Use Get-Acl to inspect a folder’s security descriptor, modify the existing ACL object, and apply it with Set-Acl. For a rule that should flow to files and subfolders, set both container and object inheritance. Preview changes with -WhatIf, and remember that NTFS permissions and SMB share permissions are separate layers.
Inspect the folder’s current permissions
Run PowerShell on Windows and set the path to the folder you want to review:
$path = 'C:DataReports'
$acl = Get-Acl -Path $path
$acl | Format-List Path,Owner,Access,Sddl
Get-Acl returns a security-descriptor object. Its Access collection contains the folder’s DACL entries for users and groups; Sddl displays the descriptor in SDDL form. Review the full access list and inheritance state before diagnosing an access problem, since Deny entries and inherited rules can affect the result. See Microsoft’s Get-Acl documentation.
Add a permission without replacing the existing ACL
Build the new rule, add it to the ACL you just read, and apply that modified descriptor. This example grants the domain group CONTOSOAnalysts Read and Execute on the folder and makes the rule inheritable by files and child folders:
#1 Best Overall
$path = 'C:DataReports'
$acl = Get-Acl -Path $path
$rule = [System.Security.AccessControl.FileSystemAccessRule]::new(
'CONTOSOAnalysts',
'ReadAndExecute',
'ContainerInherit,ObjectInherit',
'None',
'Allow'
)
$acl.SetAccessRule($rule)
Set-Acl -Path $path -AclObject $acl -WhatIf
# After reviewing the preview, apply the change:
Set-Acl -Path $path -AclObject $acl
A FileSystemAccessRule specifies the identity, access right, inheritance flags, propagation settings, and whether the entry allows or denies access. ContainerInherit,ObjectInherit targets child directories and files; None leaves propagation settings unset. The preview is useful before applying a change, but it is not a substitute for checking which path and ACL object you intend to modify. Microsoft explains the descriptor operation and rule construction in its Set-Acl documentation.
Start with the target’s current ACL when adding a rule. Passing a newly constructed security descriptor to Set-Acl can replace entries you meant to keep, because Set-Acl makes the item match the descriptor you supply.
Rank #2
- Book - powershell for sysadmins: workflow automation made easy
- Language: english
- Binding: paperback
Apply a rule to selected descendants
An inheritable rule on the parent is usually the simplest way to cover ordinary child files and folders. If you need to apply the rule directly to existing descendants as well, enumerate them and update each object’s existing ACL:
Get-ChildItem -LiteralPath $path -Recurse -Force |
ForEach-Object {
$childAcl = Get-Acl -LiteralPath $_.FullName
$childAcl.SetAccessRule($rule)
Set-Acl -LiteralPath $_.FullName -AclObject $childAcl -WhatIf
}
Review the preview, then remove -WhatIf to apply the changes. This loop targets the returned descendants; it does not itself update the starting folder. Also, a child with inheritance disabled has a protected ACL, so a parent’s inheritable rule will not automatically override that child’s permissions. Decide explicitly whether such objects should remain protected or be changed.
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallRank #3
Choose what happens to inherited permissions
Inheritance determines whether permissions continue to flow from a parent folder. Disabling it can either preserve inherited entries by converting them to explicit entries or remove those inherited entries. Re-enabling it lets parent-folder policies flow to the item again. Microsoft describes inheritance as a way to assign and manage permissions in its Access Control Overview.
Disable inheritance and keep the current inherited entries
$acl = Get-Acl -Path $path
$acl.SetAccessRuleProtection($true, $true)
Set-Acl -Path $path -AclObject $acl -WhatIf
The first $true disables inheritance; the second preserves inherited entries as explicit entries on the item.
Disable inheritance and remove inherited entries
$acl = Get-Acl -Path $path
$acl.SetAccessRuleProtection($true, $false)
Set-Acl -Path $path -AclObject $acl -WhatIf
Use this only when removing those entries is intended; access previously granted through the parent may no longer be available.
Re-enable inheritance
$acl = Get-Acl -Path $path
$acl.SetAccessRuleProtection($false, $false)
Set-Acl -Path $path -AclObject $acl -WhatIf
After reviewing the preview, apply the descriptor without -WhatIf. The method changes how parent permissions relate to the item, so choose the behavior deliberately rather than treating inheritance as a cosmetic setting. See Microsoft’s SetAccessRuleProtection documentation.
Free tools Windows power users keep installed
One-click scans. No signup required.
Best Value
Use icacls for recursive grants and ACL backups
icacls.exe is a Windows command-line alternative that can be called from PowerShell. It is convenient for recursive changes, DACL save and restore, and permission masks such as RX for read and execute, M for modify, and F for full access. For example:
icacls.exe 'C:DataReports' /grant 'CONTOSOAnalysts:(OI)(CI)(RX)' /T /C
icacls.exe 'C:DataReports*' /save 'C:Tempreports.acl' /T /C
icacls.exe 'C:DataReports' /restore 'C:Tempreports.acl' /C
In the grant, (OI) means object inherit and (CI) means container inherit; together they make the entry inheritable by files and directories. /T traverses the tree, while /C continues after errors. The save command exports DACL information for the matched files and directories, and restore applies saved information to the specified location. Confirm the intended paths and keep the backup somewhere safe before making a bulk change. Microsoft documents icacls masks, traversal, and save/restore in its icacls reference, last updated June 9, 2025; it replaces the deprecated cacls command.
| Task | PowerShell ACL objects | icacls.exe |
|---|---|---|
| Readability and script composition | Work with named ACL and rule objects, then apply the descriptor with Set-Acl. |
Compact command-line syntax for grants and other ACL operations. |
| Inheritance and propagation | Specify inheritance and propagation in a FileSystemAccessRule; control protection through SetAccessRuleProtection. |
Specify object and container inheritance with flags such as (OI) and (CI). |
| Recursive traversal | Enumerate descendants with Get-ChildItem -Recurse and update each ACL. |
Use /T to traverse the directory tree. |
| Preview and recovery | Set-Acl -WhatIf previews the operation; export and restore are not shown here as a native ACL-object workflow. |
Supports DACL save and restore; the examples use /save and /restore. |
| Identity input | Supply the account identity when constructing the access rule. | Accepts friendly names or SIDs. |
Both approaches operate on Windows security descriptors; they do not create different permission models. Choose based on whether object-based scripting and explicit rule construction or concise recursive commands and a save/restore workflow better fit the task.
Check share permissions separately
NTFS permissions belong to the file system; share permissions govern access through the SMB share. Network access depends on both layers, so a successful NTFS ACL change alone does not establish that a user can reach the folder over the network. Inspect and adjust the applicable share permissions separately from the folder’s NTFS ACL. Microsoft’s Access Control Overview covers Windows access-control concepts.
Quick Recap
Prevent common permission-change mistakes
- Test first: Try the command against a disposable folder and retain an ACL export before bulk edits.
- Verify the identity: Check spelling and whether the account is local or domain-based. If needed, use the account’s SID;
icaclsaccepts friendly names and SIDs. - Inspect the whole DACL: A Deny entry or an inherited rule may explain an unexpected result even when the new Allow rule appears correct.
- Account for protected children: A child with inheritance disabled will not simply take on a parent’s inheritable rule.
- Keep the platform in scope: Microsoft documents
Get-AclandSet-Aclas Windows-only cmdlets; do not assume the same .NET ACL behavior on non-Windows platforms. - Use previews for broad changes: Apply
-WhatIfwhile reviewing paths and intended effects, then run without it only when the target set is correct.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

