Winzero Server Migration, Domain Migration and Windows Security Software

 

Seamless Windows Active Directory Domain Migration software...

 

Follow us on Twitter

 

Twitter Updates

 

Follow us on twitter. Get the latest information on Winzero as it happens: news, new products, new product ideas, product updates, press releases and new product features.

     

     

     

     

     

    Contact Information:

     

     

    If you require an immediate response, complete the Request a Quote form and contact us directly.

     

     

    Winzero Sales:

     

    Toll Free: (US/Canada)  888-380-7477

     

    Telephone: +1 (613) 730-1001

     

    Fax: +1 (613) 248-4660

     

     

    Winzero Technical Pre-Sales

     

    Telephone: +1 (310) 928-1501

     

    Skype: WinzeroTech

     

     

    Windows Well Known SIDs

     

     

    A SID (Security Identifier) is a unique name (alphanumeric character string) that is used to identify an object, such as a user or a group of users in a network of NT/2000/XP/2003/Vista systems.

    Windows grants or denies access and privileges to resources based on ACLs, which use SIDs to uniquely identify users and their group memberships. When a user requests access to a resource, the user’s SID is checked by the ACL to determine if that user is allowed to perform that action or if that user is part of a group that is allowed to perform that action.

     



    SIDs are NOT Portable

    All SIDs are unique within a given system and are issued by what is known as an "Authority" such as a domain or local server. SIDs are in the form of a simple binary data structure, we see things in a simple string format so that we can more easily recognize them.

    The format of a SID breaks down as follows:

    S-1-5-12-7723811915-3361004348-033306820-1006.


    S - The string is a SID.
    1 - The revision level.
    5 - The identifier authority value.
    12-7723811915-3361004348-033306820  - Domain or local computer identifier


    1006 – The RID (Generated for each object from 1000 and up)

    Any group or user that is not created by default will have a RID of 1000 or greater. A RID is a Registered ID. This is the last portion of the SID. Once a RID has been issued it will never be used again even if the user and user account are deleted.

     



    Well Known RIDs


    However there are always exceptions in Microsoft Windows. Certain RIDs (below 1000) are predefined:

     

    500 - Administrator S-1-5-21----500
    501 - Guest S-1-5-21----501
    502 – KRBTGT S-1-5-21----502

    512 - Domain Admins S-1-5-21----512
    513 - Domain Users S-1-5-21----513
    514 - Domain Guest S-1-5-21----514
    515 - Domain Computers S-1-5-21----515
    516 - Domain Controllers S-1-5-21----516
    517 - Cert Publishers S-1-5-21----517
    518 - Schema Admins S-1-5-21----518
    519 - Enterprise Admins S-1-5-21----519
    520 - Group Policy Creator Owners S-1-5-21----520
    533 - RAS and IAS Servers S-1-5-21----533


    During a server or domain migration new accounts and groups are created on the target. Therefore; even if the account names are the same, new SIDs are created and any rights that the original account has or had, the new account does not.

     

    When Accounts (users and groups are deleted) their SIDs are never removed from File, folder or share ACLs. See RemoveUnknown to report, resolve and remove unknown SIDs.
     



    SIDs That Are Portable

    Well-known SIDs are a group of SIDs that identify generic users or generic groups. Their values remain constant across all operating systems and for this reason are termed well-known SIDs. These SIDs include BuiltIn accounts and groups (BuiltIn\Administrators) as well as label accounts such as the Everone group

    Well Known SIDs

    • SID: S-1-0
    Name: Null Authority
    Description: An identifier authority.

    • SID: S-1-0-0
    Name: Nobody
    Description: No security principal.

    • SID: S-1-1
    Name: World Authority
    Description: An identifier authority.

    • SID: S-1-1-0
    Name: Everyone
    Description: A group that includes all users, even anonymous users and guests. Membership is controlled by the operating system. Note By default, the Everyone group no longer includes anonymous users on a computer that is running Windows XP Service Pack 2 (SP2).

    • SID: S-1-2
    Name: Local Authority
    Description: An identifier authority.

    • SID: S-1-3
    Name: Creator Authority
    Description: An identifier authority.

    • SID: S-1-3-0
    Name: Creator Owner
    Description: A placeholder in an inheritable access control entry (ACE). When the ACE is inherited, the system replaces this SID with the SID for the object's creator.

    • SID: S-1-3-1
    Name: Creator Group
    Description: A placeholder in an inheritable ACE. When the ACE is inherited, the system replaces this SID with the SID for the primary group of the object's creator. The primary group is used only by the POSIX subsystem.

    • SID: S-1-3-2
    Name: Creator Owner Server
    Description: This SID is not used in Windows 2000.

    • SID: S-1-3-3
    Name: Creator Group Server
    Description: This SID is not used in Windows 2000.

    • SID: S-1-4
    Name: Non-unique Authority
    Description: An identifier authority.

    • SID: S-1-5
    Name: NT Authority
    Description: An identifier authority.

    • SID: S-1-5-1
    Name: Dialup
    Description: A group that includes all users who have logged on through a dial-up connection. Membership is controlled by the operating system.

    • SID: S-1-5-2
    Name: Network
    Description: A group that includes all users that have logged on through a network connection. Membership is controlled by the operating system.

    • SID: S-1-5-3
    Name: Batch
    Description: A group that includes all users that have logged on through a batch queue facility. Membership is controlled by the operating system.

    • SID: S-1-5-4
    Name: Interactive
    Description: A group that includes all users that have logged on interactively. Membership is controlled by the operating system.

    • SID: S-1-5-5-X-Y
    Name: Logon Session
    Description: A logon session. The X and Y values for these SIDs are different for each session.

    • SID: S-1-5-6
    Name: Service
    Description: A group that includes all security principals that have logged on as a service. Membership is controlled by the operating system.

    • SID: S-1-5-7
    Name: Anonymous
    Description: A group that includes all users that have logged on anonymously. Membership is controlled by the operating system.

    • SID: S-1-5-8
    Name: Proxy
    Description: This SID is not used in Windows 2000.

    • SID: S-1-5-9
    Name: Enterprise Domain Controllers
    Description: A group that includes all domain controllers in a forest that uses an Active Directory directory service. Membership is controlled by the operating system.

    • SID: S-1-5-10
    Name: Principal Self
    Description: A placeholder in an inheritable ACE on an account object or group object in Active Directory. When the ACE is inherited, the system replaces this SID with the SID for the security principal who holds the account.

    • SID: S-1-5-11
    Name: Authenticated Users
    Description: A group that includes all users whose identities were authenticated when they logged on. Membership is controlled by the operating system.

    • SID: S-1-5-12
    Name: Restricted Code
    Description: This SID is reserved for future use.

    • SID: S-1-5-13
    Name: Terminal Server Users
    Description: A group that includes all users that have logged on to a Terminal Services server. Membership is controlled by the operating system.

    • SID: S-1-5-18
    Name: Local System
    Description: A service account that is used by the operating system.

    • SID: S-1-5-19
    Name: NT Authority
    Description: Local Service

    • SID: S-1-5-20
    Name: NT Authority
    Description: Network Service
     


     

    • SID: S-1-5-32-544
    Name: Administrators
    Description: A built-in group. After the initial installation of the operating system, the only member of the group is the Administrator account. When a computer joins a domain, the Domain Admins group is added to the Administrators group. When a server becomes a domain controller, the Enterprise Admins group also is added to the Administrators group.

    • SID: S-1-5-32-545
    Name: Users
    Description: A built-in group. After the initial installation of the operating system, the only member is the Authenticated Users group. When a computer joins a domain, the Domain Users group is added to the Users group on the computer.

    • SID: S-1-5-32-546
    Name: Guests
    Description: A built-in group. By default, the only member is the Guest account. The Guests group allows occasional or one-time users to log on with limited privileges to a computer's built-in Guest account.

    • SID: S-1-5-32-547
    Name: Power Users
    Description: A built-in group. By default, the group has no members. Power users can create local users and groups; modify and delete accounts that they have created; and remove users from the Power Users, Users, and Guests groups. Power users also can install programs; create, manage, and delete local printers; and create and delete file shares.

    • SID: S-1-5-32-548
    Name: Account Operators
    Description: A built-in group that exists only on domain controllers. By default, the group has no members. By default, Account Operators have permission to create, modify, and delete accounts for users, groups, and computers in all containers and organizational units of Active Directory except the Builtin container and the Domain Controllers OU. Account Operators do not have permission to modify the Administrators and Domain Admins groups, nor do they have permission to modify the accounts for members of those groups.

    • SID: S-1-5-32-549
    Name: Server Operators
    Description: A built-in group that exists only on domain controllers. By default, the group has no members. Server Operators can log on to a server interactively; create and delete network shares; start and stop services; back up and restore files; format the hard disk of the computer; and shut down the computer.

    • SID: S-1-5-32-550
    Name: Print Operators
    Description: A built-in group that exists only on domain controllers. By default, the only member is the Domain Users group. Print Operators can manage printers and document queues
    .
    • SID: S-1-5-32-551
    Name: Backup Operators
    Description: A built-in group. By default, the group has no members. Backup Operators can back up and restore all files on a computer, regardless of the permissions that protect those files. Backup Operators also can log on to the computer and shut it down.

    • SID: S-1-5-32-552
    Name: Replicators
    Description: A built-in group that is used by the File Replication service on domain controllers. By default, the group has no members. Do not add users to this group.
    The following groups will show as SIDs until a Windows Server 2003 domain controller is made the primary domain controller (PDC) operations master role holder. (The "operations master" is also known as flexible single master operations or FSMO.)

     

    • SID: S-1-5-32-554
    Name: BUILTIN\Pre-Windows 2000 Compatible Access
    Description: An alias added by Windows 2000. A backward compatibility group which allows read access on all users and groups in the domain.

    • SID: S-1-5-32-555
    Name: BUILTIN\Remote Desktop Users
    Description: An alias. Members in this group are granted the right to logon remotely.

    • SID: S-1-5-32-556
    Name: BUILTIN\Network Configuration Operators
    Description: An alias. Members in this group can have some administrative privileges to manage configuration of networking features.

    • SID: S-1-5-32-557
    Name: BUILTIN\Incoming Forest Trust Builders
    Description: An alias. Members of this group can create incoming, one-way trusts to this forest.

    • SID: S-1-5-32-558
    Name: BUILTIN\Performance Monitor Users
    Description: An alias. Members of this group have remote access to monitor this computer.

    • SID: S-1-5-32-559
    Name: BUILTIN\Performance Log Users
    Description: An alias. Members of this group have remote access to schedule logging of performance counters on this computer.

    • SID: S-1-5-32-560
    Name: BUILTIN\Windows Authorization Access Group
    Description: An alias. Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects.

    • SID: S-1-5-32-561
    Name: BUILTIN\Terminal Server License Servers
    Description: An alias. A group for Terminal Server License Servers.
     

    • SID: S-1-5-32-562
    Name: BUILTIN\Distributed COM User

     

    • SID: S-1-5-32-568
    Name: BUILTIN\IIS_IUSRS

     

    • SID: S-1-5-32-569
    Name: BUILTIN\Cryptograhic Operators

     

    • SID: S-1-5-32-573
    Name: BUILTIN\Event Log Readers

     


     

    • SID: S-1-5-64-10
    Name: NTLM Authentication

     

    • SID: S-1-5-64-14
    Name: SChannel Authentication

     

    • SID: S-1-5-64-21
    Name: Digest Authentication

     

    • SID: S-1-5-64-1000
    Name: Other Organization


    • SID: S-1-6
    Name: Site Server Authority An identifier authority.

    • SID: S-1-7
    Name: Internet Site Authority An identifier authority.

    • SID: S-1-8
    Name: Exchange Authority An identifier authority.

    • SID: S-1-9
    Name: Resource Manager Authority An identifier
     

       

     

    Copyright Winzero Technologies. © 2001 - 2009 All rights reserved