Skip to content

Windows File and Folder Permissions: NTFS Basics

Windows NTFS permissions describe which users and groups can access a file or folder. A folder’s access control list (ACL) contains entries for identities, allowed or denied rights, and whether those rights inherit to child files and folders.

This guide reads existing permissions, then makes and removes a sample grant on a new lab folder under your profile. Do not use the practice commands on Windows, Program Files, user profile, or production data paths.


Step 1: Open the Security Properties for a Folder

01

Find the Security Tab in File Explorer

Graphical View

In File Explorer, right-click a folder, choose Properties, then open the Security tab. Select Advanced to view detailed permissions and whether an entry is inherited. The visible entries do not always explain a user’s final access by themselves; group membership and, for network access, share permissions also matter.

File Explorer → right-click folder → Properties → Security → Advanced

Step 2: Read the Current ACL from PowerShell

02

Inspect Owner and Access Entries

Read-Only Check

Get-Acl reads a security descriptor. icacls prints the folder’s access control entries in a compact form. In the output, (I) marks an inherited entry; letters such as R, W, M, and F represent read, write, modify, and full control rights.

Terminal window
$Lab = Join-Path $HOME 'NTFS-Permissions-Lab'
Get-Acl -LiteralPath $HOME | Format-List Path, Owner, AccessToString
icacls $HOME
❯ View Expected Console Output
C:\Users\Sam BUILTIN\Administrators:(I)(F)
NT AUTHORITY\SYSTEM:(I)(F)
BUILTIN\Users:(I)(RX)
DESKTOP\Sam:(I)(F)

Step 3: Create a Dedicated Permissions Lab

03

Grant Modify Rights Only on the Lab Folder

Practice Change

Create a new folder in your profile and grant your current account Modify rights on that folder and its children. (OI) means object inherit, (CI) means container inherit, and M means Modify. This adds an allow entry; any existing inherited rights remain in effect, so it does not reduce access.

Terminal window
$Lab = Join-Path $HOME 'NTFS-Permissions-Lab'
New-Item -ItemType Directory -Path $Lab -Force
$Identity = [System.Security.Principal.WindowsIdentity]::GetCurrent().Name
icacls $Lab /grant "$($Identity):(OI)(CI)M"
❯ View Expected Console Output
processed file: C:\Users\Sam\NTFS-Permissions-Lab
Successfully processed 1 files; Failed processing 0 files

Step 4: Verify the Entry and Its Inheritance Flags

04

Read Back the Lab Folder's Permissions

Verify

Re-read the lab folder ACL and confirm that the current account has an explicit Modify entry with object and container inheritance. The same icacls output can show inherited entries from the parent alongside the explicit lab grant.

Terminal window
Get-Acl -LiteralPath $Lab | Format-List Owner, AccessToString
icacls $Lab
❯ View Expected Console Output
DESKTOP\Sam:(OI)(CI)(M)

Step 5: Remove the Practice Grant

05

Clean Up the Explicit ACE You Added

Practice Cleanup

Remove the explicit grant for your current account from this dedicated lab folder, then inspect the result. This does not remove inherited permissions. The command is scoped to the lab path stored in $Lab; do not substitute a system or production path.

Terminal window
icacls $Lab /remove:g $Identity
icacls $Lab
❯ View Expected Console Output
Successfully processed 1 files; Failed processing 0 files

References

Comments