Get-Acl
See who can access a file or folder
(Get-Acl -Path .\docs).Access | Select-Object IdentityReference, FileSystemRights, AccessControlType
- Works on
- Windows
- PowerShell
- 5.1 and later
- Reference
- Microsoft Learn: Get-Acl
Every file and folder on Windows has an access control list (ACL): who is allowed to read, change, or fully control it. Get-Acl reads that list.
The .Access property holds one row per rule:
IdentityReferenceis the user or group, likeBUILTIN\Users.FileSystemRightsis what they can do:ReadAndExecute,Modify,FullControl.AccessControlTypeisAlloworDeny. A Deny rule wins over an Allow rule.
.Owner tells you who owns the item.
Try this
(Get-Acl -Path .\docs).Owner
(Get-Acl -Path .\docs).Access | Where-Object IdentityReference -like '*Users*'
Changing permissions with Set-Acl is easy to get wrong and can lock you out. For one-off changes, the Security tab in the folder's Properties is safer.
Coming from another shell
| Shell | What you might type |
|---|---|
| bash / zsh | ls -ld docs |
| cmd.exe | icacls docs |
More in From bash and From cmd.