Default Accounts and Groups in Active Directory
By default, there exist 3 domain user accounts and 51 domain security groups in Active Directory, and the default access that is provisioned in every Active Directory domain grants 23 of these principals various Active Directory Security Permissions.
Note - In each forest, the forest root domain contains 51 security groups, whereas all other domains contain 49 security groups, since the Enterprise Admins and Schema Admins groups only exist in the forest root domain.
Default Active Directory Accounts
There are 3 default domain user accounts in Active Directory -
| # . |
Name . |
SID . |
Status . |
Container . |
Protected* . |
Description . |
Notes . |
1 |
Administrator |
S-1-5-21-{-}-500 |
Enabled |
Users |
✓ |
Built-in account for administering the computer/domain |
|
3 |
Guest |
S-1-5-21-{-}-501 |
Enabled |
Users |
Built-in account for guest access to the computer/domain |
||
2 |
krbtgt |
S-1-5-21-{-}-502 |
Disabled |
Users |
✓ |
Key Distribution Center Service Account |
Default Active Directory Security Groups
There are 51 default security groups in Active Directory -
| # . |
Name . |
SID . |
Group Type . |
Container . |
Protected* . |
Description . |
Notes . |
1 |
Access Control Assistance Operators |
S-1-5-32-579 |
Builtin |
Builtin |
Members of this group can remotely query authorization attributes and permissions for resources on this computer |
||
2 |
Account Operators |
S-1-5-32-548 |
Builtin |
Builtin |
✓ |
Members can administer domain user and group accounts |
|
3 |
Administrators |
S-1-5-32-544 |
Builtin |
Builtin |
✓ |
Administrators have complete and unrestricted access to the computer/domain |
|
4 |
Backup Operators |
S-1-5-32-551 |
Builtin |
Builtin |
✓ |
Backup Operators can override security restrictions for the sole purpose of backing up or restoring files |
|
5 |
Certificate Service DCOM Access |
S-1-5-32-574 |
Builtin |
Builtin |
Members of this group are allowed to connect to Certification Authorities in the enterprise |
||
6 |
Cryptographic Operators |
S-1-5-32-569 |
Builtin |
Builtin |
Members are authorized to perform cryptographic operations |
||
7 |
Distributed COM Users |
S-1-5-32-562 |
Builtin |
Builtin |
Members are allowed to launch, activate and use Distributed COM objects on this machine |
||
8 |
Event Log Readers |
S-1-5-32-573 |
Builtin |
Builtin |
Members of this group can read event logs from local machine |
||
9 |
Guests |
S-1-5-32-546 |
Builtin |
Builtin |
Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted |
||
10 |
Hyper-V Administrators |
S-1-5-32-578 |
Builtin |
Builtin |
Members of this group have complete and unrestricted access to all features of Hyper-V |
||
11 |
IIS_IUSRS |
S-1-5-32-568 |
Builtin |
Builtin |
Built-in group used by Internet Information Services |
||
12 |
Incoming Forest Trust Builders |
S-1-5-32-557 |
Builtin |
Builtin |
Members of this group can create incoming, one-way trusts to this forest |
||
13 |
Network Configuration Operators |
S-1-5-32-556 |
Builtin |
Builtin |
Members in this group can have some administrative privileges to manage configuration of networking features |
||
14 |
OpenSSH Users |
S-1-5-32-585 |
Builtin |
Builtin |
Members of this group may connect to this computer using SSH |
||
15 |
Performance Log Users |
S-1-5-32-559 |
Builtin |
Builtin |
Members of this group may schedule logging of performance counters, enable trace providers, and collect event traces both locally and via remote access to this computer |
||
16 |
Performance Monitor Users |
S-1-5-32-558 |
Builtin |
Builtin |
Members of this group can access performance counter data locally and remotely |
||
17 |
Pre-Windows 2000 Compatible Access |
S-1-5-32-554 |
Builtin |
Builtin |
A backward compatibility group which allows read access on all users and groups in the domain |
||
18 |
Print Operators |
S-1-5-32-550 |
Builtin |
Builtin |
✓ |
Members can administer printers installed on domain controllers |
|
19 |
RDS Endpoint Servers |
S-1-5-32-576 |
Builtin |
Builtin |
Servers in this group run virtual machines and host sessions where users RemoteApp programs and personal virtual desktops run |
||
20 |
RDS Management Servers |
S-1-5-32-577 |
Builtin |
Builtin |
Servers in this group can perform routine administrative actions on servers running Remote Desktop Services |
||
21 |
RDS Remote Access Servers |
S-1-5-32-575 |
Builtin |
Builtin |
Servers in this group enable users of RemoteApp programs and personal virtual desktops access to these resources |
||
22 |
Remote Desktop Users |
S-1-5-32-555 |
Builtin |
Builtin |
Members in this group are granted the right to logon remotely |
||
23 |
Remote Management Users |
S-1-5-32-580 |
Builtin |
Builtin |
Members of this group can access WMI resources over management protocols |
||
24 |
Replicator |
S-1-5-32-552 |
Builtin |
Builtin |
✓ |
Supports file replication in a domain |
|
25 |
Server Operators |
S-1-5-32-549 |
Builtin |
Builtin |
✓ |
Members can administer domain servers |
|
26 |
Storage Replica Administrators |
S-1-5-32-582 |
Builtin |
Builtin |
Members of this group have complete and unrestricted access to all features of Storage Replica |
||
27 |
Terminal Server License Servers |
S-1-5-32-561 |
Builtin |
Builtin |
Members of this group can update user accounts in Active Directory with information about license issuance |
||
28 |
Users |
S-1-5-32-545 |
Builtin |
Builtin |
Users are prevented from making accidental or intentional system-wide changes and can run most applications |
||
29 |
Windows Authorization Access Group |
S-1-5-32-560 |
Builtin |
Builtin |
Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects |
||
30 |
Allowed RODC Password Replication Group |
S-1-5-21-{-}-571 |
Domain Local |
Users |
Members in this group can have their passwords replicated to all read-only domain controllers in the domain |
||
31 |
Cert Publishers |
S-1-5-21-{-}-517 |
Domain Local |
Users |
Members of this group are permitted to publish certificates to the directory |
||
32 |
Cloneable Domain Controllers |
S-1-5-21-{-}-522 |
Global |
Users |
Members of this group that are domain controllers may be cloned |
||
33 |
Denied RODC Password Replication Group |
S-1-5-21-{-}-572 |
Domain Local |
Users |
Members in this group cannot have their passwords replicated to any read-only domain controllers in the domain |
||
34 |
DnsAdmins |
S-1-5-21-{-}-1101 |
Domain Local |
Users |
DNS Administrators Group |
||
35 |
DnsUpdateProxy |
S-1-5-21-{-}-1102 |
Global |
Users |
DNS clients who are permitted to perform dynamic updates on behalf of some other clients (such as DHCP servers) |
||
36 |
Domain Admins |
S-1-5-21-{-}-512 |
Global |
Users |
✓ |
Designated administrators of the domain |
|
37 |
Domain Computers |
S-1-5-21-{-}-515 |
Global |
Users |
All workstations and servers joined to the domain |
||
38 |
Domain Controllers |
S-1-5-21-{-}-516 |
Global |
Users |
✓ |
All domain controllers in the domain |
|
39 |
Domain Guests |
S-1-5-21-{-}-514 |
Global |
Users |
All domain guests |
||
40 |
Domain Users |
S-1-5-21-{-}-513 |
Global |
Users |
All domain users |
||
41 |
Enterprise Admins |
S-1-5-21-{-}-519 |
Universal |
Users |
✓ |
Designated administrators of the enterprise |
|
42 |
Enterprise Key Admins |
S-1-5-21-{-}-527 |
Universal |
Users |
✓ |
Members of this group can perform administrative actions on key objects within the forest |
|
43 |
Enterprise Read-only Domain Controllers |
S-1-5-21-{-}-498 |
Universal |
Users |
Members of this group are Read-Only Domain Controllers in the enterprise |
||
44 |
External Trust Accounts |
S-1-5-21-{-}-529 |
Global |
Users |
All external trust accounts in the domain |
||
45 |
Forest Trust Accounts |
S-1-5-21-{-}-528 |
Global |
Users |
All forest trust accounts in the forest |
||
46 |
Group Policy Creator Owners |
S-1-5-21-{-}-520 |
Global |
Users |
Members in this group can modify group policy for the domain |
||
47 |
Key Admins |
S-1-5-21-{-}-526 |
Global |
Users |
✓ |
Members of this group can perform administrative actions on key objects within the domain |
|
48 |
Protected Users |
S-1-5-21-{-}-525 |
Global |
Users |
Members of this group are afforded additional protections against authentication security threats |
||
49 |
RAS and IAS Servers |
S-1-5-21-{-}-553 |
Domain Local |
Users |
Servers in this group can access remote access properties of users |
||
50 |
Read-only Domain Controllers |
S-1-5-21-{-}-521 |
Global |
Users |
✓ |
Members of this group are Read-Only Domain Controllers in the domain |
|
51 |
Schema Admins |
S-1-5-21-{-}-518 |
Universal |
Users |
✓ |
Designated administrators of the Schema |
* Protected refers to the protection provided by AdminSDHolder.