The essentials
Quick reference
One focused task per row. Jump to the related section for complete, working examples.
| Use | Syntax | Examples |
|---|---|---|
| Inspect an ACL | Get-Acl -LiteralPath 'C:\Data\Reports' | Format-List | View examples |
| List access entries | (Get-Acl -LiteralPath $path).Access |
Format-Table IdentityReference, FileSystemRights, AccessControlType, IsInherited | View examples |
| Capture SDDL | (Get-Acl -LiteralPath $path).Sddl |
Set-Content -LiteralPath '.\acl.sddl' | View examples |
| Back up a tree | icacls C:\Data\Reports /save C:\Backup\reports.acl /t /c | View examples |
| Create an allow rule | $rule = `
[System.Security.AccessControl.FileSystemAccessRule]::new('CONTOSO\Analysts', `
'ReadAndExecute', 'Allow') | View examples |
| Add a rule in memory | $acl.AddAccessRule($rule) | View examples |
| Preview applying an ACL | Set-Acl -LiteralPath $path -AclObject $acl -WhatIf | View examples |
| Inspect owner | (Get-Acl -LiteralPath $path).Owner | View examples |
| Disable inheritance in memory | $acl.SetAccessRuleProtection($true, $true) | View examples |
| Verify ACL canonical form | icacls C:\Data\Reports /verify /t | View examples |
| Inspect security groups | whoami /all | View examples |
| Test actual access | Test-Path -LiteralPath 'C:\Data\Reports\summary.csv' | View examples |
Windows file authorization is encoded in security descriptors containing owners and ordered access-control entries. Resolve identities and inheritance before editing, export a recoverable representation, prefer narrowly scoped grants over broad replacements, and verify access as the intended principal.
Step by step
Detailed examples
Read every relevant access entry before editing
Get-Acl returns an object whose Access list includes allow/deny, rights, identity, inheritance flags, and propagation flags. Effective access also depends on group membership, deny ordering, share permissions, privileges, and the process token. A formatted summary is not a full authorization proof.
$path = 'C:\Data\Reports'
$acl = Get-Acl -LiteralPath $path
$acl | Select-Object Path, Owner, Sddl
$acl.Access | Select-Object IdentityReference, AccessControlType, FileSystemRights, IsInherited, InheritanceFlags, PropagationFlags Capture recovery data outside the target tree
SDDL is useful for one descriptor; icacls /save records DACLs recursively using relative paths and can later restore them under the same root. Store backups in a protected location and test restoration on representative data. Ownership and auditing information may need separate handling.
$path = 'C:\Data\Reports'
(Get-Acl -LiteralPath $path).Sddl | Set-Content -LiteralPath 'C:\Backup\reports-root.sddl'
icacls $path /save 'C:\Backup\reports-tree.acl' /t /c Edit an in-memory descriptor and preview application
FileSystemAccessRule constructors require identity, rights, inheritance, propagation, and allow/deny semantics that match the target. AddAccessRule may merge compatible entries. Set-Acl applies a supplied descriptor as a whole, so reread immediately before change to reduce stale overwrites and use WhatIf first.
$path = 'C:\Data\Reports'
$acl = Get-Acl -LiteralPath $path
$rule = [System.Security.AccessControl.FileSystemAccessRule]::new(
'CONTOSO\Analysts', 'ReadAndExecute',
'ContainerInherit,ObjectInherit', 'None', 'Allow'
)
$acl.AddAccessRule($rule)
Set-Acl -LiteralPath $path -AclObject $acl -WhatIf Change inheritance only with a full descendant plan
Disabling inheritance can copy inherited entries or remove them, producing very different results. Owner changes affect who can edit the DACL and may require privileges. Preserve administrative recovery access, test on a small subtree, and avoid recursive ownership replacement as a routine fix.
$path = 'C:\Data\Reports'
$acl = Get-Acl -LiteralPath $path
$acl.SetAccessRuleProtection($true, $true)
$acl | Select-Object Owner, AreAccessRulesProtected, Sddl Verify structure and access under the intended token
icacls /verify checks structural consistency, not whether policy is correct. whoami /all explains the current token. Test read, write, create, delete, and traversal separately as the target principal because elevated administrator results do not predict service or user access.
icacls 'C:\Data\Reports' /verify /t
whoami /all
Get-Acl -LiteralPath 'C:\Data\Reports' | Format-List Owner, Sddl
Test-Path -LiteralPath 'C:\Data\Reports\summary.csv' Sources and further reading
References
Authoritative documentation used to verify and expand this cheat sheet.
Help us improve
Found a typo or missing example?
Tell us what would make this cheat sheet clearer, more complete, or more useful.



