You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

Windows权限中Admin1获取User1的SID等信息时的执行身份问询

Admin1's Identity When Querying User1's SID & Group Info

Nice question—let's walk through exactly how this works in Windows' security model:

  • Admin1 executes the query using their own security principal identity
    When Admin1 tries to pull User1's SID, group memberships, or other account details, they're acting as themselves—their own user account (with its attached access token) is what the Windows security subsystem validates.

  • Underlying permission checks rely on Admin1's built-in privileges
    Windows grants default permissions for account information queries to administrative groups:

    • For local accounts: Local Administrators (which Admin1 is part of) have read access to the SAM (Security Account Manager) database, where local user SIDs and group data are stored.
    • For domain accounts: Domain Admins (or delegated admin accounts) have read permissions on Active Directory objects, allowing them to fetch user SIDs, memberOf attributes, and more.
    • Tools like net user User1, Get-ADUser User1 -Properties SID,MemberOf, or even WMI calls all use Admin1's token to pass these permission checks.
  • A quick note on lower-privilege users
    Even regular users can sometimes read basic SID info for other accounts, but querying full group memberships typically requires administrative rights. Since Admin1 is an admin, their token includes the necessary privileges (like SeSecurityPrivilege locally) to bypass any restrictions here.

When you compare User1's SID/group list to a resource's ACL later, that's a separate check—but the initial data collection is entirely tied to Admin1's own account permissions.

内容的提问来源于stack exchange,提问作者CAshtones

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.21 04:20:40