Private/Set-NSPToolkitRootAcl.ps1
|
function Set-NSPToolkitRootAcl { # Administrators + SYSTEM full control, inheritance from ProgramData cut (Users can read # ProgramData by default, and these folders hold client answers). Best effort: a failure (not # elevated, non-NTFS) is a warning, never an error. param([Parameter(Mandatory)][string]$Path) try { $acl = New-Object Security.AccessControl.DirectorySecurity $acl.SetAccessRuleProtection($true, $false) $inherit = [Security.AccessControl.InheritanceFlags]'ContainerInherit, ObjectInherit' foreach ($sid in 'S-1-5-32-544', 'S-1-5-18') { $id = New-Object Security.Principal.SecurityIdentifier($sid) $rule = New-Object Security.AccessControl.FileSystemAccessRule($id, 'FullControl', $inherit, 'None', 'Allow') $acl.AddAccessRule($rule) } Set-Acl -LiteralPath $Path -AclObject $acl -ErrorAction Stop } catch { Write-Warning "Could not restrict permissions on ${Path}: $($_.Exception.Message). Client answers there may be readable by non-administrators." } } |