You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 

1.5 KiB

status last-verified owner source
current 2026-10-02 shared repository evidence

Product context

Problem

PowerShell ships only Get-Acl and Set-Acl; everything between reading and writing an ACL (permission reports, adding or removing one entry, inheritance, ownership, orphaned SIDs) needs custom .NET code. The module provides task-level cmdlets for these jobs (README.md summary).

Users

  • People who manage NTFS file and folder permissions with PowerShell (README summary). Specific personas: To confirm.

Core workflows

  1. Report permissions: Get-NTFSAccess, Get-NTFSSimpleAccess, Get-NTFSEffectiveAccess.
  2. Change permissions: Add-NTFSAccess, Remove-NTFSAccess, Clear-NTFSAccess; the audit equivalents manage the SACL.
  3. Back up and restore explicit permissions through CSV (Get-NTFSAccess | Export-Csv, Import-Csv | Add-NTFSAccess).
  4. Find and remove orphaned entries: Get-NTFSOrphanedAccess.
  5. Repair inheritance and ownership: *-NTFSAccessInheritance, Set-NTFSInheritance, Set-NTFSOwner, using backup/restore privileges.
  6. Work with paths longer than 260 characters: Get-ChildItem2 and the other *-Item2 cmdlets.

Experience goals

  • Pipeline first: item cmdlets emit objects whose FullName binds to -Path.
  • Accept account names and SIDs; output shows both when resolvable.
  • Output formatted like Get-ChildItem (NTFSSecurity.format.ps1xml).
  • Work on files the caller cannot normally open by enabling the Backup, Restore, TakeOwnership, and Security privileges automatically.