You can use Ps Get Sid to view the name of the account for a specified SID, and here you can see that the local SID that has a RID of 1000 is for the Abby account, the name of the administrator account Windows prompted me to name during setup: In addition to these dynamically created SIDs, Windows defines a number of accounts that always have predefined SIDs, not just RIDs.One example is the Everyone group, which has the SID S-1-1-0 on every Windows system: Another example, is the Local System account (System), which is the account in which several system processes like Session Manager (Smss.exe), the Service Control Manager (Services.exe) and Winlogon (Winlogon.exe) run: When an account logs on to a Windows system, the Local Security Authority Subsystem (LSASS -Lsass.exe) creates a logon session and a for the session.Instead of generating new random SIDs for these accounts, Windows ensures their uniqueness by simply appending a per-account unique number, called a (RID), to the machine SID.The RIDs for these initial accounts are predefined, so the Administrator user always has a RID of 500: After installation, Windows assigns new local user and group accounts with RIDs starting at 1000.Every process running in my interactive session, for example, has a copy of the token that they inherited originally from the process, the process Winlogon creates as the first of any interactive logon.You can view the contents of a process’s token by double-clicking on the process in Process Explorer and switching to the Security page of the process properties dialog: When one of my processes opens an operating system object, like a file or registry key, the security subsystem executes a permission check that evaluates entries in the object’s access control list (ACL) that reference a SID included in the process’s token.Windows uses SIDs to represent not just machines, but all Security principals include machines, domain computer accounts, users and security groups.Names are simply user-friendly representations for SIDs, allowing you to rename an account and not have to update access control lists (ACLs) that reference the account to reflect the change.

When you access a file on the share, the file server driver on that system uses the token from the logon session for the permission check, leveraging a mechanism called .A SID is a variable-length numeric value that consists of a structure revision number, a 48-bit identifier authority value, and a variable number of 32-bit subauthority or relative identifier (RID) values.The authority value identifies the agent that issued the SID, and this agent is typically a Windows local system or a domain.A similar check happens for remote logon sessions, which are the kind created by a "net use" of a remote computer's share.