The essentials

Quick reference

One focused task per row. Jump to the related section for complete, working examples.

UseSyntaxExamples
Inspect an ACLGet-Acl -LiteralPath 'C:\Data\Reports' | Format-ListView examples
List access entries(Get-Acl -LiteralPath $path).Access | Format-Table IdentityReference, FileSystemRights, AccessControlType, IsInheritedView examples
Capture SDDL(Get-Acl -LiteralPath $path).Sddl | Set-Content -LiteralPath '.\acl.sddl'View examples
Back up a treeicacls C:\Data\Reports /save C:\Backup\reports.acl /t /cView examples
Create an allow rule$rule = ` [System.Security.AccessControl.FileSystemAccessRule]::new('CONTOSO\Analysts', ` 'ReadAndExecute', 'Allow')View examples
Add a rule in memory$acl.AddAccessRule($rule)View examples
Preview applying an ACLSet-Acl -LiteralPath $path -AclObject $acl -WhatIfView examples
Inspect owner(Get-Acl -LiteralPath $path).OwnerView examples
Disable inheritance in memory$acl.SetAccessRuleProtection($true, $true)View examples
Verify ACL canonical formicacls C:\Data\Reports /verify /tView examples
Inspect security groupswhoami /allView examples
Test actual accessTest-Path -LiteralPath 'C:\Data\Reports\summary.csv'View examples

Windows file authorization is encoded in security descriptors containing owners and ordered access-control entries. Resolve identities and inheritance before editing, export a recoverable representation, prefer narrowly scoped grants over broad replacements, and verify access as the intended principal.

Step by step

Detailed examples

01

Read every relevant access entry before editing

Get-Acl returns an object whose Access list includes allow/deny, rights, identity, inheritance flags, and propagation flags. Effective access also depends on group membership, deny ordering, share permissions, privileges, and the process token. A formatted summary is not a full authorization proof.

Detailed DACL inventory
$path = 'C:\Data\Reports'
$acl = Get-Acl -LiteralPath $path
$acl | Select-Object Path, Owner, Sddl
$acl.Access | Select-Object IdentityReference, AccessControlType, FileSystemRights, IsInherited, InheritanceFlags, PropagationFlags
Back to quick reference ↑
02

Capture recovery data outside the target tree

SDDL is useful for one descriptor; icacls /save records DACLs recursively using relative paths and can later restore them under the same root. Store backups in a protected location and test restoration on representative data. Ownership and auditing information may need separate handling.

Back up and inspect before change
$path = 'C:\Data\Reports'
(Get-Acl -LiteralPath $path).Sddl | Set-Content -LiteralPath 'C:\Backup\reports-root.sddl'
icacls $path /save 'C:\Backup\reports-tree.acl' /t /c
Back to quick reference ↑
03

Edit an in-memory descriptor and preview application

FileSystemAccessRule constructors require identity, rights, inheritance, propagation, and allow/deny semantics that match the target. AddAccessRule may merge compatible entries. Set-Acl applies a supplied descriptor as a whole, so reread immediately before change to reduce stale overwrites and use WhatIf first.

Preview a folder-tree read grant
$path = 'C:\Data\Reports'
$acl = Get-Acl -LiteralPath $path
$rule = [System.Security.AccessControl.FileSystemAccessRule]::new(
  'CONTOSO\Analysts', 'ReadAndExecute',
  'ContainerInherit,ObjectInherit', 'None', 'Allow'
)
$acl.AddAccessRule($rule)
Set-Acl -LiteralPath $path -AclObject $acl -WhatIf
Back to quick reference ↑
04

Change inheritance only with a full descendant plan

Disabling inheritance can copy inherited entries or remove them, producing very different results. Owner changes affect who can edit the DACL and may require privileges. Preserve administrative recovery access, test on a small subtree, and avoid recursive ownership replacement as a routine fix.

Model protected inheritance without applying it
$path = 'C:\Data\Reports'
$acl = Get-Acl -LiteralPath $path
$acl.SetAccessRuleProtection($true, $true)
$acl | Select-Object Owner, AreAccessRulesProtected, Sddl
Back to quick reference ↑
05

Verify structure and access under the intended token

icacls /verify checks structural consistency, not whether policy is correct. whoami /all explains the current token. Test read, write, create, delete, and traversal separately as the target principal because elevated administrator results do not predict service or user access.

Post-change verification set
icacls 'C:\Data\Reports' /verify /t
whoami /all
Get-Acl -LiteralPath 'C:\Data\Reports' | Format-List Owner, Sddl
Test-Path -LiteralPath 'C:\Data\Reports\summary.csv'
Back to quick reference ↑

Sources and further reading

References

Authoritative documentation used to verify and expand this cheat sheet.

  1. MicrosoftGet-Acllearn.microsoft.com
  2. MicrosoftSet-Acllearn.microsoft.com
  3. MicrosoftFileSystemAccessRule Classlearn.microsoft.com
  4. Microsofticaclslearn.microsoft.com

Help us improve

Found a typo or missing example?

Tell us what would make this cheat sheet clearer, more complete, or more useful.

Share feedback