FM 13-01 Chapter 13 · Windows and Active Directory
Windows SID
Security identifiers between string, hex and Base64 objectSid, with well-known SIDs and RIDs named.
Local only Runs in your browser. Nothing you enter leaves this page.
Usable as a step in ChainWell-known domain RIDs
| RID | Name | Note |
|---|---|---|
| 498 | Enterprise Read-only Domain Controllers | forest root domain |
| 500 | Administrator | privileged |
| 501 | Guest | |
| 502 | krbtgt (KDC service account) | privileged |
| 503 | DefaultAccount | local machine |
| 504 | WDAGUtilityAccount | local machine |
| 512 | Domain Admins | privileged |
| 513 | Domain Users | |
| 514 | Domain Guests | |
| 515 | Domain Computers | |
| 516 | Domain Controllers | privileged |
| 517 | Cert Publishers | |
| 518 | Schema Admins | privileged, forest root domain |
| 519 | Enterprise Admins | privileged, forest root domain |
| 520 | Group Policy Creator Owners | privileged |
| 521 | Read-only Domain Controllers | |
| 522 | Cloneable Domain Controllers | |
| 525 | Protected Users | |
| 526 | Key Admins | privileged |
| 527 | Enterprise Key Admins | privileged, forest root domain |
| 553 | RAS and IAS Servers | |
| 571 | Allowed RODC Password Replication Group | |
| 572 | Denied RODC Password Replication Group |
A SID is a revision, a 48-bit authority and up to 15 32-bit sub-authorities. In binary the
authority is big-endian and the sub-authorities little-endian, which is why the hex looks
scrambled. Domain accounts are S-1-5-21-domain-RID. AD also accepts the string form
directly: (objectSid=S-1-5-21-…). Names follow Microsoft's "Well-known SIDs" list.