Discovering SMB Share Permissions on Windows Servers with PowerShell

SMB share permissions control who can access a Windows file share over the network. This example queries the share access control entries (ACEs) on a remote Windows server and exports them to a CSV file. It uses the SmbShare module through a CIM session, rather than reading a folder ACL and treating it as a share ACL.

Requirements

Run this from a Windows computer with PowerShell and network access to the target server. Remote CIM/WSMan connectivity must be configured, and the account needs permission to enumerate shares and read their access entries. Test the connection and authorization with your server administrator if session creation fails. The script does not change permissions.

Export remote SMB share permissions

$serverName = Read-Host "Enter the server name"
$timestamp = Get-Date -Format "yyyyMMdd-HHmmss"
$outputFile = Join-Path $env:TEMP "SharePermissions-$timestamp.csv"
$cimSession = $null

try {
    $cimSession = New-CimSession -ComputerName $serverName -ErrorAction Stop
    $shares = Get-SmbShare -CimSession $cimSession -ErrorAction Stop |
        Where-Object { -not $_.Special }

    $results = foreach ($share in $shares) {
        Get-SmbShareAccess -Name $share.Name -CimSession $cimSession -ErrorAction Stop |
            Select-Object @{Name = "Server"; Expression = { $serverName }},
                Name, ScopeName, AccountName, AccessControlType, AccessRight
    }

    if ($results) {
        $results | Export-Csv -Path $outputFile -NoTypeInformation
        Write-Host "Exported share permissions to $outputFile"
    }
    else {
        Write-Warning "No non-special SMB shares or access entries were returned."
    }
}
catch {
    Write-Error "Unable to query SMB share permissions on '$serverName': $_"
}
finally {
    if ($cimSession) {
        Remove-CimSession -CimSession $cimSession
    }
}

Share permissions are not the whole access check

Get-SmbShareAccess reports the SMB share ACL. A user’s effective access to files also depends on the NTFS permissions on the shared folder and its contents. Review both layers when auditing access; do not assume that the share ACL alone describes the final permissions. This script intentionally exports share-level entries only.

The query excludes special administrative shares. Remove the Where-Object { -not $_.Special } filter if your audit explicitly needs them and your policy permits it. The output is written to the current user’s temporary folder; move it to an approved location and protect it according to your access-reporting policy.

See Microsoft’s documentation for Get-SmbShareAccess and Get-SmbShare for supported parameters and behavior. Validate the script in a test environment before using it for an audit.