# Remove NTFS permissions multiple users and folders

**URL:** <https://forums.powershell.org/t/remove-ntfs-permissions-multiple-users-and-folders/20051>\
**Category:** PowerShell Help\
**Created:** [August 1, 2022, 4:30pm UTC](https://forums.powershell.org/t/remove-ntfs-permissions-multiple-users-and-folders/20051 "2022-08-01T16:30:40Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![whitz3nd](https://avatars.discourse-cdn.com/v4/letter/w/c2a13f/32.png) [@whitz3nd](https://forums.powershell.org/u/whitz3nd)\
**Post date:** [August 1, 2022, 4:30pm UTC](https://forums.powershell.org/t/remove-ntfs-permissions-multiple-users-and-folders/20051/1 "2022-08-01T16:30:40Z")

</div>

I am working on a powershell script that will be removing NTFS permissions to many folders at once via a csv that has the users for that folder.

I am running into an issue with the last part which is the $variable.removeaccessrule($accessrule). I am getting the following error when testing the script:

Exception calling “RemoveAccessRule” with “1” argument(s): “Some or all identity references could not be translated.”  
At C:\scripts\Remove\_explicit\_Full Control\_use.ps1:13 char:2

- $acl.RemoveAccessRule($AccessRule)
- 

```auto
+ CategoryInfo : NotSpecified: (:) [], MethodInvocationException
+ FullyQualifiedErrorId : IdentityNotMappedException

```

Here is the script I am working with:

$sprdsheetdir = "C:\scripts\exports\ftproot2" #directory where users csv resides  
$folderdir = "C:\scripts\Testing" #directory where folders needing perm change  
$sheets = get-childitem $sprdsheetdir  
$folderdirs = get-childitem $folderdir

foreach($sheet in $sheets)  
{  
$test = import-csv “C:\scripts\exports\ftproot2$sheet”  
$acluser = $test.IdentityReference  
$acl = foreach($folder in $folderdirs){get-acl -path “C:\scripts\Testing$folder”}  
$AccessRule = New-Object System.Security.AccessControl.FileSystemAccessRule($acluser,“FullControl”,“ContainerInherit,ObjectInherit”,“None”,“Allow”)  
$acl.RemoveAccessRule($AccessRule)  
$acl | set-acl -Path “C:\scripts\Testing$folder”  
}

After I have run the script and get the above error. I check to see what is stored in the $AccessRule variable and I get the following:

FileSystemRights : FullControl  
AccessControlType : Allow  
IdentityReference : domain\user1 domain\user2 domain\user3 domain\user4 domain\user5  
IsInherited : False  
InheritanceFlags : ContainerInherit, ObjectInherit  
PropagationFlags : None

which is what I am expecting. I have a script that does reference a .csv and is able to remove the users, but it is only for one folder. I have close to 200 in this one directory I need to remove explicit permissions and doing it one at a time is not really optimal.

I am sure the script could be written cleaner, but, it is working up to this one point. I would greatly appreciate any and all input on what I am missing or need to alter to get this to work.

---

<div class="post-metadata">

**Author:** ![Olaf](https://sea1.discourse-cdn.com/flex019/user_avatar/forums.powershell.org/olaf/32/992_2.png) [@Olaf](https://forums.powershell.org/u/Olaf)\
**Post date:** [August 1, 2022, 4:33pm UTC](https://forums.powershell.org/t/remove-ntfs-permissions-multiple-users-and-folders/20051/2 "2022-08-01T16:33:09Z")

</div>

Chris,  
Welcome to the forum. 👋🏽

Before we proceed could you please help us by formatting your code, sample data, console output or error messages as code using the _preformatted text_ button ( **\</\>** ). Simply place your cursor on an empty line, click the button and paste your code.

Thanks in advance

[How to format code in PowerShell.org](https://us1.discourse-cdn.com/flex019/uploads/powershell/original/2X/b/bee50c628238f2c076c0504efb6b15f2fb11f002.gif) \<---- Click 👆🏽 😉

---

<div class="post-metadata">

**Author:** ![dotnVo](https://avatars.discourse-cdn.com/v4/letter/d/4af34b/32.png) [@dotnVo](https://forums.powershell.org/u/dotnVo)\
**Post date:** [May 16, 2024, 8:17pm UTC](https://forums.powershell.org/t/remove-ntfs-permissions-multiple-users-and-folders/20051/3 "2024-05-16T20:17:37Z")

</div>


