-RegistryKeySecurityDescriptor.
Reasons Read WindowsAccessControlDscReason[] Returns why the resource is not in the desired state. Not configurable.

Description

Compares the selected sections of the registry key security descriptor against the desired SDDL and rewrites only those sections. The registry view is part of the resource identity, so the 32-bit and 64-bit views of the same path are two separate targets.

Home

Commands

DSC resources

Clone this wiki locally