I was playing around with a little tool chml that allows you to do more with IL than icacls. You can set SACL's on files through SDDL strings whereas icacls only lets you set the level, not the qualifier (NX: No execute, NR: No read, NW: no write). icacls