An access control entry is a single rule that says who can do what with a file or folder on your computer

When you store a file on your computer, Windows or Mac keeps track of who is allowed to open it, change it, or delete it. An access control entry (often shortened to ACE) is one of those rules. Think of it as a single line in a permission slip: "User Sarah can read this document" or "The Guest account cannot open this folder." Your operating system checks these entries every time someone tries to access a file, and either allows or blocks the action based on what the entry says.

Access control entries are invisible to most people most of the time. You only see them when you right-click a file, choose Properties or Get Info, and look at the Sharing & Permissions tab. But they are working constantly in the background, protecting your files from being read, modified, or deleted by people or programs you did not intend to give that power to.

Key Takeaways

  • An access control entry is a single permission rule that specifies what one user or group can do with one file or folder.
  • Each entry contains three pieces of information: who (the user or group), what action (read, write, delete), and which file or folder it applies to.
  • Multiple entries stack together to form an access control list, which is the complete set of permissions for that file.
  • On Windows, you can view and edit access control entries by right-clicking a file, choosing Properties, and going to the Security tab.
  • Changing access control entries incorrectly can lock you out of your own files, so most people should leave them at their default settings.

How an access control entry is structured

Every access control entry has three core parts. The first is the principal — the user, group, or program that the rule applies to. On your home computer, this might be your own user account, the Guest account, or a group like "Administrators." In a workplace, it could be a department or a specific person.

The second part is the permission type — what action the principal is allowed or denied. Common permissions include Read (open and view the file), Write (change or save over the file), Execute (run the file if it is a program), and Delete (remove the file). Some systems break these down further: on Windows, you might see "Modify," "Read & Execute," or "List Folder Contents."

The third part is whether the entry allows or denies that action. Most entries are "allow" rules, but you can also create "deny" rules that explicitly block someone from doing something, even if another rule would otherwise let them. A deny rule always wins over an allow rule.

Access control entries versus access control lists

The terms sound similar, and they are related, but they are not the same thing. An access control list (ACL) is the complete collection of all access control entries for one file or folder. If a file has five different rules — one for you, one for your spouse, one for Administrators, one for Guest, and one that denies a specific program — then that file has one ACL containing five ACEs.

Think of it like a guest list for a party. Each individual entry on the list ("Sarah can bring a plus-one," "Marcus cannot bring pets") is an access control entry. The entire guest list together is the access control list. Your operating system reads the whole list before deciding whether to let someone in.

Where you see access control entries on Windows

On Windows, access control entries are managed through the NTFS file system, which is the standard way Windows stores files on modern computers. To view the entries for a file or folder, right-click it, select Properties, and go to the Security tab. You will see a list of users and groups, and if you click on one and then click Edit, you can see what permissions that principal has.

The permissions shown in that dialog are the individual access control entries. For example, you might see "SYSTEM" with "Full Control" checked, your own username with "Modify" checked, and "Users" with "Read & Execute" and "Read" checked. Each of those is one access control entry. If you want to change who can do what with that file, you would add, remove, or modify entries here — though Windows will warn you if you are about to change permissions on a system file.

Most people never need to touch these settings. Windows sets sensible defaults when you create a file: you can do anything with it, other users on your computer can read it but not change it, and Guest accounts have very limited access. Changing entries yourself can accidentally lock you out of your own files, so only do this if you understand what you are changing.

Where you see access control entries on Mac

On Mac, access control entries work similarly but the interface is different. Right-click a file or folder, select Get Info, and scroll down to Sharing & Permissions. You will see a list of users and groups with a dropdown menu next to each one showing their access level: Read & Write, Read Only, Write Only, or None.

Each of those dropdowns represents one access control entry. If you change a user from "Read Only" to "Read & Write," you are modifying that entry. Unlike Windows, Mac does not show as many granular permission types — you are mostly choosing between read, write, or both — but the concept is identical. The operating system checks these entries before letting anyone open, change, or delete the file.

Why access control entries matter for security

Access control entries are one of the main ways your operating system prevents unauthorized access to your files. If you store a document with sensitive information — tax returns, medical records, passwords — the access control entries on that file are what stop other people on your computer from reading it. When you share a folder with a family member or coworker, you are creating access control entries that let them read or edit files in that folder without giving them access to everything else on your computer.

They also protect you from malicious programs. When you install software, part of what the installer does is set access control entries so that the program can only read and write to the folders it needs. A well-behaved program should not have permission to read your Documents folder or your email. If a program is compromised or behaves maliciously, those access control entries limit the damage it can do.

That said, access control entries are not a substitute for strong passwords or encryption. Someone with physical access to your computer, or someone who knows your password, can usually change the access control entries on their own files. And if your entire hard drive is encrypted (as it should be), access control entries are a second layer of protection, not the first one.

Common mistakes when changing access control entries

The most common mistake is removing your own access to a file by accident. If you delete your user account from the access control list, or change your permissions to "None," you may not be able to open that file again without administrator help. Windows will sometimes let you take ownership of the file and fix it yourself, but this is not may provide.

Another mistake is making a file world-readable when you meant to share it with one person. If you change the "Everyone" group to "Read," then literally anyone on your network (or anyone who gains access to your computer) can read that file. It is usually safer to add the specific person's username to the access control list instead of using broad groups.

A third mistake is not realizing that access control entries are inherited. If you change permissions on a folder, all the files inside it usually inherit those same permissions. If you make a folder world-readable, every file in it becomes world-readable too. This is useful when you want to change many files at once, but dangerous if you do not realize it is happening.

Frequently Asked Questions

Can I see access control entries on my phone?

Not in the same way as on a computer. Phones use a different permission system — when you install an app, you grant it permission to access your camera, location, contacts, and so on. These are similar in concept to access control entries, but the interface is much simpler and you cannot edit them the way you can on a computer. You can only grant or deny each permission as a whole.

What does "Full Control" mean in an access control entry?

Full Control means the user can read, write, delete, and change the permissions on that file or folder. It is the highest level of access. On a file you own, you should always have Full Control. On files you share with others, you usually want to give them Read or Read & Write instead, depending on whether you want them to be able to change the file.

If I delete an access control entry, does the file get deleted?

No. Deleting an access control entry removes that user's permission to access the file, but the file itself stays on your computer. If you delete your own entry by mistake, you may not be able to open the file anymore, but it is still there. You can usually fix this by taking ownership of the file through the Properties dialog.

Do access control entries work the same way on external hard drives?

It depends on the file system. If your external drive is formatted as NTFS (Windows) or APFS (Mac), then yes, access control entries work the same way. If it is formatted as FAT32 or exFAT, then it does not support access control entries at all — anyone who can plug in the drive can read any file on it. This is why external drives are often formatted as FAT32 for compatibility, even though it means giving up permission controls.

Can I use access control entries to prevent someone from deleting a file?

You can deny them the Delete permission, but this is not foolproof. If someone has Write permission on the folder that contains the file, they can usually delete the file anyway by deleting the folder. To truly protect a file from deletion, you need encryption or a backup system, not just access control entries.