Default Accounts and Groups in Active Directory


By default, there exist 3 domain user accounts and 51 domain security groups in Active Directory, and the default access that is provisioned in every Active Directory domain grants 23 of these principals various Active Directory Security Permissions.


Note - In each forest, the forest root domain contains 51 security groups, whereas all other domains contain 49 security groups, since the Enterprise Admins and Schema Admins groups only exist in the forest root domain.


Default Active Directory Accounts

There are 3 default domain user accounts in Active Directory -

#
.
Name
.
SID
.
Status
.
Container
.
Protected*
.
Description
.
Notes
.
1
Administrator
S-1-5-21-{-}-500
Enabled
Users
Built-in account for administering the computer/domain
3
Guest
S-1-5-21-{-}-501
Enabled
Users
Built-in account for guest access to the computer/domain
2
krbtgt
S-1-5-21-{-}-502
Disabled
Users
Key Distribution Center Service Account




Default Active Directory Security Groups

There are 51 default security groups in Active Directory -

#
.
Name
.
SID
.
Group Type
.
Container
.
Protected*
.
Description
.
Notes
.
1
Access Control Assistance Operators
S-1-5-32-579
Builtin
Builtin
Members of this group can remotely query authorization attributes and permissions for resources on this computer
2
Account Operators
S-1-5-32-548
Builtin
Builtin
Members can administer domain user and group accounts
3
Administrators
S-1-5-32-544
Builtin
Builtin
Administrators have complete and unrestricted access to the computer/domain
4
Backup Operators
S-1-5-32-551
Builtin
Builtin
Backup Operators can override security restrictions for the sole purpose of backing up or restoring files
5
Certificate Service DCOM Access
S-1-5-32-574
Builtin
Builtin
Members of this group are allowed to connect to Certification Authorities in the enterprise
6
Cryptographic Operators
S-1-5-32-569
Builtin
Builtin
Members are authorized to perform cryptographic operations
7
Distributed COM Users
S-1-5-32-562
Builtin
Builtin
Members are allowed to launch, activate and use Distributed COM objects on this machine
8
Event Log Readers
S-1-5-32-573
Builtin
Builtin
Members of this group can read event logs from local machine
9
Guests
S-1-5-32-546
Builtin
Builtin
Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted
10
Hyper-V Administrators
S-1-5-32-578
Builtin
Builtin
Members of this group have complete and unrestricted access to all features of Hyper-V
11
IIS_IUSRS
S-1-5-32-568
Builtin
Builtin
Built-in group used by Internet Information Services
12
Incoming Forest Trust Builders
S-1-5-32-557
Builtin
Builtin
Members of this group can create incoming, one-way trusts to this forest
13
Network Configuration Operators
S-1-5-32-556
Builtin
Builtin
Members in this group can have some administrative privileges to manage configuration of networking features
14
OpenSSH Users
S-1-5-32-585
Builtin
Builtin
Members of this group may connect to this computer using SSH
15
Performance Log Users
S-1-5-32-559
Builtin
Builtin
Members of this group may schedule logging of performance counters, enable trace providers, and collect event traces both locally and via remote access to this computer
16
Performance Monitor Users
S-1-5-32-558
Builtin
Builtin
Members of this group can access performance counter data locally and remotely
17
Pre-Windows 2000 Compatible Access
S-1-5-32-554
Builtin
Builtin
A backward compatibility group which allows read access on all users and groups in the domain
18
Print Operators
S-1-5-32-550
Builtin
Builtin
Members can administer printers installed on domain controllers
19
RDS Endpoint Servers
S-1-5-32-576
Builtin
Builtin
Servers in this group run virtual machines and host sessions where users RemoteApp programs and personal virtual desktops run
20
RDS Management Servers
S-1-5-32-577
Builtin
Builtin
Servers in this group can perform routine administrative actions on servers running Remote Desktop Services
21
RDS Remote Access Servers
S-1-5-32-575
Builtin
Builtin
Servers in this group enable users of RemoteApp programs and personal virtual desktops access to these resources
22
Remote Desktop Users
S-1-5-32-555
Builtin
Builtin
Members in this group are granted the right to logon remotely
23
Remote Management Users
S-1-5-32-580
Builtin
Builtin
Members of this group can access WMI resources over management protocols
24
Replicator
S-1-5-32-552
Builtin
Builtin
Supports file replication in a domain
25
Server Operators
S-1-5-32-549
Builtin
Builtin
Members can administer domain servers
26
Storage Replica Administrators
S-1-5-32-582
Builtin
Builtin
Members of this group have complete and unrestricted access to all features of Storage Replica
27
Terminal Server License Servers
S-1-5-32-561
Builtin
Builtin
Members of this group can update user accounts in Active Directory with information about license issuance
28
Users
S-1-5-32-545
Builtin
Builtin
Users are prevented from making accidental or intentional system-wide changes and can run most applications
29
Windows Authorization Access Group
S-1-5-32-560
Builtin
Builtin
Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects
30
Allowed RODC Password Replication Group
S-1-5-21-{-}-571
Domain Local
Users
Members in this group can have their passwords replicated to all read-only domain controllers in the domain
31
Cert Publishers
S-1-5-21-{-}-517
Domain Local
Users
Members of this group are permitted to publish certificates to the directory
32
Cloneable Domain Controllers
S-1-5-21-{-}-522
Global
Users
Members of this group that are domain controllers may be cloned
33
Denied RODC Password Replication Group
S-1-5-21-{-}-572
Domain Local
Users
Members in this group cannot have their passwords replicated to any read-only domain controllers in the domain
34
DnsAdmins
S-1-5-21-{-}-1101
Domain Local
Users
DNS Administrators Group
35
DnsUpdateProxy
S-1-5-21-{-}-1102
Global
Users
DNS clients who are permitted to perform dynamic updates on behalf of some other clients (such as DHCP servers)
36
Domain Admins
S-1-5-21-{-}-512
Global
Users
Designated administrators of the domain
37
Domain Computers
S-1-5-21-{-}-515
Global
Users
All workstations and servers joined to the domain
38
Domain Controllers
S-1-5-21-{-}-516
Global
Users
All domain controllers in the domain
39
Domain Guests
S-1-5-21-{-}-514
Global
Users
All domain guests
40
Domain Users
S-1-5-21-{-}-513
Global
Users
All domain users
41
Enterprise Admins
S-1-5-21-{-}-519
Universal
Users
Designated administrators of the enterprise
42
Enterprise Key Admins
S-1-5-21-{-}-527
Universal
Users
Members of this group can perform administrative actions on key objects within the forest
43
Enterprise Read-only Domain Controllers
S-1-5-21-{-}-498
Universal
Users
Members of this group are Read-Only Domain Controllers in the enterprise
44
External Trust Accounts
S-1-5-21-{-}-529
Global
Users
All external trust accounts in the domain
45
Forest Trust Accounts
S-1-5-21-{-}-528
Global
Users
All forest trust accounts in the forest
46
Group Policy Creator Owners
S-1-5-21-{-}-520
Global
Users
Members in this group can modify group policy for the domain
47
Key Admins
S-1-5-21-{-}-526
Global
Users
Members of this group can perform administrative actions on key objects within the domain
48
Protected Users
S-1-5-21-{-}-525
Global
Users
Members of this group are afforded additional protections against authentication security threats
49
RAS and IAS Servers
S-1-5-21-{-}-553
Domain Local
Users
Servers in this group can access remote access properties of users
50
Read-only Domain Controllers
S-1-5-21-{-}-521
Global
Users
Members of this group are Read-Only Domain Controllers in the domain
51
Schema Admins
S-1-5-21-{-}-518
Universal
Users
Designated administrators of the Schema


* Protected refers to the protection provided by AdminSDHolder.