lsacl [ –s | –l ] [ –n ] { [ –f path-name ] | [ –r registry-value-name ] }
–s | –l Specifies short or long format; displays generic rights, by default.
–n Specifies that the numeric security ID (SID) is not to be translated into the user’s name. Use this option if the domain controller is down or if the user’s account has been removed.
–f Reads a security descriptor from a file; allows you to display the contents of the filesidentity.sd and groups.sd.
–f Reads a security descriptor from a file; allows you to display the contents of the files identity.sd and groups.sd.