FM Field Manual smhansen.dev

FM 13-01 Chapter 13 · Windows and Active Directory

Windows SID

Security identifiers between string, hex and Base64 objectSid, with well-known SIDs and RIDs named.

Local only Runs in your browser. Nothing you enter leaves this page.

Usable as a step in Chain
Well-known domain RIDs
RIDNameNote
498Enterprise Read-only Domain Controllersforest root domain
500Administratorprivileged
501Guest
502krbtgt (KDC service account)privileged
503DefaultAccountlocal machine
504WDAGUtilityAccountlocal machine
512Domain Adminsprivileged
513Domain Users
514Domain Guests
515Domain Computers
516Domain Controllersprivileged
517Cert Publishers
518Schema Adminsprivileged, forest root domain
519Enterprise Adminsprivileged, forest root domain
520Group Policy Creator Ownersprivileged
521Read-only Domain Controllers
522Cloneable Domain Controllers
525Protected Users
526Key Adminsprivileged
527Enterprise Key Adminsprivileged, forest root domain
553RAS and IAS Servers
571Allowed RODC Password Replication Group
572Denied RODC Password Replication Group

A SID is a revision, a 48-bit authority and up to 15 32-bit sub-authorities. In binary the authority is big-endian and the sub-authorities little-endian, which is why the hex looks scrambled. Domain accounts are S-1-5-21-domain-RID. AD also accepts the string form directly: (objectSid=S-1-5-21-…). Names follow Microsoft's "Well-known SIDs" list.

  • No entry in this manual matches “”.

↑ ↓ move · Enter open · Esc close