NTFS Permissions Report — one-liner generator

Pick a folder, watch the preview, copy the one-liner, run it on the server.

What to scan
-Path

-FilterGroup

Matches names containing this text. Folders never disappear — only their permission lists shrink.

-MaxDepth

0 = just this folder.

-ResolveMembers

Asks Active Directory for the members of each group — slower.

-SuggestGroups

Proposes one security group per folder + access level to replace per-user permissions; turns on member resolution.

What you get

A bare file name is saved to the Desktop of the server you run the command on; a full path like C:\Reports\x.html is used as given. The HTML report opens by itself.

-OutputHTML

Folder tree, anomalies, per-group access — the main output.

-OutputCSV

One row per permission entry.

-GenerateFixScript

icacls commands — all commented out, review before running.

-GroupScript

Two-phase script for the suggested groups — Phase 1 only adds, removals stay commented out.

Advanced options
Advanced — speed, caching, change tracking, console output
-Threads

Speed only — never changes results.

-CacheFile

An existing cache is loaded instead of re-scanning.

-ForceRescan

Only matters with a cache file.

-BaselineFile

The first run records the folders; later runs list what was added, removed or re-permissioned.

-GroupPrefix

Names look like FS-Finance-Modify. Letters, digits, - and _; starts with a letter; max 15. Enabled with group suggestions.

-ShowTree

Verbosity only.