5.9 KiB
Examples
These examples show common tasks with the NTFSSecurity module. Replace the sample paths and accounts with your own. For background, see Concepts.
Changing permissions on items you don't own, changing owners, and every audit operation need an elevated PowerShell session. See Privileges.
Read permissions
Get the access entries of a folder:
Get-NTFSAccess -Path C:\Data
Get the access entries of every item in a folder:
Get-ChildItem -Path C:\Data | Get-NTFSAccess
Get only the explicit entries in a folder tree, including items with paths longer than 260 characters:
Get-ChildItem2 -Path C:\Data -Recurse | Get-NTFSAccess -ExcludeInherited
Get the entries of one account, either with -Account or with
Where-Object:
Get-NTFSAccess -Path C:\Data -Account 'CONTOSO\JohnDoe'
Get-NTFSAccess -Path C:\Data | Where-Object { $_.Account -like '*JohnDoe*' }
Grant permissions
Give an account the Modify permission on a folder, its subfolders, and its files:
Add-NTFSAccess -Path C:\Data -Account 'CONTOSO\JohnDoe' -AccessRights Modify
Give a group read access to a folder and its subfolders, but not to the files:
Add-NTFSAccess -Path C:\Data -Account 'CONTOSO\Domain Users' -AccessRights ReadAndExecute -AppliesTo ThisFolderAndSubfolders
Deny a group the right to delete anything in a folder:
Add-NTFSAccess -Path C:\Data\Public -Account 'CONTOSO\Interns' -AccessRights Delete, DeleteSubdirectoriesAndFiles -AccessType Deny
Remove permissions
Remove an entry by account and rights:
Remove-NTFSAccess -Path C:\Data -Account 'CONTOSO\JohnDoe' -AccessRights Modify
Remove all explicit entries of an account by piping them to
Remove-NTFSAccess:
Get-NTFSAccess -Path C:\Data -Account 'CONTOSO\JohnDoe' -ExcludeInherited | Remove-NTFSAccess
Back up and restore permissions
Save the explicit entries of a folder and everything below it to a CSV file:
$items = @(Get-Item2 -Path C:\Data) + @(Get-ChildItem2 -Path C:\Data -Recurse)
$items | Get-NTFSAccess -ExcludeInherited | Export-Csv -Path C:\Backup\permissions.csv -NoTypeInformation
Restore the entries. Each row contains the path, account, rights, type, and
inheritance settings of one entry, which Add-NTFSAccess binds by property
name:
Import-Csv -Path C:\Backup\permissions.csv | Add-NTFSAccess
Restoring adds the saved entries. It doesn't remove entries that were added after the backup.
Find and remove orphaned entries
List entries whose account no longer exists:
Get-ChildItem2 -Path C:\Data -Recurse | Get-NTFSOrphanedAccess
Remove them:
Get-ChildItem2 -Path C:\Data -Recurse | Get-NTFSOrphanedAccess | Remove-NTFSAccess
Review the list before you remove anything. An account also looks orphaned when Windows can't resolve it temporarily, for example because a domain controller is unreachable.
Check effective access
Show the access that the current user has on a folder:
Get-NTFSEffectiveAccess -Path C:\Data
Show the access of another account, by name or by SID:
Get-NTFSEffectiveAccess -Path C:\Data -Account 'CONTOSO\JohnDoe'
Get-NTFSEffectiveAccess -Path C:\Data -Account S-1-5-32-545
Manage inheritance
Find the folders that don't inherit permissions from their parent:
Get-ChildItem2 -Path C:\Data -Recurse -Directory | Get-NTFSInheritance | Where-Object { -not $_.AccessInheritanceEnabled }
Turn inheritance back on for a whole folder tree. Explicit entries stay in place:
Get-ChildItem2 -Path C:\Data -Recurse | Enable-NTFSAccessInheritance
Block inheritance on a folder. The inherited entries are copied as explicit entries:
Disable-NTFSAccessInheritance -Path C:\Data\Finance
Reset a folder to inherited permissions only:
Enable-NTFSAccessInheritance -Path C:\Data\Finance -RemoveExplicitAccessRules
Manage ownership
List the owners of all items in a folder tree:
Get-ChildItem2 -Path C:\Data -Recurse | Get-NTFSOwner
Make the local Administrators group the owner of a folder. This needs an elevated session:
Set-NTFSOwner -Path C:\Data -Account 'BUILTIN\Administrators'
Make several changes in one write
Get the security descriptor once, change it in memory, and write it back.
With security descriptor input, specify -AppliesTo (or the inheritance and
propagation flags) so that PowerShell can choose the parameter set:
$sd = Get-NTFSSecurityDescriptor -Path C:\Data
$sd | Add-NTFSAccess -Account 'CONTOSO\JohnDoe' -AccessRights Modify -AppliesTo ThisFolderSubfoldersAndFiles
$sd | Remove-NTFSAccess -Account 'CONTOSO\Interns' -AccessRights ReadAndExecute -AppliesTo ThisFolderSubfoldersAndFiles
$sd | Set-NTFSSecurityDescriptor
Audit access
Log every successful and failed attempt to delete items in a folder. This needs an elevated session, and Windows only writes the events when the Audit File System policy is enabled:
Add-NTFSAudit -Path C:\Data\Finance -Account 'Everyone' -AccessRights Delete, DeleteSubdirectoriesAndFiles
Get-NTFSAudit -Path C:\Data\Finance
Work with long paths
Find files whose full path is longer than 260 characters and show their permissions:
Get-ChildItem2 -Path C:\Data -Recurse -File | Where-Object { $_.FullName.Length -gt 260 } | Get-NTFSAccess
Use privileges
List the privileges of the current PowerShell process:
Get-Privileges
In an elevated session, enable the Backup, Restore, Take Ownership, and Security privileges for the rest of the session, and disable them again when you're done:
Enable-Privileges
Get-ChildItem2 -Path D:\Shares -Recurse | Get-NTFSAccess -ExcludeInherited
Disable-Privileges