Write DACL is an Active Directory permission that allows a principal to modify the Discretionary Access Control List on an object. In practice, that means the holder can change who has access and what they can do, which can open the door to privilege escalation and broader control over the object.
What Write DACL Means in Active Directory
Write DACL is a delegated permission on an Active Directory object that lets a principal change the object’s discretionary access control list, which in turn changes who can access it and what they can do.
Why Write DACL Matters
Write DACL is not a routine read or modify right, it is a control over the object’s authorization boundary. Because the ACL defines access to the object, the ability to rewrite that ACL can override normal privilege boundaries and make other permissions effectively negotiable.
In practice, this means the right is often treated as highly sensitive on users, groups, computers, OUs, and domain objects. A principal with Write DACL may be able to grant itself additional access, delegate access to others, or alter protections that were supposed to restrict administrative actions.
How Write DACL Is Abused or Applied
Attackers and red teams value Write DACL because it can be a pivot point for privilege escalation. If an account can edit the DACL on a target object, it may be able to add permissions that lead to takeover of that object or to broader directory control, depending on what the object represents and what other rights exist around it.
Defenders should think of it as a control-plane permission, not merely an object permission. The security impact depends on the object’s importance, whether inheritance is involved, and whether the principal can combine Write DACL with other directory rights to expand access.
Common Misunderstandings and Control Implications
Write DACL is sometimes mistaken for a harmless administrative convenience because it does not directly say “full control.” In reality, changing the DACL can be enough to manufacture that outcome indirectly, so it should be reviewed with the same care as other high-impact directory permissions.
Its meaning is also context-dependent. On a low-value object, the risk may be limited; on privileged users, admin groups, GPO-linked containers, or domain-scoped objects, the same permission can become a path to large-scale directory compromise.
Risk and Threat Considerations
Write DACL is attractive to attackers because it can convert partial access into durable control by rewriting permissions rather than exploiting software flaws. Once an attacker can alter access rules on a valuable object, they may be able to preserve access, widen permissions, or stage follow-on escalation through the directory.
Failure mechanism: A principal with Write DACL can add or replace ACEs on the target object, potentially granting itself or an accomplice permissions that were not originally intended.
Impact: This can lead to privilege escalation, unauthorized administrative changes, and broader compromise of directory-managed assets if the affected object is sensitive enough.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 provides the primary governance reference for this term.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST SP 800-53 Rev 5 | AC-6 — Least Privilege | Write DACL can expand access beyond intended privilege boundaries. |
| AC-2 — Account Management | Write DACL assignments are a privileged access entitlement that must be governed. | |
| AU-6 — Audit Review, Analysis, and Reporting | DACL changes are security-relevant directory events that warrant monitoring. | |
| Recommendation — Restrict DACL-editing rights to the smallest set of trusted administrators. Review who holds DACL-editing rights and remove them when not needed. Monitor and review ACL changes on sensitive directory objects for abnormal activity. | ||
Practitioner Guidance
Why practitioners should care: Treat Write DACL as a high-risk permission wherever it touches privileged users, security groups, OUs, or domain objects. It is often the difference between limited access and the ability to rewrite the rules of access themselves.
What to watch for: Unexpected Write DACL assignments, especially when granted through group nesting, delegated administration, or inheritance, deserve immediate review because they can create hidden escalation paths.
Practitioner takeaway: If a principal can change the DACL on an important object, it can often change the security outcome for that object too.
Related resources from NHI Mgmt Group
- How should security teams govern AI tools that write into workspace settings?
- How do security teams decide whether HRIS write-back is safe in joiner automation?
- What breaks when a document parser can write files outside its temp directory?
- How should security teams write an access onboarding and termination policy?
Deepen Your Knowledge
Reviewed and updated by the NHIMG editorial team on September 26, 2026.
NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org