Some IdentityReferences cannot be translated to [System.Security.Principal.SecurityIdentifier] because they don't map to a SecurityIdentifier. An example is: IdentityReference : APPLICATION PACKAGE AUTHORITY\ALL APPLICATION PACKAGES In such case, it is better to catch the exception and treat it as $false.