Access Control Model
Enables control on the ability of a process to access objects and other resources in active directory based on:

It is a list of Access Control Entries (ACE) – ACE corresponds to individual permission or audits access. Who has permission and what can be done on an object?
Get the ACLs associated with a specified object
Get-DomainObjectAcl -Identity studentuser47 –ResolveGUIDs

Get-DomainObjectAcl -Identity studentuser47 -ResolveGUIDs | select SecurityIdentifier , ActiveDirectoryRights, ObjectDN, AceType

Get-DomainObjectAcl -Searchbase "LDAP://CN=Domain Admins,CN=Users,DC=us,DC=techcorp,DC=local" -ResolveGUIDs

Get-DomainObjectAcl -Identity "Domain Admins" -ResolveGUIDs

Get-DomainObjectAcl -Searchbase "LDAP://CN=Domain Admins,CN=Users,DC=us,DC=techcorp,DC=local" -ResolveGUIDs | select SecurityIdentifier , ActiveDirectoryRights, ObjectDN, AceType

(Get-Acl 'AD:\CN=Administrator,CN=Users,DC=us,DC=techcorp,DC=local').Access