Can UnRAR Preserve Windows ACLs on Extraction?

Yes, UnRAR can preserve and restore Windows Access Control Lists (ACLs) during extraction, provided the original archive was created with security data included. This guide explains how UnRAR handles Windows security permissions, the specific command-line switches required during extraction, and the technical prerequisites needed to apply file permissions successfully.

Archive Creation Requirements

Before UnRAR can restore any permissions, the RAR archive must contain the original NTFS security descriptor data. Standard RAR compression ignores ACLs by default to reduce archive size and improve cross-platform compatibility.

To save security metadata during archive creation, the archive must be created using WinRAR or the RAR command-line utility with the -ow switch:

rar a -ow backup.rar C:\Path\To\Files

If an archive was compressed without this flag, no ACL metadata exists inside the archive, making permission restoration impossible upon extraction.

Extracting with ACLs Using the Command Line

To restore Windows security permissions during extraction, execute unrar using the -ow switch. This flag tells the utility to process file owner, group, and access control information.

Use the following syntax in an elevated command prompt:

unrar x -ow backup.rar C:\Target\Directory\
  • x: Instructs UnRAR to extract files with full paths.
  • -ow: Applies the stored NTFS owner and ACL settings to the extracted files and directories.

Mandatory System Prerequisites

Even with the correct archive and command parameters, Windows security models impose strict technical requirements:

  1. Target File System: The destination drive must use the NTFS file system. File systems such as FAT32, exFAT, or standard network shares without NTFS tunneling do not support Windows ACLs and will discard the metadata.
  2. Elevated Privileges: Extracting ACLs requires elevated administrative rights. The command prompt or terminal must be launched using "Run as administrator" to grant SeRestorePrivilege and SeSecurityPrivilege, which allow the operating system to set file ownership and discretionary access control lists (DACLs).
  3. Domain and SID Validity: ACLs are tied to Windows Security Identifiers (SIDs). If an archive is extracted on a different machine or domain where the original user and group SIDs do not exist, Windows will display unresolved SIDs (e.g., Account Unknown) in the file security properties.

Platform Limitations

The preservation of Windows ACLs is strictly supported in Windows environments. While Linux and macOS versions of the unrar tool can unpack file content from archives containing Windows security descriptors, they cannot translate NTFS ACLs into native POSIX permissions. Similarly, standard graphical extraction tools like 7-Zip will extract the raw file contents but ignore proprietary RAR security metadata, resulting in files inheriting the default permissions of the destination folder instead.