About this article
This article was created using an automated generation workflow powered by generative AI. It reviews the official Microsoft bitwise operation specifications for PowerShell and VBA, explaining why flags 1, 2, and 4 are combined using OR and evaluated using AND through small integers.Verification Status: 📘 Official Microsoft specifications verified, not tested on physical PowerShell/VBA devices.
Information Verification Reference Date: October 5, 2026
When reviewing the Windows API or legacy VBA code, option values are often listed as 1、2、4、8 , and these are sometimes combined into a single integer.
This isa bit flag system where each function is assigned to a separate bit.
- Viewing 1, 2, and 4 in Binary
- OR returns 1 if either bit is 1.
- Using AND to check if a feature is enabled
- Just because "addition also equals 3" does not mean they are the same
- Let us change only one place
- Any and All are different
- Why this frequently appears in Windows API constants
- A similar perspective exists in chmod numeric values.
- Pay attention to types when using them in production.
- Daily-Code-Samples
- Official Documentation
Viewing 1, 2, and 4 in Binary
Read = 1 = 0001 Write = 2 = 0010 Delete = 4 = 0100
The positions where 1 occurs for each value do not overlap.
When enabling Read and Write, you can use -bor in PowerShell.
$Read = 1 $Write = 2 $flags = $Read -bor $Write $flags
The result is 3.
In binary, it is
0001 0010 ---- 0011
.
OR returns 1 if either bit is 1.
flowchart LR
A["Read 0001"] --> C["OR"]
B["Write 0010"] --> C
C --> D["0011 = 3"]
In PowerShell, -bor compares each bit of the integers and sets the result to 1 if either or both bits are 1.
In VBA, Or for numeric values acts as a bitwise OR.
Const FlagRead As Long = 1 Const FlagWrite As Long = 2 Dim flags As Long flags = FlagRead Or FlagWrite
Using AND to check if a feature is enabled
Check if Read is included.
PowerShell:
($flags -band $Read) -ne 0
VBA:
(flags And FlagRead) <> 0
0011 AND 0001 is 0001, so it is not zero. In other words, the Read bit is set.
Delete is
0011 AND 0100 = 0000
, so it is not included.
Just because "addition also equals 3" does not mean they are the same
This is the most critical part.
1 + 2 = 3 1 OR 2 = 3
Looking only at
, flags might seem to work with simple addition.
1 + 1 = 2 1 OR 1 = 1
Addition causes a carry, whereas OR is an operation that "sets the bit," so if it is already 1, it remains 1.
Therefore, there are cases where the results happen to be the same because the values are non-overlapping powers of two.therefore, addition and OR are not the same operation.
Let us change only one place
We also add Delete to the Read + Write state.
PowerShell:
$Delete = 4 $flags = $Read -bor $Write -bor $Delete
The expected value is 7, or in binary 0111.
Next, we check Write only.
($flags -band $Write) -ne 0
By assigning functionality to each bit, a single integer can represent multiple ON/OFF states.
Any and All are different
When evaluating multiple required flags, distinguish whether "any single one is sufficient" or "all are required".
For example, when the required mask is Read OR Write = 3 and the current flags are Read OR Delete = 5.
$required = 3 $flags = 5 $common = $flags -band $required $hasAny = $common -ne 0 $hasAll = $common -eq $required
In this case, Read is shared so it is hasAny=True, and since there is no Write, it is hasAll=False.
Why this frequently appears in Windows API constants
In the Win32 API and similar frameworks, it is common to design functions that combine flag values to pass multiple options in a single argument.
00000001 = Option A 00000010 = Option B 00000100 = Option C 00001000 = Option D
If each bit is distinct, a single integer can hold multiple states.
However, real APIs contain not only single flags but also composite constants combining multiple bits. Do not guess and add values together; instead, consult the official specification of the API.
A similar perspective exists in chmod numeric values.
The 4、2、1 used in Linux permissions
read = 4
write = 2
execute = 1
can be understood as a combination of these bits.
7 can be expressed as 4+2+1, but essentially it represents a state where all three permission bits are set.
Pay attention to types when using them in production.
When handling flags, verify whether it is:
32-bit or 64-bit
signed or unsigned
how unknown bits are handled
a composite mask or a single flag
.
The tutorial's 1/2/4 must not be directly reused for permission values in actual systems.
Daily-Code-Samples
Reusable versions comparing PowerShell, VBA, and Any/All implementations are provided.

