Trinetri logo
Device Control

File Access Control

File Access Control enables organizations to centrally manage and enforce access permissions for files and folders across enterprise endpoints. Administrators can define granular policies for users and groups, restrict unauthorized access, protect sensitive data, and ensure consistent security, compliance, and audit readiness through centralized policy deployment and real-time enforcement.

  • 1 min
  • July 14, 2026

What You'll Learn

  • How to create a File Access Control policy targeting a file or folder path
  • How to define an access control action with a User/Group Principal and Allow/Deny permissions
  • How to add more than one access control action to a single policy
  • How to deploy a File Access Control policy to specific endpoints
  • How to confirm a policy applied successfully via the deployment task output
CTA background

Experience Trinetri Autonomous Platform in Action.

Frequently Asked Questions

What does the Configuration Level field control? Configuration Level sets whether the File Access Control policy is applied at the Computer level, alongside the policy's Name and Description.
What does Apply On Startup do? Enabling this checkbox re-applies the file access control action(s) whenever the endpoint starts up, rather than only at the time of deployment.
What do I configure inside an access control action? Each action sets a Target Type (such as File) and a Path (for example a folder like D:\Finance_FIM\), a User/Group Principal the rule applies to (such as Everyone), an Action mode, and a Permissions table covering Read, Write, Execute, Modify, and Full Control, each independently switchable to Allow or Deny.
Can a single policy cover more than one path or rule? Yes. The Add Access Control Action option adds another action block (Action 2, Action 3, and so on) to the same policy, each with its own Target Type, Path, Principal, and Permissions.
How do I deploy a File Access Control policy to specific machines? From Policy Deployments, create a new deployment, set the Scope to Specific Endpoints, choose the target endpoint(s), select the File Access Control Policy and a Deployment Policy, and optionally choose who to Notify before publishing.
How do I confirm a File Access Control policy applied correctly? Opening the deployment's task shows a File Control Output log, which reports lines such as Starting file access control task, Applying file access control, and File access control applied successfully for the targeted endpoint.