Domain groups
CNSAM NameMember of groupsdescriptionCreated onChanged onSID
Shared Support AccountsShared Support Accounts  05/28/22 11:11:3205/28/22 11:12:041103
DnsUpdateProxyDnsUpdateProxy DNS clients who are permitted to perform dynamic updates on behalf of some other clients (such as DHCP servers).05/28/22 11:05:1705/28/22 11:05:171102
DnsAdminsDnsAdmins DNS Administrators Group05/28/22 11:05:1705/28/22 11:05:171101
Enterprise Key AdminsEnterprise Key Admins Members of this group can perform administrative actions on key objects within the forest.05/28/22 11:03:4305/28/22 11:19:47527
Key AdminsKey Admins Members of this group can perform administrative actions on key objects within the domain.05/28/22 11:03:4305/28/22 11:19:47526
Protected UsersProtected Users Members of this group are afforded additional protections against authentication security threats. See http://go.microsoft.com/fwlink/?LinkId=298939 for more information.05/28/22 11:03:4305/28/22 11:03:43525
Cloneable Domain ControllersCloneable Domain Controllers Members of this group that are domain controllers may be cloned.05/28/22 11:03:4305/28/22 11:03:43522
Enterprise Read-only Domain ControllersEnterprise Read-only Domain Controllers Members of this group are Read-Only Domain Controllers in the enterprise05/28/22 11:03:4305/28/22 11:03:43498
Read-only Domain ControllersRead-only Domain ControllersDenied RODC Password Replication GroupMembers of this group are Read-Only Domain Controllers in the domain05/28/22 11:03:4305/28/22 11:19:47521
Denied RODC Password Replication GroupDenied RODC Password Replication Group Members in this group cannot have their passwords replicated to any read-only domain controllers in the domain05/28/22 11:03:4305/28/22 11:03:43572
Allowed RODC Password Replication GroupAllowed RODC Password Replication Group Members in this group can have their passwords replicated to all read-only domain controllers in the domain05/28/22 11:03:4305/28/22 11:03:43571
Terminal Server License ServersTerminal Server License Servers Members of this group can update user accounts in Active Directory with information about license issuance, for the purpose of tracking and reporting TS Per User CAL usage05/28/22 11:03:4305/28/22 11:03:43561
Windows Authorization Access GroupWindows Authorization Access Group Members of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects05/28/22 11:03:4305/28/22 11:03:43560
Incoming Forest Trust BuildersIncoming Forest Trust Builders Members of this group can create incoming, one-way trusts to this forest05/28/22 11:03:4305/28/22 11:03:43557
Pre-Windows 2000 Compatible AccessPre-Windows 2000 Compatible Access A backward compatibility group which allows read access on all users and groups in the domain05/28/22 11:03:4305/28/22 11:03:43554
Account OperatorsAccount Operators Members can administer domain user and group accounts05/28/22 11:03:4305/28/22 11:19:47548
Server OperatorsServer Operators Members can administer domain servers05/28/22 11:03:4305/28/22 11:19:47549
RAS and IAS ServersRAS and IAS Servers Servers in this group can access remote access properties of users05/28/22 11:03:4305/28/22 11:03:43553
Group Policy Creator OwnersGroup Policy Creator OwnersDenied RODC Password Replication GroupMembers in this group can modify group policy for the domain05/28/22 11:03:4305/28/22 11:03:43520
Domain GuestsDomain GuestsGuestsAll domain guests05/28/22 11:03:4305/28/22 11:03:43514
Domain UsersDomain UsersUsersAll domain users05/28/22 11:03:4305/28/22 11:03:43513
Domain AdminsDomain AdminsDenied RODC Password Replication Group, AdministratorsDesignated administrators of the domain05/28/22 11:03:4305/28/22 11:19:47512
Cert PublishersCert PublishersDenied RODC Password Replication GroupMembers of this group are permitted to publish certificates to the directory05/28/22 11:03:4305/28/22 11:03:43517
Enterprise AdminsEnterprise AdminsDenied RODC Password Replication Group, AdministratorsDesignated administrators of the enterprise05/28/22 11:03:4305/28/22 11:19:47519
Schema AdminsSchema AdminsDenied RODC Password Replication GroupDesignated administrators of the schema05/28/22 11:03:4305/28/22 11:19:47518
Domain ControllersDomain ControllersDenied RODC Password Replication GroupAll domain controllers in the domain05/28/22 11:03:4305/28/22 11:19:47516
Domain ComputersDomain Computers All workstations and servers joined to the domain05/28/22 11:03:4305/28/22 11:03:43515
Storage Replica AdministratorsStorage Replica Administrators Members of this group have complete and unrestricted access to all features of Storage Replica.05/28/22 11:01:5605/28/22 11:01:56582
Remote Management UsersRemote Management Users Members of this group can access WMI resources over management protocols (such as WS-Management via the Windows Remote Management service). This applies only to WMI namespaces that grant access to the user.05/28/22 11:01:5605/28/22 11:12:04580
Access Control Assistance OperatorsAccess Control Assistance Operators Members of this group can remotely query authorization attributes and permissions for resources on this computer.05/28/22 11:01:5605/28/22 11:01:56579
Hyper-V AdministratorsHyper-V Administrators Members of this group have complete and unrestricted access to all features of Hyper-V.05/28/22 11:01:5605/28/22 11:01:56578
RDS Management ServersRDS Management Servers Servers in this group can perform routine administrative actions on servers running Remote Desktop Services. This group needs to be populated on all servers in a Remote Desktop Services deployment. The servers running the RDS Central Management service must be included in this group.05/28/22 11:01:5605/28/22 11:01:56577
RDS Endpoint ServersRDS Endpoint Servers Servers in this group run virtual machines and host sessions where users RemoteApp programs and personal virtual desktops run. This group needs to be populated on servers running RD Connection Broker. RD Session Host servers and RD Virtualization Host servers used in the deployment need to be in this group.05/28/22 11:01:5605/28/22 11:01:56576
RDS Remote Access ServersRDS Remote Access Servers Servers in this group enable users of RemoteApp programs and personal virtual desktops access to these resources. In Internet-facing deployments, these servers are typically deployed in an edge network. This group needs to be populated on servers running RD Connection Broker. RD Gateway servers and RD Web Access servers used in the deployment need to be in this group.05/28/22 11:01:5605/28/22 11:01:56575
Certificate Service DCOM AccessCertificate Service DCOM Access Members of this group are allowed to connect to Certification Authorities in the enterprise05/28/22 11:01:5605/28/22 11:01:56574
Event Log ReadersEvent Log Readers Members of this group can read event logs from local machine05/28/22 11:01:5605/28/22 11:01:56573
Cryptographic OperatorsCryptographic Operators Members are authorized to perform cryptographic operations.05/28/22 11:01:5605/28/22 11:01:56569
IIS_IUSRSIIS_IUSRS Built-in group used by Internet Information Services.05/28/22 11:01:5605/28/22 11:01:56568
Distributed COM UsersDistributed COM Users Members are allowed to launch, activate and use Distributed COM objects on this machine.05/28/22 11:01:5605/28/22 11:01:56562
Performance Log UsersPerformance Log Users Members of this group may schedule logging of performance counters, enable trace providers, and collect event traces both locally and via remote access to this computer05/28/22 11:01:5605/28/22 11:01:56559
Performance Monitor UsersPerformance Monitor Users Members of this group can access performance counter data locally and remotely05/28/22 11:01:5605/28/22 11:01:56558
Network Configuration OperatorsNetwork Configuration Operators Members in this group can have some administrative privileges to manage configuration of networking features05/28/22 11:01:5605/28/22 11:01:56556
Remote Desktop UsersRemote Desktop Users Members in this group are granted the right to logon remotely05/28/22 11:01:5605/28/22 11:01:56555
ReplicatorReplicator Supports file replication in a domain05/28/22 11:01:5605/28/22 11:19:47552
Backup OperatorsBackup Operators Backup Operators can override security restrictions for the sole purpose of backing up or restoring files05/28/22 11:01:5605/28/22 11:19:47551
Print OperatorsPrint Operators Members can administer printers installed on domain controllers05/28/22 11:01:5605/28/22 11:19:47550
GuestsGuests Guests have the same access as members of the Users group by default, except for the Guest account which is further restricted05/28/22 11:01:5605/28/22 11:03:43546
UsersUsers Users are prevented from making accidental or intentional system-wide changes and can run most applications05/28/22 11:01:5605/28/22 11:03:43545
AdministratorsAdministrators Administrators have complete and unrestricted access to the computer/domain05/28/22 11:01:5605/28/22 11:19:47544