You can not select more than 25 topics Topics must start with a letter or number, can include dashes ('-') and can be up to 35 characters long.
 
 

4.0 KiB

external help file Module Name online version schema
NTFSSecurity.dll-Help.xml NTFSSecurity https://github.com/raandree/NTFSSecurity/blob/master/Docs/Cmdlets/Get-Privileges.md 2.0.0

Get-Privileges

SYNOPSIS

Gets the privileges in the access token of the current PowerShell process.

SYNTAX

Get-Privileges [<CommonParameters>]

DESCRIPTION

The Get-Privileges cmdlet reads the access token of the current PowerShell process and returns one ProcessPrivileges.PrivilegeAndAttributes object for every privilege the token contains. Each object names the privilege in the Privilege property, the raw token attributes in PrivilegeAttributes, and the resulting state in PrivilegeState, which is Enabled, Disabled, or Removed.

The cmdlet only reads; it never changes a privilege. Use it to check whether the four privileges that NTFSSecurity depends on (Backup, Restore, Take Ownership, and Security) are available before you run the file system cmdlets, and to confirm the result of Enable-Privileges and Disable-Privileges.

Only privileges that the account holds in this session appear in the list; privileges the account does not have are not listed at all. Because Windows removes the administrative privileges from the token of a session that is not elevated, a standard session returns a much shorter list than an elevated one.

EXAMPLES

Example 1: List the privileges of the current session

PS C:\> Get-Privileges

This command returns every privilege in the access token of the current PowerShell process together with its state.

Example 2: List only the privileges that are currently enabled

PS C:\> Get-Privileges | Where-Object { $_.PrivilegeState -eq 'Enabled' }

This command filters the result down to the privileges that are in use, which is a short list in a session that has not enabled anything.

Example 3: Check the privileges that NTFSSecurity uses

PS C:\> Get-Privileges | Where-Object { $_.Privilege -in 'Backup', 'Restore', 'TakeOwnership', 'Security' }

This command shows the four file system privileges. An empty result means that the session does not hold them, which is the normal case outside an elevated session.

Example 4: Test a single privilege before taking ownership

PS C:\> (Get-Privileges | Where-Object { $_.Privilege -eq 'TakeOwnership' }).PrivilegeState

This command returns the state of the Take Ownership privilege alone and returns nothing when the session does not hold it.

PARAMETERS

CommonParameters

This cmdlet supports the common parameters: -Debug, -ErrorAction, -ErrorVariable, -InformationAction, -InformationVariable, -OutVariable, -OutBuffer, -PipelineVariable, -Verbose, -WarningAction, and -WarningVariable. For more information, see about_CommonParameters.

INPUTS

None

This cmdlet does not accept pipeline input.

OUTPUTS

ProcessPrivileges.PrivilegeAndAttributes

The cmdlet returns one object per privilege in the token of the current process. Privilege names the privilege, PrivilegeAttributes holds the token attributes as a combination of Disabled, EnabledByDefault, Enabled, Removed, and UsedForAccess, and PrivilegeState reduces those attributes to Enabled, Disabled, or Removed.

NOTES

This cmdlet reads the access token of the current PowerShell process only. It reports no privileges of other processes or sessions, and it changes nothing. Use Enable-Privileges and Disable-Privileges to change the state of the file system privileges.

Unlike the file system cmdlets of the module, Get-Privileges is not affected by the EnablePrivileges setting in the PrivateData section of NTFSSecurity.psd1 and never enables a privilege on its own.

Enable-Privileges

Disable-Privileges

Set-NTFSOwner

Get-NTFSSecurityDescriptor