Skip to content

Security_SetServicePermissions

Sets permissions on a Service for a Trustee.

sRight can be one of the following values:

  • F: Full Control
  • R: Generic Read
  • W: Generic Write
  • X: Generic Execute
  • L: Read Control
  • Q: Query Service Configuration
  • S: Query Service Status
  • E: Enumerate Dependent Services
  • C: Service Change Configuration
  • T: Start Service
  • O: Stop Service
  • P: Pause/Continue Service
  • I: Interrogate Service
  • U: Service User-Defined Control Commands

Security_SetServicePermissions(sService, sTrustee, sRight) As Boolean

Name of the service (the service name, not the display name)

A trustee is a user or group. The trustee can be a name in the format Domain\User or a well-known SID (security identifier). Some built-in group names, such as Power Users, are localized, so use the SID for those.

Access right to set. To set more than one right, combine the letters in one string, for example "TO".

The function returns False if SubInACL.exe can’t be found, or if SubInACL reports an error. See Security functions for where the library looks for SubInACL.exe.

If bStatus Then bStatus = Security_SetServicePermissions("Service", "S-1-5-4", "F")

Scripting Guidelines

Security functions Security_DenyServiceAccess Security_RevokeServicePermissions Constants Package Property Variables