Windows File and Folder Permissions: NTFS Basics
Windows NTFS permissions describe which users and groups can access a file or folder. A folder’s access control list (ACL) contains entries for identities, allowed or denied rights, and whether those rights inherit to child files and folders.
This guide reads existing permissions, then makes and removes a sample grant on a new lab folder under your profile. Do not use the practice commands on Windows, Program Files, user profile, or production data paths.
Step 1: Open the Security Properties for a Folder
Find the Security Tab in File Explorer
Graphical ViewIn File Explorer, right-click a folder, choose Properties, then open the Security tab. Select Advanced to view detailed permissions and whether an entry is inherited. The visible entries do not always explain a user’s final access by themselves; group membership and, for network access, share permissions also matter.
File Explorer → right-click folder → Properties → Security → AdvancedStep 2: Read the Current ACL from PowerShell
Inspect Owner and Access Entries
Read-Only CheckGet-Acl reads a security descriptor. icacls prints the folder’s access control entries in a compact form. In the output, (I) marks an inherited entry; letters such as R, W, M, and F represent read, write, modify, and full control rights.
$Lab = Join-Path $HOME 'NTFS-Permissions-Lab'Get-Acl -LiteralPath $HOME | Format-List Path, Owner, AccessToStringicacls $HOME❯ View Expected Console Output
C:\Users\Sam BUILTIN\Administrators:(I)(F) NT AUTHORITY\SYSTEM:(I)(F) BUILTIN\Users:(I)(RX) DESKTOP\Sam:(I)(F)Step 3: Create a Dedicated Permissions Lab
Grant Modify Rights Only on the Lab Folder
Practice ChangeCreate a new folder in your profile and grant your current account Modify rights on that folder and its children. (OI) means object inherit, (CI) means container inherit, and M means Modify. This adds an allow entry; any existing inherited rights remain in effect, so it does not reduce access.
$Lab = Join-Path $HOME 'NTFS-Permissions-Lab'New-Item -ItemType Directory -Path $Lab -Force$Identity = [System.Security.Principal.WindowsIdentity]::GetCurrent().Nameicacls $Lab /grant "$($Identity):(OI)(CI)M"❯ View Expected Console Output
processed file: C:\Users\Sam\NTFS-Permissions-LabSuccessfully processed 1 files; Failed processing 0 filesStep 4: Verify the Entry and Its Inheritance Flags
Read Back the Lab Folder's Permissions
VerifyRe-read the lab folder ACL and confirm that the current account has an explicit Modify entry with object and container inheritance. The same icacls output can show inherited entries from the parent alongside the explicit lab grant.
Get-Acl -LiteralPath $Lab | Format-List Owner, AccessToStringicacls $Lab❯ View Expected Console Output
DESKTOP\Sam:(OI)(CI)(M)Step 5: Remove the Practice Grant
Clean Up the Explicit ACE You Added
Practice CleanupRemove the explicit grant for your current account from this dedicated lab folder, then inspect the result. This does not remove inherited permissions. The command is scoped to the lab path stored in $Lab; do not substitute a system or production path.
icacls $Lab /remove:g $Identityicacls $Lab❯ View Expected Console Output
Successfully processed 1 files; Failed processing 0 files