diff --git a/windows/security/identity-protection/access-control/special-identities.md b/windows/security/identity-protection/access-control/special-identities.md index 16e282f16f..b29d15b901 100644 --- a/windows/security/identity-protection/access-control/special-identities.md +++ b/windows/security/identity-protection/access-control/special-identities.md @@ -34,364 +34,153 @@ Although the special identity groups can be assigned rights and permissions to r For information about security groups and group scope, see [Active Directory Security Groups](active-directory-security-groups.md). -The special identity groups are described in the following tables. +The special identity groups are described in the following tables. -- [Anonymous Logon](#bkmk-anonymouslogon) +- [Anonymous Logon](#Anonymous-Logon) -- [Authenticated User](#bkmk-authenticateduser) +- [Authenticated User](#Authenticated-Users) -- [Batch](#bkmk-batch) +- [Batch](#batch) -- [Creator Group](#bkmk-creatorgroup) +- [Creator Group](#Creator-Group) -- [Creator Owner](#bkmk-creatorowner) +- [Creator Owner](#Creator-Owner) -- [Dialup](#bkmk-dialup) +- [Dialup](#Dialup) -- [Digest Authentication](#bkmk-digestauth) +- [Digest Authentication](#Digest-Authentication) -- [Enterprise Domain Controllers](#bkmk-entdcs) +- [Enterprise Domain Controllers](#Enterprise-Domain-Controllers) -- [Everyone](#bkmk-everyone) +- [Everyone](#everyone) -- [Interactive](#bkmk-interactive) +- [Interactive](#interactive) -- [Local Service](#bkmk-localservice) +- [Local Service](#local-service) -- [LocalSystem](#bkmk-localsystem) +- [LocalSystem](#LocalSystem) -- [Network](#bkmk-network) +- [Network](#network) -- [Network Service](#bkmk-networkservice) +- [Network Service](#Network-Service) -- [NTLM Authentication](#bkmk-ntlmauth) +- [NTLM Authentication](#NTLM-Authentication) -- [Other Organization](#bkmk-otherorganization) +- [Other Organization](#Other-Organization) -- [Principal Self](#bkmk-principalself) +- [Principal Self](#Principal-Self) -- [Remote Interactive Logon](#bkmk-remoteinteractivelogon) +- [Remote Interactive Logon](#Remote-Interactive-Logon) -- [Restricted](#bkmk-restrictedcode) +- [Restricted](#Restricted) -- [SChannel Authentication](#bkmk-schannelauth) +- [SChannel Authentication](#SChannel-Authentication) -- [Service](#bkmk-service) +- [Service](#Service) -- [Terminal Server User](#bkmk-terminalserveruser) +- [Terminal Server User](#Terminal-Server-User) -- [This Organization](#bkmk-thisorg) +- [This Organization](#This-Organization) -- [Window Manager\\Window Manager Group](#bkmk-windowmanager) +- [Window Manager\\Window Manager Group](#Window-Manager\\Window-Manager-Group) -## Anonymous Logon +## Anonymous Logon Any user who accesses the system through an anonymous logon has the Anonymous Logon identity. This identity allows anonymous access to resources, such as a web page that is published on corporate servers. The Anonymous Logon group is not a member of the Everyone group by default. -
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-7 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-11 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=System,cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-[Access this computer from the network](/windows/device-security/security-policy-settings/access-this-computer-from-the-network): SeNetworkLogonRight -[Add workstations to domain](/windows/device-security/security-policy-settings/add-workstations-to-domain): SeMachineAccountPrivilege -[Bypass traverse checking](/windows/device-security/security-policy-settings/bypass-traverse-checking): SeChangeNotifyPrivilege |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-3 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-3-1 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-3-0 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-1 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-64-21 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-9 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights Assignment |
-[Access this computer from the network](/windows/device-security/security-policy-settings/access-this-computer-from-the-network): SeNetworkLogonRight -[Allow log on locally](/windows/device-security/security-policy-settings/allow-log-on-locally): SeInteractiveLogonRight |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-1-0 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-[Access this computer from the network](/windows/device-security/security-policy-settings/access-this-computer-from-the-network): SeNetworkLogonRight -[Act as part of the operating system](/windows/device-security/security-policy-settings/act-as-part-of-the-operating-system): SeTcbPrivilege -[Bypass traverse checking](/windows/device-security/security-policy-settings/bypass-traverse-checking): SeChangeNotifyPrivilege |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-4 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-19 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default user rights |
-[Adjust memory quotas for a process](/windows/device-security/security-policy-settings/adjust-memory-quotas-for-a-process): SeIncreaseQuotaPrivilege -[Bypass traverse checking](/windows/device-security/security-policy-settings/bypass-traverse-checking): SeChangeNotifyPrivilege -[Change the system time](/windows/device-security/security-policy-settings/change-the-system-time): SeSystemtimePrivilege -[Change the time zone](/windows/device-security/security-policy-settings/change-the-time-zone): SeTimeZonePrivilege -[Create global objects](/windows/device-security/security-policy-settings/create-global-objects): SeCreateGlobalPrivilege -[Generate security audits](/windows/device-security/security-policy-settings/generate-security-audits): SeAuditPrivilege -[Impersonate a client after authentication](/windows/device-security/security-policy-settings/impersonate-a-client-after-authentication): SeImpersonatePrivilege -[Replace a process level token](/windows/device-security/security-policy-settings/replace-a-process-level-token): SeAssignPrimaryTokenPrivilege |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-18 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-2 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-20 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-[Adjust memory quotas for a process](/windows/device-security/security-policy-settings/adjust-memory-quotas-for-a-process): SeIncreaseQuotaPrivilege -[Bypass traverse checking](/windows/device-security/security-policy-settings/bypass-traverse-checking): SeChangeNotifyPrivilege -[Create global objects](/windows/device-security/security-policy-settings/create-global-objects): SeCreateGlobalPrivilege -[Generate security audits](/windows/device-security/security-policy-settings/generate-security-audits): SeAuditPrivilege -[Impersonate a client after authentication](/windows/device-security/security-policy-settings/impersonate-a-client-after-authentication): SeImpersonatePrivilege -[Restore files and directories](/windows/device-security/security-policy-settings/restore-files-and-directories): SeRestorePrivilege -[Replace a process level token](/windows/device-security/security-policy-settings/replace-a-process-level-token): SeAssignPrimaryTokenPrivilege |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-64-10 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-1000 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-10 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-14 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-12 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-64-14 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-6 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-[Create global objects](/windows/device-security/security-policy-settings/create-global-objects): SeCreateGlobalPrivilege -[Impersonate a client after authentication](/windows/device-security/security-policy-settings/impersonate-a-client-after-authentication): SeImpersonatePrivilege |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-13 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-S-1-5-15 |
-
Object Class |
-Foreign Security Principal |
-
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-None |
-
Attribute | -Value | -
---|---|
Well-Known SID/RID |
-- |
Object Class |
-- |
Default Location in Active Directory |
-cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain> |
-
Default User Rights |
-[Bypass traverse checking](/windows/device-security/security-policy-settings/bypass-traverse-checking): SeChangeNotifyPrivilege -[Increase a process working set](/windows/device-security/security-policy-settings/increase-a-process-working-set): SeIncreaseWorkingSetPrivilege |
-