Skip to content

WindowsAccessControlTaskFolderAccessRule

raandree edited this page Sep 6, 2026 · 1 revision

Parameters

Parameter Attribute DataType Description Allowed Values
AccessControlType Key System.Security.AccessControl.AccessControlType Whether the entry is an allow or a deny entry. Allow, Deny
AccessRights Key WindowsTaskFolderRights The exact task folder rights the entry grants or denies. ListTasks, CreateTask, CreateSubfolder, ReadExtendedProperties, WriteExtendedProperties, Traverse, DeleteChild, ReadProperties, WriteProperties, Delete, ReadPermissions, ChangePermissions, TakeOwnership, Synchronize, Read, ReadAndTraverse, Write, Modify, FullControl, GenericAll, GenericExecute, GenericWrite, GenericRead
Account Key System.String The principal the rule applies to. An alias is normalized by security identifier, so any spelling that resolves to the same principal matches.
AppliesTo Key System.String The inheritance scope of the entry across the folder, its subfolders, and the tasks in them. ThisFolderOnly, ThisFolderSubfoldersAndTasks, ThisFolderAndSubfolders, ThisFolderAndTasks, SubfoldersAndTasksOnly, SubfoldersOnly, TasksOnly
Path Key System.String The task folder the rule applies to.
AllowedRootPath Required System.String The task folder subtree the configuration is allowed to write under. A target outside it is refused before anything is written.
Ensure Write WindowsAccessControlDscEnsure Whether the exact entry must be present or absent. Defaults to Present. Absent, Present
Reasons Read WindowsAccessControlDscReason[] Returns why the resource is not in the desired state. Not configurable.

Description

The composite key identifies exactly one explicit access control entry on a Task Scheduler folder by path, account, rights, qualifier, and inheritance scope. Every write is confined to AllowedRootPath.

Home

Commands

DSC resources

Clone this wiki locally