Can UnRAR Preserve Windows ACLs on Extraction?
Yes, UnRAR can preserve and restore Windows Access Control Lists (ACLs) during extraction, provided the original archive was created with security data included. This guide explains how UnRAR handles Windows security permissions, the specific command-line switches required during extraction, and the technical prerequisites needed to apply file permissions successfully.
Archive Creation Requirements
Before UnRAR can restore any permissions, the RAR archive must contain the original NTFS security descriptor data. Standard RAR compression ignores ACLs by default to reduce archive size and improve cross-platform compatibility.
To save security metadata during archive creation, the archive must
be created using WinRAR or the RAR command-line utility with the
-ow switch:
rar a -ow backup.rar C:\Path\To\FilesIf an archive was compressed without this flag, no ACL metadata exists inside the archive, making permission restoration impossible upon extraction.
Extracting with ACLs Using the Command Line
To restore Windows security permissions during extraction, execute
unrar using the -ow switch. This flag tells
the utility to process file owner, group, and access control
information.
Use the following syntax in an elevated command prompt:
unrar x -ow backup.rar C:\Target\Directory\x: Instructs UnRAR to extract files with full paths.-ow: Applies the stored NTFS owner and ACL settings to the extracted files and directories.
Mandatory System Prerequisites
Even with the correct archive and command parameters, Windows security models impose strict technical requirements:
- Target File System: The destination drive must use the NTFS file system. File systems such as FAT32, exFAT, or standard network shares without NTFS tunneling do not support Windows ACLs and will discard the metadata.
- Elevated Privileges: Extracting ACLs requires
elevated administrative rights. The command prompt or terminal must be
launched using "Run as administrator" to grant
SeRestorePrivilegeandSeSecurityPrivilege, which allow the operating system to set file ownership and discretionary access control lists (DACLs). - Domain and SID Validity: ACLs are tied to Windows
Security Identifiers (SIDs). If an archive is extracted on a different
machine or domain where the original user and group SIDs do not exist,
Windows will display unresolved SIDs (e.g.,
Account Unknown) in the file security properties.
Platform Limitations
The preservation of Windows ACLs is strictly supported in Windows
environments. While Linux and macOS versions of the unrar
tool can unpack file content from archives containing Windows security
descriptors, they cannot translate NTFS ACLs into native POSIX
permissions. Similarly, standard graphical extraction tools like 7-Zip
will extract the raw file contents but ignore proprietary RAR security
metadata, resulting in files inheriting the default permissions of the
destination folder instead.