These examples show common tasks with the NTFSSecurity module. Replace the sample paths and accounts with your own. For background, see Concepts.
Changing permissions on items you don't own, changing owners, and every audit operation need an elevated PowerShell session. See Privileges.
Get the access entries of a folder:
Get-NTFSAccess -Path C:\DataGet the access entries of every item in a folder:
Get-ChildItem -Path C:\Data | Get-NTFSAccessGet only the explicit entries in a folder tree, including items with paths longer than 260 characters:
Get-ChildItem2 -Path C:\Data -Recurse | Get-NTFSAccess -ExcludeInheritedGet the entries of one account, either with -Account or with
Where-Object:
Get-NTFSAccess -Path C:\Data -Account 'CONTOSO\JohnDoe'
Get-NTFSAccess -Path C:\Data | Where-Object { $_.Account -like '*JohnDoe*' }Give an account the Modify permission on a folder, its subfolders, and its files:
Add-NTFSAccess -Path C:\Data -Account 'CONTOSO\JohnDoe' -AccessRights ModifyGive a group read access to a folder and its subfolders, but not to the files:
Add-NTFSAccess -Path C:\Data -Account 'CONTOSO\Domain Users' -AccessRights ReadAndExecute -AppliesTo ThisFolderAndSubfoldersDeny a group the right to delete anything in a folder:
Add-NTFSAccess -Path C:\Data\Public -Account 'CONTOSO\Interns' -AccessRights Delete, DeleteSubdirectoriesAndFiles -AccessType DenyRemove an entry by account and rights:
Remove-NTFSAccess -Path C:\Data -Account 'CONTOSO\JohnDoe' -AccessRights ModifyRemove all explicit entries of an account by piping them to
Remove-NTFSAccess:
Get-NTFSAccess -Path C:\Data -Account 'CONTOSO\JohnDoe' -ExcludeInherited | Remove-NTFSAccessSave the explicit entries of a folder and everything below it to a CSV file:
$items = @(Get-Item2 -Path C:\Data) + @(Get-ChildItem2 -Path C:\Data -Recurse)
$items | Get-NTFSAccess -ExcludeInherited | Export-Csv -Path C:\Backup\permissions.csv -NoTypeInformationRestore the entries. Each row contains the path, account, rights, type, and
inheritance settings of one entry, which Add-NTFSAccess binds by property
name:
Import-Csv -Path C:\Backup\permissions.csv | Add-NTFSAccessRestoring adds the saved entries. It doesn't remove entries that were added after the backup.
List entries whose account no longer exists:
Get-ChildItem2 -Path C:\Data -Recurse | Get-NTFSOrphanedAccessRemove them:
Get-ChildItem2 -Path C:\Data -Recurse | Get-NTFSOrphanedAccess | Remove-NTFSAccessReview the list before you remove anything. An account also looks orphaned when Windows can't resolve it temporarily, for example because a domain controller is unreachable.
Show the access that the current user has on a folder:
Get-NTFSEffectiveAccess -Path C:\DataShow the access of another account, by name or by SID:
Get-NTFSEffectiveAccess -Path C:\Data -Account 'CONTOSO\JohnDoe'
Get-NTFSEffectiveAccess -Path C:\Data -Account S-1-5-32-545Find the folders that don't inherit permissions from their parent:
Get-ChildItem2 -Path C:\Data -Recurse -Directory | Get-NTFSInheritance | Where-Object { -not $_.AccessInheritanceEnabled }Turn inheritance back on for a whole folder tree. Explicit entries stay in place:
Get-ChildItem2 -Path C:\Data -Recurse | Enable-NTFSAccessInheritanceBlock inheritance on a folder. The inherited entries are copied as explicit entries:
Disable-NTFSAccessInheritance -Path C:\Data\FinanceReset a folder to inherited permissions only:
Enable-NTFSAccessInheritance -Path C:\Data\Finance -RemoveExplicitAccessRulesList the owners of all items in a folder tree:
Get-ChildItem2 -Path C:\Data -Recurse | Get-NTFSOwnerMake the local Administrators group the owner of a folder. This needs an elevated session:
Set-NTFSOwner -Path C:\Data -Account 'BUILTIN\Administrators'Get the security descriptor once, change it in memory, and write it back.
With security descriptor input, specify -AppliesTo (or the inheritance and
propagation flags) so that PowerShell can choose the parameter set:
$sd = Get-NTFSSecurityDescriptor -Path C:\Data
$sd | Add-NTFSAccess -Account 'CONTOSO\JohnDoe' -AccessRights Modify -AppliesTo ThisFolderSubfoldersAndFiles
$sd | Remove-NTFSAccess -Account 'CONTOSO\Interns' -AccessRights ReadAndExecute -AppliesTo ThisFolderSubfoldersAndFiles
$sd | Set-NTFSSecurityDescriptorLog every successful and failed attempt to delete items in a folder. This needs an elevated session, and Windows only writes the events when the Audit File System policy is enabled:
Add-NTFSAudit -Path C:\Data\Finance -Account 'Everyone' -AccessRights Delete, DeleteSubdirectoriesAndFiles
Get-NTFSAudit -Path C:\Data\FinanceFind files whose full path is longer than 260 characters and show their permissions:
Get-ChildItem2 -Path C:\Data -Recurse -File | Where-Object { $_.FullName.Length -gt 260 } | Get-NTFSAccessList the privileges of the current PowerShell process:
Get-PrivilegesIn an elevated session, enable the Backup, Restore, Take Ownership, and Security privileges for the rest of the session, and disable them again when you're done:
Enable-Privileges
Get-ChildItem2 -Path D:\Shares -Recurse | Get-NTFSAccess -ExcludeInherited
Disable-Privileges