Skip to content

Security_SetRegPermissions

Sets access right for a trustee on a Registry Key.

sRight can be one of the following values:

  • F: Full Control
  • R: Read
  • A: Read Control
  • Q: Query Value
  • S: Set Value
  • C: Create Sub key
  • E: Enumerate Sub keys
  • Y: Notify
  • L: Create Link
  • D: Delete
  • W: Write DAC
  • O: Write owner

To set more than one right, combine the letters in one string, for example "QS". Each letter is applied as a separate right.

Security_SetRegPermissions(sHandle, sKey, sTrustee, sRight, bIncludeSubKeys) As Boolean

Root key: HKLM, HKCU, HKCR, HKU or HKCC. The long names, such as HKEY_LOCAL_MACHINE, also work.

Path of the subkey, for example Software\CapaInstaller

A trustee is a user or group. The trustee can be a name in the format Domain\User or a well-known SID (security identifier). Some built-in group names, such as Power Users, are localized, so use the SID for those.

Access right to set

True also sets the right on all subkeys. False sets it on the key only.

The function returns False if sHandle or a letter in sRight isn’t valid, or if SetACL can’t be found. See Security functions.

If bStatus Then bStatus = Security_SetRegPermissions("HKLM", "Software\CapaInstaller", "S-1-5-4", "F", True)

Scripting Guidelines

Security functions Security_DenyRegAccess Security_RevokeRegPermissions Constants Package Property Variables