Re: Please Clarify foir me...



Hi Robert,

I think you may be confusing SIDs with GUIDs and other
forms of UIDs (unique identifiers). SIDs have a specific
form, with a part that represents the domain or machine,
so, other than the well-known (like for Administrator) a
SID is unique among installs (of machines or domains).

It is true to say that all security principals are internally
each represented by a unique SID. These are normally
stated as being accounts and groups, but note that these
these include the so-called built-in, well-known principals
(ex. Interactive, Network, etc.).

I think it is also true to state the reverse, that any SID
represents a security principal. (i.e. having a unique object
id, a unique rid, etc. is not the same as having a sid).

Roger

"Robert Bollinger" <Robert@xxxxxxxxxxxxxxxx> wrote in message
news:EA48BCFF-FF24-4CFB-B848-A283E4D9E540@xxxxxxxxxxxxxxxx
Hello All -

IF a windows securty principal is this:

any object that has an SID attached to it,. then does that make (really)
any object in active directory, the file system, services, dns records
etc. Security Principals?

I understand that user accounts, computer accounts, serivce accounts are
security principals but am i correct that "Any Object" is considered a
security principal if it has
an SID assigned to it?


Thank You,

Robert


.



Relevant Pages

  • Re: Infrastructure Master FSMO role, Global Catalogs and Forest Trusts
    ... Name = SID ... that had the trust. ... Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: What is the difference between a SID and a GUID?
    ... So GUIDs are basically unique identifiers for each object in AD, ... additionally these objects may or may not be actual security principals (and ... >> What is the difference between a SID and a GUID? ... > A GUID - is a generic term for a guaranteed unique identifier. ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to comprehend "security principal"?
    ... security principles are referenced by the OS using a SID that ... The SID is a globally unique number that includes the domain SID and a ... >A "Security Principal" is an entity, represented by an object in the> directory, that has the ability to access directory resources such as, ... you might find that> Organizational Units are Security Principals as well (the subject of> intense ...
    (microsoft.public.win2000.active_directory)
  • Re: Rename "Users" OU
    ... Actually the user's container has a Well known GUID. ... identifier - containers are not security principals, so no SID. ... The issue is that an application MUST hold its accounts in the users OU, ...
    (microsoft.public.win2000.active_directory)
  • Re: SID in Domain
    ... to be Security Principals. ... If the SID were to change, then the ACL would be totally messed up. ... > When a computer joins to a domain, ...
    (microsoft.public.windows.server.active_directory)