Re: How to comprehend "security principal"?

Tech-Archive recommends: Speed Up your PC by fixing your registry

From: Glenn L (the.only(delete)_at_gmail.com)
Date: 11/04/04


Date: Wed, 3 Nov 2004 20:32:15 -0800

Additionally, security principles are referenced by the OS using a SID that
is assigned to the principle.
The SID is a globally unique number that includes the domain SID and a
unique RID (relative identifier)

When a principle authenticates to the domain (only users and computers can
authenticate), it recieves a "token", which is a data structure that
contains, among other things, the SIDs of all the groups to which the
principle is a member.
The principle presents this token to any resource it wishes to access.

-- 
Glenn L
CCNA, MCSE (2000,2003) + Security
"Dave Shaw [MVP - Directory Services]" <dhshaw@NO-SPAM.msn.com> wrote in 
message news:OKJq%237awEHA.1984@TK2MSFTNGP14.phx.gbl...
>A "Security Principal" is an entity, represented by an object in the
> directory, that has the ability to access directory resources such as, 
> data
> on drives, printers, objects in the directory itself, etc.  Security
> Principals are either assigned rights or inherit them.
>
> In Active Directory, there are three recognized Security Principals: 
> Users,
> Computers, and Groups.  In other directories, you might find that
> Organizational Units are Security Principals as well (the subject of 
> intense
> debate at times).
>
> -ds
>
>
> "Leo Zhang" <zhjno1xp@163.com> wrote in message
> news:u4LiAyXwEHA.4004@tk2msftngp13.phx.gbl...
>> How to comprehend "security principal"?
>>
>>
>
> 


Relevant Pages

  • Re: Infrastructure Master FSMO role, Global Catalogs and Forest Trusts
    ... Name = SID ... that had the trust. ... Joe Richards Microsoft MVP Windows Server Directory Services ...
    (microsoft.public.windows.server.active_directory)
  • Re: What is the difference between a SID and a GUID?
    ... So GUIDs are basically unique identifiers for each object in AD, ... additionally these objects may or may not be actual security principals (and ... >> What is the difference between a SID and a GUID? ... > A GUID - is a generic term for a guaranteed unique identifier. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Please Clarify foir me...
    ... forms of UIDs (unique identifiers). ... SID is unique among installs. ... It is true to say that all security principals are internally ... I understand that user accounts, computer accounts, serivce accounts are ...
    (microsoft.public.win2000.security)
  • Re: SID in Domain
    ... to be Security Principals. ... If the SID were to change, then the ACL would be totally messed up. ... > When a computer joins to a domain, ...
    (microsoft.public.windows.server.active_directory)
  • Re: How to comprehend "security principal"?
    ... directory, that has the ability to access directory resources such as, data ... on drives, printers, objects in the directory itself, etc. Security ... Organizational Units are Security Principals as well (the subject of intense ...
    (microsoft.public.win2000.active_directory)