Thursday, February 16, 2006

Why Understanding SIDs is Important

An understanding of Windows Security Identifiers (SIDs) is important to successful server, server data and domain migrations.

The SID is a unique name (alphanumeric character string) that is used to identify an object, such as a user or a group of users in a network of NT/2000/XP/2003 systems.

Windows grants or denies access and privileges to resources based on ACLs, which use SIDs to uniquely identify users and their group memberships. When a user requests access to a resource, the user’s SID is checked by the ACL to determine if that user is allowed to perform that action or if that user is part of a group that is allowed to perform that action.


SIDs are NOT Portable

This information is useful for troubleshooting issues involving security reporting, server migrations and domain migrations.

All SIDs are unique within a given system and are issued by what is known as an "Authority" such as a domain or local server. While Windows 2000/2003 is most comfortable using SIDs in the form of a simple binary data structure, we humans like to see things in a simple string format so that we can more easily recognize them.

As a result, you and I never see SIDs in their native format but instead see things like S-1-5-12-7723811915-3361004348-033306820-1006.

The format of this SID breaks down as follows:

S - The string is a SID.
1 - The revision level.
5 - The identifier authority value.
12–7723811915-3361004348-033306820 Domain or local computer identifier
1006 – The RID (Generated for each object from 1000 and up)

Any group or user that is not created by default will have a RID of 1000 or greater. A RID is a Registered ID. This is the last portion of the SID. Once a RID has been issued it will never be used again even if the user and user account are deleted.
However there are always exceptions in Microsoft Windows. Certain RIDs (below 1000) are predefined:

500 - Administrator S-1-5-21----500
501 - Guest S-1-5-21----501
502 – KRBTGT S-1-5-21----502

512 - Domain Admins S-1-5-21----512
513 - Domain Users S-1-5-21----513
514 - Domain Guest S-1-5-21----514
515 - Domain Computers S-1-5-21----515
516 - Domain Controllers S-1-5-21----516
517 - Cert Publishers S-1-5-21----517
518 - Schema Admins S-1-5-21----518
519 - Enterprise Admins S-1-5-21----519
520 - Group Policy Creator Owners S-1-5-21----520
533 - RAS and IAS Servers S-1-5-21----533


During a server or domain migration new accounts and groups are created on the target. Therefore; even if the account names are the same, new SIDs are created and any rights that the original account has or had, the new account does not.

There are two methods of dealing with SID disassociation:

SidHistory - Append the old SID to the new account (Windows 2000 and up). This method is available in domain migration only. There are known issues using this method.

ReACL Process – by creating a mapping between old and new SIDs, The new SIDs are appended or replaced for each ACL for files, folders, shares, local groups membership, printers, mapped drives, profiles and rights.

SIDs That Are Portable - Well Known SIDs

Well-known SIDs are a group of SIDs that identify generic users or generic groups. Their values remain constant across all operating systems and for this reason are termed well-known SIDs

You can find the well-known SIDs in Active Directory in a container called WellKnown Security Principals. To see this container, launch Adsiedit.msc or Ldp from the Windows Server 2003 Support Tools and use it to view the top-level containers inside the Configuration naming context.

A universal well-known SID is a SID that is common to all machines. That is, the value SID is the same on my machine as it is on yours.

These SIDs include BuiltIn accounts and groups (BuiltIn\Administrators) as well as label accounts such as the Everone group

Well Known SIDs

• SID: S-1-0
Name: Null Authority
Description: An identifier authority.

• SID: S-1-0-0
Name: Nobody
Description: No security principal.

• SID: S-1-1
Name: World Authority
Description: An identifier authority.

• SID: S-1-1-0
Name: Everyone
Description: A group that includes all users, even anonymous users and guests. Membership is controlled by the operating system. Note By default, the Everyone group no longer includes anonymous users on a computer that is running Windows XP Service Pack 2 (SP2).

• SID: S-1-2
Name: Local Authority
Description: An identifier authority.

• SID: S-1-3
Name: Creator Authority
Description: An identifier authority.

• SID: S-1-3-0
Name: Creator Owner
Description: A placeholder in an inheritable access control entry (ACE). When the ACE is inherited, the system replaces this SID with the SID for the object's creator.

• SID: S-1-3-1
Name: Creator Group
Description: A placeholder in an inheritable ACE. When the ACE is inherited, the system replaces this SID with the SID for the primary group of the object's creator. The primary group is used only by the POSIX subsystem.

• SID: S-1-3-2
Name: Creator Owner Server
Description: This SID is not used in Windows 2000.

• SID: S-1-3-3
Name: Creator Group Server
Description: This SID is not used in Windows 2000.

• SID: S-1-4
Name: Non-unique Authority
Description: An identifier authority.

• SID: S-1-5
Name: NT Authority
Description: An identifier authority.

• SID: S-1-5-1
Name: Dialup
Description: A group that includes all users who have logged on through a dial-up connection. Membership is controlled by the operating system.

• SID: S-1-5-2
Name: Network
Description: A group that includes all users that have logged on through a network connection. Membership is controlled by the operating system.

• SID: S-1-5-3
Name: Batch
Description: A group that includes all users that have logged on through a batch queue facility. Membership is controlled by the operating system.

• SID: S-1-5-4
Name: Interactive
Description: A group that includes all users that have logged on interactively. Membership is controlled by the operating system.

• SID: S-1-5-5-X-Y
Name: Logon Session
Description: A logon session. The X and Y values for these SIDs are different for each session.

• SID: S-1-5-6
Name: Service
Description: A group that includes all security principals that have logged on as a service. Membership is controlled by the operating system.

• SID: S-1-5-7
Name: Anonymous
Description: A group that includes all users that have logged on anonymously. Membership is controlled by the operating system.

• SID: S-1-5-8
Name: Proxy
Description: This SID is not used in Windows 2000.

• SID: S-1-5-9
Name: Enterprise Domain Controllers
Description: A group that includes all domain controllers in a forest that uses an Active Directory directory service. Membership is controlled by the operating system.

• SID: S-1-5-10
Name: Principal Self
Description: A placeholder in an inheritable ACE on an account object or group object in Active Directory. When the ACE is inherited, the system replaces this SID with the SID for the security principal who holds the account.

• SID: S-1-5-11
Name: Authenticated Users
Description: A group that includes all users whose identities were authenticated when they logged on. Membership is controlled by the operating system.

• SID: S-1-5-12
Name: Restricted Code
Description: This SID is reserved for future use.

• SID: S-1-5-13
Name: Terminal Server Users
Description: A group that includes all users that have logged on to a Terminal Services server. Membership is controlled by the operating system.

• SID: S-1-5-18
Name: Local System
Description: A service account that is used by the operating system.

• SID: S-1-5-19
Name: NT Authority
Description: Local Service

• SID: S-1-5-20
Name: NT Authority
Description: Network Service

• SID: S-1-5-32-544
Name: Administrators
Description: A built-in group. After the initial installation of the operating system, the only member of the group is the Administrator account. When a computer joins a domain, the Domain Admins group is added to the Administrators group. When a server becomes a domain controller, the Enterprise Admins group also is added to the Administrators group.

• SID: S-1-5-32-545
Name: Users
Description: A built-in group. After the initial installation of the operating system, the only member is the Authenticated Users group. When a computer joins a domain, the Domain Users group is added to the Users group on the computer.

• SID: S-1-5-32-546
Name: Guests
Description: A built-in group. By default, the only member is the Guest account. The Guests group allows occasional or one-time users to log on with limited privileges to a computer's built-in Guest account.

• SID: S-1-5-32-547
Name: Power Users
Description: A built-in group. By default, the group has no members. Power users can create local users and groups; modify and delete accounts that they have created; and remove users from the Power Users, Users, and Guests groups. Power users also can install programs; create, manage, and delete local printers; and create and delete file shares.

• SID: S-1-5-32-548
Name: Account Operators
Description: A built-in group that exists only on domain controllers. By default, the group has no members. By default, Account Operators have permission to create, modify, and delete accounts for users, groups, and computers in all containers and organizational units of Active Directory except the Builtin container and the Domain Controllers OU. Account Operators do not have permission to modify the Administrators and Domain Admins groups, nor do they have permission to modify the accounts for members of those groups.

• SID: S-1-5-32-549
Name: Server Operators
Description: A built-in group that exists only on domain controllers. By default, the group has no members. Server Operators can log on to a server interactively; create and delete network shares; start and stop services; back up and restore files; format the hard disk of the computer; and shut down the computer.

• SID: S-1-5-32-550
Name: Print Operators
Description: A built-in group that exists only on domain controllers. By default, the only member is the Domain Users group. Print Operators can manage printers and document queues
.
• SID: S-1-5-32-551
Name: Backup Operators
Description: A built-in group. By default, the group has no members. Backup Operators can back up and restore all files on a computer, regardless of the permissions that protect those files. Backup Operators also can log on to the computer and shut it down.

• SID: S-1-5-32-552
Name: Replicators
Description: A built-in group that is used by the File Replication service on domain controllers. By default, the group has no members. Do not add users to this group.
The following groups will show as SIDs until a Windows Server 2003 domain controller is made the primary domain controller (PDC) operations master role holder. (The "operations master" is also known as flexible single master operations or FSMO.)

• SID: S-1-5-32-554
Name: BUILTIN\Pre-Windows 2000 Compatible Access
Description: An alias added by Windows 2000. A backward compatibility group which allows read access on all users and groups in the domain.

• SID: S-1-5-32-555
Name: BUILTIN\Remote Desktop Users
Description: An alias. Members in this group are granted the right to logon remotely.

• SID: S-1-5-32-556
Name: BUILTIN\Network Configuration Operators
Description: An alias. Members in this group can have some administrative privileges to manage configuration of networking features.

• SID: S-1-5-32-557
Name: BUILTIN\Incoming Forest Trust Builders
Description: An alias. Members of this group can create incoming, one-way trusts to this forest.

• SID: S-1-5-32-558
Name: BUILTIN\Performance Monitor Users
Description: An alias. Members of this group have remote access to monitor this computer.

• SID: S-1-5-32-559
Name: BUILTIN\Performance Log Users
Description: An alias. Members of this group have remote access to schedule logging of performance counters on this computer.

• SID: S-1-5-32-560
Name: BUILTIN\Windows Authorization Access Group
Description: An alias. Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects.

• SID: S-1-5-32-561
Name: BUILTIN\Terminal Server License Servers
Description: An alias. A group for Terminal Server License Servers.

• SID: S-1-6
Name: Site Server Authority An identifier authority.

• SID: S-1-7
Name: Internet Site Authority An identifier authority.

• SID: S-1-8
Name: Exchange Authority An identifier authority.

• SID: S-1-9
Name: Resource Manager Authority An identifier

2 comments:

G said...

Good article, too bad the first post is by a sitespamer :(

Arun.P.C said...

Fantastic post! Very informative! Could you throw some light on how Active Directory servers treat SIDs? Do syspreped images have different SIDs all the time?

Thanks,
Arun.PC
http://arunpc.com