Members from any domain may be added. Also, you can use a universal group to assign permissions for access to resources in any domain. Universal security groups are not available in mixed mode. The full feature set of Windows and later Microsoft NT-based operating systems is available only in native mode. The universal scope can contain user accounts, universal groups, and global groups from any domain. The scope can be a member of domain local or universal groups in any domain.
Universal groups are required for mail-enabled groups distribution lists. This is document ahrl in the Knowledge Base. Last modified on Skip to: content search login.
Default groups are located in the Builtin container and in the Users container in Active Directory Users and Computers. The Builtin container includes groups that are defined with the Domain Local scope.
The Users includes contains groups that are defined with Global scope and groups that are defined with Domain Local scope. You can move groups that are located in these containers to other groups or organizational units OU within the domain, but you cannot move them to other domains.
Some of the administrative groups that are listed in this topic and all members of these groups are protected by a background process that periodically checks for and applies a specific security descriptor. This descriptor is a data structure that contains security information associated with a protected object.
This process ensures that any successful unauthorized attempt to modify the security descriptor on one of the administrative accounts or groups will be overwritten with the protected settings. The security descriptor is present on the AdminSDHolder object. This means that if you want to modify the permissions on one of the service administrator groups or on any of its member accounts, you must modify the security descriptor on the AdminSDHolder object so that it will be applied consistently.
Be careful when you make these modifications because you are also changing the default settings that will be applied to all of your protected administrative accounts. The following tables provide descriptions of the default groups that are located in the Builtin and Users containers in each operating system.
Members of this group can remotely query authorization attributes and permissions for resources on the computer. The Access Control Assistance Operators group applies to versions of the Windows Server operating system listed in the Active Directory default security groups by operating system version.
The Account Operators group grants limited account creation privileges to a user. Members of this group can create and modify most types of accounts, including those of users, local groups, and global groups, and members can log in locally to domain controllers.
Members of the Account Operators group cannot manage the Administrator user account, the user accounts of administrators, or the Administrators , Server Operators , Account Operators , Backup Operators , or Print Operators groups. Members of this group cannot modify user rights. The Account Operators group applies to versions of the Windows Server operating system listed in the Active Directory default security groups by operating system version.
By default, this built-in group has no members, and it can create and manage users and groups in the domain, including its own membership and that of the Server Operators group. This group is considered a service administrator group because it can modify Server Operators, which in turn can modify domain controller settings.
As a best practice, leave the membership of this group empty, and do not use it for any delegated administration. This group cannot be renamed, deleted, or moved. Allow log on locally : SeInteractiveLogonRight.
Members of the Administrators group have complete and unrestricted access to the computer, or if the computer is promoted to a domain controller, members have unrestricted access to the domain. The Administrators group applies to versions of the Windows Server operating system listed in the Active Directory default security groups by operating system version.
The Administrators group has built-in capabilities that give its members full control over the system. This built-in group controls access to all the domain controllers in its domain, and it can change the membership of all administrative groups. Membership can be modified by members of the following groups: the default service Administrators, Domain Admins in the domain, or Enterprise Admins.
This group has the special privilege to take ownership of any object in the directory or any resource on a domain controller. This account is considered a service administrator group because its members have full access to the domain controllers in the domain. Default user rights changes: Allow log on through Terminal Services existed in Windows Server , and it was replaced by Allow log on through Remote Desktop Services.
Remove computer from docking station was removed in Windows Server R2. Adjust memory quotas for a process : SeIncreaseQuotaPrivilege. Access this computer from the network : SeNetworkLogonRight.
Back up files and directories : SeBackupPrivilege. Bypass traverse checking : SeChangeNotifyPrivilege. Change the system time : SeSystemTimePrivilege. Change the time zone : SeTimeZonePrivilege. Create a pagefile : SeCreatePagefilePrivilege. Create global objects : SeCreateGlobalPrivilege. Enable computer and user accounts to be trusted for delegation : SeEnableDelegationPrivilege. Force shutdown from a remote system : SeRemoteShutdownPrivilege. Impersonate a client after authentication : SeImpersonatePrivilege.
Load and unload device drivers : SeLoadDriverPrivilege. Log on as a batch job : SeBatchLogonRight. Manage auditing and security log : SeSecurityPrivilege. Modify firmware environment values : SeSystemEnvironmentPrivilege. Perform volume maintenance tasks : SeManageVolumePrivilege. Profile system performance : SeSystemProfilePrivilege. Remove computer from docking station : SeUndockPrivilege. Restore files and directories : SeRestorePrivilege.
Shut down the system : SeShutdownPrivilege. Take ownership of files or other objects : SeTakeOwnershipPrivilege. The purpose of this security group is to manage a RODC password replication policy. This group has no members by default, and it results in the condition that new Read-only domain controllers do not cache user credentials.
Members of the Backup Operators group can back up and restore all files on a computer, regardless of the permissions that protect those files. Backup Operators also can log on to and shut down the computer.
By default, this built-in group has no members, and it can perform backup and restore operations on domain controllers. Its membership can be modified by the following groups: default service Administrators, Domain Admins in the domain, or Enterprise Admins. It cannot modify the membership of any administrative groups.
While members of this group cannot change server settings or modify the configuration of the directory, they do have the permissions needed to replace files including operating system files on domain controllers. Because of this, members of this group are considered service administrators.
The Backup Operators group applies to versions of the Windows Server operating system listed in the Active Directory default security groups by operating system version. Members of the Cert Publishers group are authorized to publish certificates for User objects in Active Directory. The Cert Publishers group applies to versions of the Windows Server operating system listed in the Active Directory default security groups by operating system version.
Members of the Cloneable Domain Controllers group that are domain controllers may be cloned. In Windows Server R2 and Windows Server , you can deploy domain controllers by copying an existing virtual domain controller. In a virtual environment, you no longer have to repeatedly deploy a server image that is prepared by using sysprep. This security group was introduced in Windows Server , and it has not changed in subsequent versions. Members of this group are authorized to perform cryptographic operations.
The Cryptographic Operators group applies to versions of the Windows Server operating system listed in the Active Directory default security groups by operating system version. This security group was introduced in Windows Vista Service Pack 1, and it has not changed in subsequent versions. This group contains a variety of high-privilege accounts and security groups. Microsoft Component Object Model COM is a platform-independent, distributed, object-oriented system for creating binary software components that can interact.
Distributed Component Object Model DCOM allows applications to be distributed across locations that make the most sense to you and to the application. This group appears as a SID until the domain controller is made the primary domain controller and it holds the operations master role also known as flexible single master operations or FSMO.
The Distributed COM Users group applies to versions of the Windows Server operating system listed in the Active Directory default security groups by operating system version. They are permitted to perform dynamic updates on behalf of other clients such as DHCP servers. Adding clients to this security group mitigates this scenario. However, to protect against unsecured records or to permit members of the DnsUpdateProxy group to register records in zones that allow only secured dynamic updates, you must create a dedicated user account and configure DHCP servers to perform DNS dynamic updates by using the credentials of this account user name, password, and domain.
Multiple DHCP servers can use the credentials of one dedicated user account. Members of the Domain Admins security group are authorized to administer the domain. By default, the Domain Admins group is a member of the Administrators group on all computers that have joined a domain, including the domain controllers.
The Domain Admins group is the default owner of any object that is created in Active Directory for the domain by any member of the group. If members of the group create other objects, such as files, the default owner is the Administrators group.
The Domain Admins group controls access to all domain controllers in a domain, and it can modify the membership of all administrative accounts in the domain. Membership can be modified by members of the service administrator groups in its domain Administrators and Domain Admins , and by members of the Enterprise Admins group. This is considered a service administrator account because its members have full access to the domain controllers in a domain.
The Domain Admins group applies to versions of the Windows Server operating system listed in the Active Directory default security groups by operating system version. This group can include all computers and servers that have joined the domain, excluding domain controllers. By default, any computer account that is created automatically becomes a member of this group. The Domain Computers group applies to versions of the Windows Server operating system listed in the Active Directory default security groups by operating system version.
The Domain Controllers group can include all domain controllers in the domain. New domain controllers are automatically added to this group. The Domain Controllers group applies to versions of the Windows Server operating system listed in the Active Directory default security groups by operating system version. When members of this group sign in as local guests on a domain-joined computer, a domain profile is created on the local computer.
The Domain Guests group applies to versions of the Windows Server operating system listed in the Active Directory default security groups by operating system version.
The Domain Users group includes all user accounts in a domain. When you create a user account in a domain, it is automatically added to this group. By default, any user account that is created in the domain automatically becomes a member of this group. This group can be used to represent all users in the domain. For example, if you want all domain users to have access to a printer, you can assign permissions for the printer to this group or add the Domain Users group to a local group on the print server that has permissions for the printer.
The Domain Users group applies to versions of the Windows Server operating system listed in the Active Directory default security groups by operating system version.
The Enterprise Admins group exists only in the root domain of an Active Directory forest of domains. Members of this group can locally sign in to and shut down domain controllers in the domain.
This group has no default members. Because members of this group can load and unload device drivers on all domain controllers in the domain, add users with caution. This security group has not changed since Windows Server However, in Windows Server R2, functionality was added to manage print administration. Load and unload device drivers : SeLoadDriverPrivilege Shut down the system : SeShutdownPrivilege Protected Users Members of the Protected Users group are afforded additional protection against the compromise of credentials during authentication processes.
This security group is designed as part of a strategy to effectively protect and manage credentials within the enterprise. Members of this group automatically have non-configurable protection applied to their accounts. Membership in the Protected Users group is meant to be restrictive and proactively secure by default. The only method to modify the protection for an account is to remove the account from the security group. This domain-related, global group triggers non-configurable protection on devices and host computers, starting with the Windows Server R2 and Windows 8.
It also triggers non-configurable protection on domain controllers in domains with a primary domain controller running Windows Server R2 or Windows Server This greatly reduces the memory footprint of credentials when users sign in to computers on the network from a non-compromised computer. Passwords are not cached on a device running Windows 8.
This means that the domain must be configured to support at least the AES cipher suite. This means that former connections to other systems may fail if the user is a member of the Protected Users group. The default Kerberos ticket-granting tickets TGTs lifetime setting of four hours is configurable by using Authentication Policies and Silos, which can be accessed through the Active Directory Administrative Center. This means that when four hours has passed, the user must authenticate again.
This group was introduced in Windows Server R2. For more information about how this group works, see Protected Users Security Group. By default, this group has no members. Servers that are members in the RDS Endpoint Servers group can run virtual machines and host sessions where user RemoteApp programs and personal virtual desktops run.
This group needs to be populated on servers running RD Connection Broker. Session Host servers and RD Virtualization Host servers used in the deployment need to be in this group. Servers that are members in the RDS Management Servers group can be used to perform routine administrative actions on servers running Remote Desktop Services. This group needs to be populated on all servers in a Remote Desktop Services deployment.
In Internet facing deployments, these servers are typically deployed in an edge network. For more information, see Host desktops and apps in Remote Desktop Services. This group is comprised of the Read-only domain controllers in the domain. A Read-only domain controller makes it possible for organizations to easily deploy a domain controller in scenarios where physical security cannot be guaranteed, such as branch office locations, or in scenarios where local storage of all domain passwords is considered a primary threat, such as in an extranet or in an application-facing role.
Because administration of a Read-only domain controller can be delegated to a domain user or security group, an Read-only domain controller is well suited for a site that should not have a user who is a member of the Domain Admins group.
A Read-only domain controller encompasses the following functionality:. It appears as a SID until the domain controller is made the primary domain controller and it holds the operations master role also known as flexible single master operations or FSMO. This applies only to WMI namespaces that grant access to the user. For more information, see What's New in MI? Computers that are members of the Replicator group support file replication in a domain.
FRS can copy and maintain shared files and folders on multiple servers simultaneously. When changes occur, content is synchronized immediately within sites and by a schedule between sites. For more information, see:. Members of the Schema Admins group can modify the Active Directory schema. This group exists only in the root domain of an Active Directory forest of domains.
The group is authorized to make schema changes in Active Directory. This group has full administrative access to the schema.
The membership of this group can be modified by any of the service administrator groups in the root domain. This is considered a service administrator account because its members can modify the schema, which governs the structure and content of the entire directory. Members in the Server Operators group can administer domain controllers. This group exists only on domain controllers. By default, the group has no members. Members of the Server Operators group can sign in to a server interactively, create and delete network shared resources, start and stop services, back up and restore files, format the hard disk drive of the computer, and shut down the computer.
By default, this built-in group has no members, and it has access to server configuration options on domain controllers. Its membership is controlled by the service administrator groups Administrators and Domain Admins in the domain, and the Enterprise Admins group in the forest root domain. Members in this group cannot change any administrative group memberships. This is considered a service administrator account because its members have physical access to domain controllers, they can perform maintenance tasks such as backup and restore , and they have the ability to change binaries that are installed on the domain controllers.
Note the default user rights in the following table. Members of the Terminal Server License Servers group can update user accounts in Active Directory with information about license issuance.
Members of the Users group are prevented from making accidental or intentional system-wide changes, and they can run most applications. After the initial installation of the operating system, the only member is the Authenticated Users group. When a computer joins a domain, the Domain Users group is added to the Users group on the computer. Users can perform tasks such as running applications, using local and network printers, shutting down the computer, and locking the computer. Users can install applications that only they are allowed to use if the installation program of the application supports per-user installation.
Cannot be moved Safe to delegate management of this group to non-Service admins? Some applications have features that read the token-groups-global-and-universal TGGAU attribute on user account objects or on computer account objects in Active Directory Domain Services.
Applications that read this attribute or that call an API referred to as a function that reads this attribute do not succeed if the calling security context does not have access to the attribute. This tab displays the security properties of a remote file share. To view this information, you must have the following permissions and memberships, as appropriate for the version of Windows Server that the file server is running.
If the file share is hosted on a server that is running a supported version of the operating system:. If the file share is hosted on a server that is running a version of Windows Server that is earlier than Windows Server Therefore, when the Access Denied Assistance functionality is enabled, all authenticated users who have Read permissions to the file share can view the file share permissions.
Skip to main content. This browser is no longer supported. Download Microsoft Edge More info. Contents Exit focus mode. Is this page helpful? Please rate your experience Yes No. Any additional feedback? Note In addition to these three scopes, the default groups in the Builtin container have a group scope of Builtin Local. Note By default, this built-in group has no members, and it can create and manage users and groups in the domain, including its own membership and that of the Server Operators group.
Note The Administrators group has built-in capabilities that give its members full control over the system. Note A Guest account is a default member of the Guests security group. Note Prior to Windows Server , access to features in Hyper-V was controlled in part by membership in the Administrators group.
Note This group appears as a SID until the domain controller is made the primary domain controller and it holds the operations master role also known as flexible single master operations or FSMO. Warning If you are a member of the Performance Log Users group, you must configure Data Collector Sets that you create to run under your credentials.
Warning This group appears as a SID until the domain controller is made the primary domain controller and it holds the operations master role also known as flexible single master operations or FSMO.
Submit and view feedback for This product This page. View all page feedback. In this article. Accounts from any domain in the same forest Global groups from any domain in the same forest Other Universal groups from any domain in the same forest. Can be converted to Domain Local scope if the group is not a member of any other Universal groups Can be converted to Global scope if the group does not contain any other Universal groups.
Other Universal groups in the same forest Domain Local groups in the same forest or trusting forests Local groups on computers in the same forest or trusting forests. Universal groups from any domain in the same forest Other Global groups from the same domain Domain Local groups from any domain in the same forest, or from any trusting domain. Accounts from any domain or any trusted domain Global groups from any domain or any trusted domain Universal groups from any domain in the same forest Other Domain Local groups from the same domain Accounts, Global groups, and Universal groups from other forests and from external domains.
Other Domain Local groups from the same domain Local groups on computers in the same domain, excluding built-in groups that have well-known SIDs. Cloneable Domain Controllers. Cryptographic Operators.
0コメント