From f2bdc70846d12e378e4e23f7215eb8aa57f94a4a Mon Sep 17 00:00:00 2001 From: JasonJiachengZhao <48364192+JasonJiachengZhao@users.noreply.github.com> Date: Mon, 22 Apr 2019 15:15:55 -0700 Subject: [PATCH] Adding information about Device owner to the table Adding information about Device owner to the table --- .../active-directory-security-groups.md | 63 +++++++++++++++++++ 1 file changed, 63 insertions(+) diff --git a/windows/security/identity-protection/access-control/active-directory-security-groups.md b/windows/security/identity-protection/access-control/active-directory-security-groups.md index 0b2f989db7..4fa0568986 100644 --- a/windows/security/identity-protection/access-control/active-directory-security-groups.md +++ b/windows/security/identity-protection/access-control/active-directory-security-groups.md @@ -3692,6 +3692,69 @@ This security group was introduced in Windows ServerĀ 2012, and it has not chang +### Device Owners +This group is currently unused on Windows. + +Microsoft does not recommend changing the default configuration where this security group has zero members. Changing the default configuration could hinder future scenarios that rely on this group. + +The Device Owners group applies to versions of the Windows Server operating system listed in the [Active Directory Default Security Groups table](#bkmk-groupstable). + +
Attribute | +Value | +
---|---|
Well-Known SID/RID |
+S-1-5-32-583 |
+
Type |
+BuiltIn Local |
+
Default container |
+CN=BuiltIn, DC=<domain>, DC= |
+
Default members |
+None |
+
Default member of |
+None |
+
Protected by ADMINSDHOLDER? |
+No |
+
Safe to move out of default container? |
+Can be moved out but it is not recommended |
+
Safe to delegate management of this group to non-Service admins? |
+No |
+
Default User Rights |
+[Allow log on locally](/windows/device-security/security-policy-settings/allow-log-on-locally): SeInteractiveLogonRight +[Access this computer from the network](/windows/device-security/security-policy-settings/access-this-computer-from-the-network): SeNetworkLogonRight +[Bypass traverse checking](/windows/device-security/security-policy-settings/bypass-traverse-checking): SeChangeNotifyPrivilege +[Change the time zone](/windows/device-security/security-policy-settings/change-the-time-zone): SeTimeZonePrivilege + |
+