From 4ee01e5749efa4fd9daada1701bf8af6b5929fbc Mon Sep 17 00:00:00 2001 From: Raimund Andree Date: Thu, 8 Oct 2026 15:38:29 +0000 Subject: [PATCH] docs: explain how to compare the permissions of two items Entries and descriptors are equal only when they hold the same .NET object, as in .NET, so two reads of the same entry differ. The FAQ shows how to compare the entries of two items with Compare-Object -Property. Decision 22, item 9: keep the equality of .NET, an assumption in autopilot, flagged for the maintainer's review. Co-authored-by: Copilot <223556219+Copilot@users.noreply.github.com> Co-authored-by: AI Assistant --- Docs/FAQ.md | 18 ++++++++++++++++++ 1 file changed, 18 insertions(+) diff --git a/Docs/FAQ.md b/Docs/FAQ.md index 8fd93fb..1232611 100644 --- a/Docs/FAQ.md +++ b/Docs/FAQ.md @@ -75,3 +75,21 @@ relative path is resolved against the current file system location, also a name that starts with a dot, such as `.gitignore`; before 5.0.0-rc6, the cmdlets dropped the first two characters of such a name. See [Long paths](Concepts.md#long-paths). + +## How do I compare the permissions of two items? + +Compare the properties of the entries, not the entries themselves. Each +entry that `Get-NTFSAccess` returns is an object of its own, and like the +access rules of .NET, two entries are equal only when they are the same +object, even when they grant the same rights to the same account. +`Compare-Object` with `-Property` lists the entries that only one of the +items has: + +```powershell +$properties = 'Account', 'AccessRights', 'AccessControlType', 'InheritanceFlags', 'PropagationFlags' +Compare-Object -ReferenceObject (Get-NTFSAccess -Path C:\Data\A) -DifferenceObject (Get-NTFSAccess -Path C:\Data\B) -Property $properties +``` + +The same works for the entries of `Get-NTFSAudit`, with `AuditFlags` in +place of `AccessControlType`. See +[Get-NTFSAccess](Cmdlets/Get-NTFSAccess.md).