How to Store NTFS Permissions in 7-Zip CLI

This guide explains how to preserve NTFS file security permissions when creating archives using the 7-Zip command-line interface (CLI). By default, standard archiving discards access control lists (ACLs) and security descriptors, but using a specific CLI parameter ensures all file ownership and permission data remain intact during compression and extraction.

The Parameter: -sni

The parameter used to store and restore NTFS file security information in the 7-Zip CLI is -sni.

The -sni switch instructs 7-Zip to read and store NT security information (ownership, auditing, and discretionary access control lists) inside the archive. This switch is supported when creating .7z and .wim archives.

How to Create an Archive with NTFS Permissions

To back up files while preserving their security descriptors, append -sni to the a (add) command:

7z a -sni backup.7z "C:\Data\SecureFolder"

In this command:

  • a tells 7-Zip to create an archive.
  • -sni enables the preservation of NTFS security permissions.
  • backup.7z is the target archive name.
  • "C:\Data\SecureFolder" is the source path.

How to Extract and Restore NTFS Permissions

To restore the stored permissions during extraction, use the x (extract with full paths) command along with the -sni switch:

7z x -sni backup.7z -o"C:\RestoredData"

If you do not include -sni during extraction, 7-Zip will extract the files using the default permissions inherited from the destination directory instead of restoring the original security settings.

Important Requirements

  • Administrator Privileges: You must run the Command Prompt or PowerShell as an Administrator to both read and write certain security descriptors (such as SACLs and ownership).
  • File System Compatibility: Storing and restoring permissions requires an NTFS file system on the target storage drive.
  • Alternate Data Streams: The -sni parameter only saves security permissions. If your files also contain NTFS Alternate Data Streams, combine -sni with the -sns parameter (-sni -sns) to capture both.