An access control list is a set of rules that decides who can do what with a file, folder, or network resource
An access control list, or ACL, is a list attached to a file, folder, printer, or network device that says which users or groups can access it and what they're allowed to do. Instead of a simple "everyone can read this" or "nobody can touch this," an ACL lets you be specific: you might let one person edit a document, let another person only read it, and block a third person entirely.
ACLs exist on nearly every operating system and network. Windows, Mac, Linux, and most network equipment use them. When you right-click a file on Windows and look at its properties, the "Security" tab shows the ACL. On a Mac, it's under "Get Info" and "Sharing & Permissions." On a network, a router or server's ACL controls which devices can connect and what they can do once they're connected.
The core idea is the same everywhere: instead of trusting everyone equally or locking everyone out equally, you create a list of exceptions. Each entry in the list names a user or group and grants or denies specific permissions.
Key Takeaways
- An ACL is a list of rules attached to a file, folder, or device that specifies which users or groups can access it and what actions they can perform.
- Each entry in an ACL typically includes a user or group name, a permission type (read, write, execute, delete), and whether that permission is allowed or denied.
- ACLs exist on personal computers, network servers, routers, and cloud storage services, and they work the same way across all of them.
- Denying a permission in an ACL always overrides allowing it, so a single "deny" rule blocks access even if another rule says "allow."
How an ACL entry is structured
Each line in an access control list contains three pieces of information: who, what, and yes or no. The "who" is a user account or a group of accounts. The "what" is a specific permission, like read, write, execute, or delete. The "yes or no" is whether that permission is granted or denied.
On a Windows computer, if you open a file's properties and click the Security tab, you see a list of users and groups on the left. When you click one, the permissions appear on the right: "Full Control," "Modify," "Read & Execute," "Read," and "Write." Each one has a checkbox that can be checked (allowed), unchecked (not mentioned), or explicitly denied. A denied permission always wins. If one rule says "Alice can read this file" and another says "Alice cannot read this file," the deny wins and Alice cannot read it.
Network ACLs work the same way but control traffic instead of file access. A network ACL on a router might say "allow traffic from 192.168.1.100 to port 443" or "deny all traffic from 10.0.0.0/8." The router checks each packet against the list in order and applies the first matching rule.
Where you encounter ACLs in daily use
On your personal computer, ACLs control which user accounts can read, edit, or delete your files and folders. When you create a new user account on Windows or Mac, the system automatically sets up ACLs so that user can access their own files but not yours. If you share a folder with a coworker over the network, you're creating an ACL entry that grants them read or write permission to that folder.
Cloud storage services like Google Drive, OneDrive, and Dropbox use ACLs too, though they call them "sharing settings." When you right-click a file and choose "Share," you're creating an ACL entry. You pick a person or group, decide whether they can view, comment, or edit, and the service stores that rule. The next time that person tries to access the file, the service checks the ACL and either allows or blocks them.
Network printers use ACLs to control who can print. A company might set up an ACL so that only employees in the Marketing department can use the color printer, while everyone can use the black-and-white one. Routers and firewalls use ACLs to control which devices can connect to the network and which traffic is allowed in or out.
The difference between ACLs and other permission systems
ACLs are not the only way to control access. Some systems use role-based access control, or RBAC, which assigns permissions to job titles or roles instead of individual people. Instead of listing "Alice can edit this document," RBAC says "anyone with the Editor role can edit this document." When Alice gets promoted and her role changes, her permissions change automatically without anyone having to update the ACL.
Other systems use attribute-based access control, or ABAC, which makes decisions based on attributes like time of day, location, or device type. An ABAC rule might say "allow access only if the user is in the office and logging in from a company computer." ACLs are simpler and older; they just list who can do what. RBAC and ABAC are more flexible for large organizations but harder to set up and understand.
Most real systems use a mix. A company might use RBAC for broad permissions (editors, viewers, admins) and then use ACLs to make exceptions for specific people or situations.
Common mistakes when setting up ACLs
The most common mistake is leaving the default permissions too open. When you create a new folder, the system might automatically grant "Everyone" read access. If you put sensitive information in that folder and forget to change the ACL, anyone on the network can see it. Always check the default permissions and tighten them before adding sensitive files.
Another mistake is not understanding that deny always wins. If you're trying to give a group of people access to a folder but one person should be blocked, you can't just add them to the group and hope. You have to explicitly deny them in the ACL, or remove them from the group. Leaving a permission unchecked is not the same as denying it; it just means the rule doesn't apply.
A third mistake is forgetting to update ACLs when people leave or change roles. If an employee leaves and you don't remove their name from the ACL, they might still be able to access files if they remember the password or if their account is reactivated. Regular audits of who has access to what are important for security.
How to read and change an ACL on your own computer
On Windows, right-click a file or folder, choose "Properties," and click the "Security" tab. You see a list of users and groups. Click one to see their permissions. To add a new user, click "Edit," then "Add," and type the username. To remove someone, click their name and click "Remove." To change their permissions, click their name, then check or uncheck the boxes next to each permission type.
On Mac, right-click a file or folder, choose "Get Info," and scroll down to "Sharing & Permissions." You see a list of users and groups. Click the padlock icon at the bottom to unlock it (you'll need your password), then click the "+" button to add a user or the "-" button to remove one. Click the dropdown next to each user to change their permission level from "Read Only" to "Read & Write" or vice versa.
On Linux, the command line is often faster. The ls -l command shows permissions in a short form like "rwxr-xr--". The chmod command changes them, and the chown command changes the owner. These are more powerful but also more dangerous if you make a mistake, so be careful.
ACLs on networks and servers
Network ACLs work at a different level than file ACLs. Instead of controlling access to a single file, they control traffic flowing through a network device. A router or firewall checks every packet against the ACL and decides whether to allow it through, block it, or send it somewhere else.
Network ACLs are usually written in a text format that looks like a list of rules. Each rule specifies a source address, a destination address, a port or protocol, and an action (allow or deny). The device checks rules in order from top to bottom and stops at the first match. This means the order matters: if you have a rule that allows all traffic followed by a rule that denies traffic from a specific address, the allow rule wins because it matches first.
Cloud services and managed networks often hide the ACL from you and instead offer a simpler interface. AWS, Azure, and Google Cloud all use ACLs behind the scenes, but they present them as "security groups," "network security groups," or "firewall rules." The concept is the same: you're listing who can access what and what they can do.
Frequently Asked Questions
What happens if an ACL is empty or doesn't exist?
If a file has no ACL or an empty one, the behavior depends on the system. On most systems, the default is to deny access to everyone except the owner. Some systems inherit permissions from the parent folder. It's safer to assume that an empty ACL means nobody can access something, but you should check your operating system's documentation to be sure.
Can I use an ACL to control access to a file on a USB drive?
It depends on the file system. If the USB drive is formatted as NTFS (Windows) or HFS+ (Mac), it can store ACLs. If it's formatted as FAT32 or exFAT, it cannot. When you copy a file from an NTFS drive to a FAT32 drive, the ACL is lost. This is one reason why sharing files on USB drives can be risky: the permissions don't travel with the file.
Do I need to understand ACLs to use my computer safely?
Not in detail, but it helps to know that they exist and that you can change them. Most people only need to know how to share a folder with a coworker or how to check who has access to a sensitive file. If you work in IT or security, you'll need to understand them much more deeply.
What's the difference between an ACL and a password?
A password controls whether you can log in at all. An ACL controls what you can do once you're logged in. You might have the password to a computer, but the ACL on a specific folder might prevent you from reading it. They work together: the password gets you in the door, and the ACL decides which rooms you can enter.