Deletes the access control entries (ACEs) specified with the /ACL
qualifier and replaces them with those specified with /REPLACE.
Any ACEs specified with the /ACL qualifier must exist and must be
specified in the order in which they appear in the current ACL.