Home › Active Directory users and groups › Step 8

Special identities in Windows and AD DS

Step 8 of 9 in Active Directory users and groups · video 3:02

Can't see the video? Watch it on YouTube.

What you will learn

About this lesson

Special identities look like groups, but Windows decides who belongs to them from the way a user connects, not from a membership list. They do not appear in Active Directory Users and Computers, and their membership cannot be viewed, edited or nested into other groups, yet they can be used when granting rights and permissions. The lesson describes the important ones: Anonymous Logon, which has not been part of Everyone since Windows Server 2003; Authenticated Users, which leaves out the Guest account; Everyone, which covers authenticated users plus Guest; Interactive, for people signed in on the computer itself, including through Remote Desktop; Network, for access across the network; and Creator Owner, which stands for whoever created an object. Two practical cases show why this matters: a folder readable only when signed in locally, built with the Interactive identity, and home folders where Creator Owner gives each user full control of the subfolder they created.

Good to know: Creator Owner is a placeholder: the person who creates an object receives only the permissions that were granted to Creator Owner on the parent folder, which is full control in the home-folder example.

Check yourself

Answer in your head first, then open each question to see the answer.

1. What is the difference between Everyone and Authenticated Users?

Everyone includes authenticated users and also the Guest account. Authenticated Users leaves out Guest, even if the Guest account has a password, so it is the safer choice when you mean real signed-in accounts.

2. Can you add a user to the Interactive identity, or nest Network inside another group?

No. The operating system controls the membership of special identities, so they cannot be edited or added to other groups. You can only use them in rights and permission entries.

3. Users should be able to open a folder when signed in at the server itself but not through a mapped drive. Which special identity helps?

Interactive. Grant the permission to Interactive rather than to the users' accounts: people signed in locally (or through Remote Desktop) match it, while the same people connecting over the network match Network instead and get no access.

4. Why is Creator Owner used on the root folder that holds users' home directories?

Permissions granted to Creator Owner on the root are applied to whoever creates a subfolder. Each user who creates their home directory therefore gets full control of it without the administrator setting permissions folder by folder.

Go deeper

This lesson comes from the course below - with the full set of lessons, demonstrations and practice.

Main course

Active Directory and Windows Server 90+ Hour with Labs

4.4★ · 5,924 students on Udemy

See the course on Udemy

Also in this shorter course

Active Directory: Managing Groups, Computers and OUs

4.5★ · 1,445 students on Udemy

See the course on Udemy
← Default administrative groups in Active DirectoryNext: Managing group membership with Restricted Groups →

Video lesson by Vitalii Shumylo. The summary and the questions on this page were written from the lesson with AI help and checked against its transcript.