mirror of https://github.com/raandree/NTFSSecurity
You can not select more than 25 topics
Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
1.8 KiB
1.8 KiB
| status | date | last-verified | owner | source |
|---|---|---|---|---|
| accepted | 2026-10-05 | 2026-10-05 | shared | maintainer decision D3 for the overnight run of 2026-10-04 (defect group E) |
Decision 13: Set-NTFSInheritance keeps entries like the dedicated cmdlets
- Choice:
Set-NTFSInheritanceuses the defaults of the dedicated cmdlets.-AccessInheritanceEnabled $falsecopies the inherited access entries into the DACL, likeDisable-NTFSAccessInheritance, and-AuditInheritanceEnabled $truekeeps the explicit audit entries, likeEnable-NTFSAuditInheritance. The other two directions already matched. The same applies to a security descriptor in memory, whose kept entries stay marked as inherited until it is written. - Way back:
Disable-NTFSAccessInheritance -RemoveInheritedAccessRulesremoves the inherited access entries, andEnable-NTFSAuditInheritance -RemoveExplicitAuditRulesremoves the explicit audit entries.Set-NTFSInheritancegets no switches for that. - Rationale: Before 5.0.0, two of the four directions removed entries,
unlike the dedicated cmdlets. Turning access inheritance off on an item
without explicit entries left an empty DACL, which denies access to
everyone. 5.0.0 is a major version, so the change ships there, listed
under
Changedin the changelog. - Related:
Clear-NTFSAccess -DisableInheritancekeeps discarding the inherited entries, because removing every entry is the purpose of that cmdlet; its page states the empty DACL and its risk (decision D2 of the same run). The audit switches were renamed to-RemoveInheritedAuditRulesand-RemoveExplicitAuditRules, with the old names as aliases (D4). - Rejected: adding
-RemoveInheritedAccessRulesand-RemoveExplicitAuditRulesswitches toSet-NTFSInheritance, which would duplicate the dedicated cmdlets.