Sign Up

Sign Up to our social questions and Answers Engine to ask questions, answer people’s questions, and connect with other people.

Have an account? Sign In

Have an account? Sign In Now

Sign In

Login to our social questions & Answers Engine to ask questions answer people’s questions & connect with other people.

Sign Up Here

Forgot Password?

Don't have account, Sign Up Here

Forgot Password

Lost your password? Please enter your email address. You will receive a link and will create a new password via email.

Have an account? Sign In Now

You must login to ask a question.

Forgot Password?

Need An Account, Sign Up Here

Please briefly explain why you feel this question should be reported.

Please briefly explain why you feel this answer should be reported.

Please briefly explain why you feel this user should be reported.

Sign InSign Up

The Archive Base

The Archive Base Logo The Archive Base Logo

The Archive Base Navigation

  • SEARCH
  • Home
  • About Us
  • Blog
  • Contact Us
Search
Ask A Question

Mobile menu

Close
Ask a Question
  • Home
  • Add group
  • Groups page
  • Feed
  • User Profile
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Buy Points
  • Users
  • Help
  • Buy Theme
  • SEARCH
Home/ Questions/Q 6157047
In Process

The Archive Base Latest Questions

Editorial Team
  • 0
Editorial Team
Asked: May 23, 20262026-05-23T20:43:04+00:00 2026-05-23T20:43:04+00:00

According to this article on Access Tokens , a token contains several pieces of

  • 0

According to this article on Access Tokens, a token contains several pieces of information, including:

  • The security identifier (SID) for the user’s account
  • An owner SID

I would expect the owner SID and user account SID to be the same. In what example scenario would they be different?

Further documentation explains that the Login SID of an access token is sometimes used in a DACL. I’d like to know a security “pattern” where a DACL would be assigned an access or deny of a particular Login SID. At face value, it seems like a far-fetched case. About the only use I could imagine, would be to deny one logged in user from having visibility about what other users are also logged in. Is there more?

  • 1 1 Answer
  • 0 Views
  • 0 Followers
  • 0
Share
  • Facebook
  • Report

Leave an answer
Cancel reply

You must login to add an answer.

Forgot Password?

Need An Account, Sign Up Here

1 Answer

  • Voted
  • Oldest
  • Recent
  • Random
  1. Editorial Team
    Editorial Team
    2026-05-23T20:43:05+00:00Added an answer on May 23, 2026 at 8:43 pm

    The owner SID represents the entity that should be designated as the owner of any objects created under the focal token. One of the key scenarios under which one expect the owner SID to differ from the login SID is when the System objects: Default owner for objects created by members of the Administrators group local security policy option is configured so that the Administrators group becomes the owner of objects created by a logged in administrator.

    The only really “typical” cases for using a logon SID in a DACL would be when controlling access to a process or a transient resource running under the current logon session. For details, see http://blogs.msdn.com/b/david_leblanc/archive/2007/07/29/logon-id-sids.aspx.

    • 0
    • Reply
    • Share
      Share
      • Share on Facebook
      • Share on Twitter
      • Share on LinkedIn
      • Share on WhatsApp
      • Report

Sidebar

Related Questions

According this article , generic JPA DAO(Data Access Object) is a pretty nice pattern.
According to this Wikipedia article on Google App Engine : Developers have read-only access
I want to Register some user defined character fonts programmatically. According to this article
According to this article , it says: Use a delegate in the following circumstances:
According to this article , it's possible to get multiline XML comments -- instead
According to this article about writing shell extensions in .Net, inheriting the shell interfaces
I am doing a tutorial according to this article . This is basic Hello
I've got a PHP-fpm setup on nginx setup according to this article: http://interfacelab.com/nginx-php-fpm-apc-awesome/ PHP
According to this MSDN article about medium trust , under medium-trust: FileIOPermission is restricted.
According to this article , Enumerations don't count as single-constructor types as far as

Explore

  • Home
  • Add group
  • Groups page
  • Communities
  • Questions
    • New Questions
    • Trending Questions
    • Must read Questions
    • Hot Questions
  • Polls
  • Tags
  • Badges
  • Users
  • Help
  • SEARCH

Footer

© 2021 The Archive Base. All Rights Reserved
With Love by The Archive Base

Insert/edit link

Enter the destination URL

Or link to existing content

    No search term specified. Showing recent items. Search or use up and down arrow keys to select an item.