Skip to content

WindowsAccessControlScheduledTaskSecurityDescriptor

raandree edited this page Sep 6, 2026 · 1 revision

Parameters

Parameter Attribute DataType Description Allowed Values
Sections Key WindowsSecurityDescriptorSection The security descriptor sections this resource owns. Only the access section is supported for a registered task. Owner, Group, Access, Audit, All
TaskName Key System.String The name of the registered task whose DACL is managed.
TaskPath Key System.String The task folder that contains the registered task.
AllowedRootPath Required System.String The task folder subtree the configuration is allowed to write under. A target outside it is refused before anything is written.
Sddl Required System.String The desired DACL in SDDL form. Capture it from Get-ScheduledTaskSecurityDescriptor.
Reasons Read WindowsAccessControlDscReason[] Returns why the resource is not in the desired state. Not configurable.

Description

Compares the registered task's access control list against the desired SDDL and rewrites it. Access control entry order is ignored during comparison because the Task Scheduler service canonicalizes it after a write, so this resource cannot detect a reordering that moves an allow entry ahead of a deny entry.

Home

Commands

DSC resources

Clone this wiki locally