GUIDs are assigned to every object that is created by Active Directory, not only User and Group objects. Security authorities never issue the same SID twice, and they never reuse SIDs for deleted accounts.

Services running as NetworkService access local resources as ordinary users and access network resources by using the computer's identity. A local group that is responsible for copying security databases from the primary domain controller to the backup domain controllers. The following table describes changes in SID implementation in the Windows operating systems that are designated in the list. If a user moves from one domain to another, the user gets a new SID. This token provides the security context for whatever actions the user performs on that computer. A group that includes all users who sign in to a server with Remote Desktop Services enabled. A global group, which by default, has only one member: the domain's built-in Guest account. All Capability SIDs that the operating system is aware of are stored in the Windows Registry in the path `HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\CapabilityClasses\AllCachedCapabilities'. Account Operators do not have permission to modify the Administrators and Domain Admins groups, nor do they have permission to modify the accounts for members of those groups. An identity that is used by services that have no need for extensive local access but do need authenticated network access.

Each time a User object moves to another domain, a new SID is generated and stored in the ObjectSID property, and another value is added to the list of old SIDs in SIDHistory. A group that includes users who are logged on to the physical console. No two computer SIDs are ever the same. A group that represents the current owner of the object. Power users can create local users and groups; modify and delete accounts that they have created; and remove users from the Power Users, Users, and Guests groups. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SecurityManager\CapabilityClasses\AllCachedCapabilities\capabilityClass_Restricted A user account for the system administrator. This SID is used in inheritable ACEs. A SID that is used when the Digest authentication package authenticated the client. Before the new value is written to the property, the previous value is copied to another property of a User object, SIDHistory. The account exists only on domain controllers.

