Free tools Windows power users keep installed
One-click scans. No signup required.
Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
Authenticated Users is a Windows special security identity with the well-known SID S-1-5-11. It matches security principals that Windows has successfully authenticated, including users and computers and, subject to trust and resource context, identities from trusted domains. It is not a manually maintained Active Directory group, and it does not grant permission by itself.
Use it when the requirement truly is “any authenticated identity may access this resource.” For sensitive data, write access, or human-only access, a dedicated security group is usually safer.
What Authenticated Users means
Windows uses Authenticated Users as a well-known identity that can appear in access-control entries. Its SID is S-1-5-11. Membership is determined when Windows builds an access token for a logon; administrators do not populate it in Active Directory Users and Computers.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minute| Property | Value |
|---|---|
| Display name | Authenticated Users |
| SID | S-1-5-11 |
| Type | Special identity / well-known security principal |
| Membership | Calculated by Windows from the authentication context |
| Common uses | File, share, printer, service, application, user-rights and policy permissions |
Microsoft documents the SID and scope in its security-identifier reference and describes special identities in its special-identities guide.
#1 Best Overall
Is it a real Active Directory group?
It behaves like a group during an access check, and ACL editors display it as NT AUTHORITYAuthenticated Users. However, it is not an ordinary AD security group with a member list that administrators can edit. Special identities are not managed through the normal ADUC group-membership workflow; Microsoft explains this limitation in its troubleshooting guidance.
Who is included?
Domain users
A user who successfully authenticates to Active Directory normally receives S-1-5-11 in the resulting token.
Local users
A local account that successfully authenticates to a Windows computer can match Authenticated Users on that computer. Its effective rights still depend on local groups, ACLs, logon type, remote-account restrictions and other policy. Local-account scope is described in Microsoft’s local-account documentation.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Computer accounts
Windows authenticates computers as well as people. A computer account can therefore match an ACL on a remote share, service or other network resource. This is a common reason a permission intended for “users” is broader than expected.
Service accounts and scheduled-task identities
A service or scheduled task may receive Authenticated Users when it authenticates normally, but its token is not necessarily the same as an interactive administrator’s token. Check the account configured for the service, task or application pool.
Rank #2
Identities from trusted domains
Authenticated Users is not automatically limited to the current domain. Authenticated principals from trusted domains can qualify, depending on the trust, authentication method, SID handling and resource-server context.
Who is excluded?
Anonymous Logon
Anonymous Logon is the separate identity S-1-5-7. A connection that supplies no authenticated identity does not become Authenticated Users. Do not confuse a web site’s “anonymous access” setting with the Windows Anonymous Logon SID.
Guest
Windows explicitly excludes the built-in Guest identity from Authenticated Users, even where Guest can authenticate in a particular configuration. The exclusion is specified in Microsoft’s well-known SID specification.
Authenticated Users compared with similar identities
| Identity | What it represents | Anonymous included? | Guest included? | Computer accounts? |
|---|---|---|---|---|
| Authenticated Users | Security principals successfully authenticated | No | No | Yes |
| Everyone | Broad Windows identity for interactive, network, dial-up and authenticated contexts | Not by default on modern Windows | Yes, according to Microsoft’s special-groups documentation | Broad enough to cover many computer access contexts |
| Anonymous Logon | Unauthenticated access identity (S-1-5-7) |
Itself | No | No |
| Users | A particular local built-in group | No | Only if explicitly a member | Not generally |
| Domain Users | Active Directory group containing domain user accounts | No | Only if explicitly a member | Not generally |
| Administrators | Membership in an administrative group | No | No normal assumption | Only where explicitly a member |
Microsoft notes that modern Windows no longer includes Anonymous Logon in Everyone by default; legacy systems and unusual policy configurations should be evaluated separately. Authenticated Users is generally narrower than Everyone, but it is still not a human-only or single-domain boundary.
Authentication is not authorization
Authentication answers “Who are you?” Authorization answers “What may that identity do?” The presence of S-1-5-11 proves only that Windows accepted an identity. Access still depends on the target ACL, inherited entries, explicit allow and deny ACEs, user-rights assignments, application checks and the authentication context. Microsoft’s overview of Windows access control explains this separation.
Rank #3
An ACL entry for Authenticated Users might allow read, modify, execute, network logon, printer use or application access. It grants none of those rights unless the resource’s authorization system references the identity.
How to verify the identity in a token
Run these commands in the session that is actually accessing the resource:
whoami
whoami /user
whoami /groups
whoami /all
whoami /all displays the current account, SIDs, group memberships and privileges. Look for an entry similar to:
NT AUTHORITYAuthenticated Users
S-1-5-11
The output describes one logon token. After a group or policy change, sign out and sign in again, restart the relevant service, or create a new session before testing; existing process tokens are not automatically rebuilt.
How to inspect a resource ACL
PowerShell
Get-Acl -Path 'C:DataExample' | Format-List
Get-Acl reads the security descriptor. Inspect explicit and inherited rules and identify entries for Authenticated Users or NT AUTHORITYAuthenticated Users.
The Tool Desk
Outbyte Driver Updater FREEFix the driver behind crashes, sound loss and screen glitchesFind Drivers →Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Graphical interface
- Right-click the file or folder and select Properties.
- Open Security, then select Advanced.
- Review explicit and inherited entries, including both allow and deny rules.
- Confirm which object types child objects inherit the permission.
Effective-permission testing
accesschk.exe -nobanner "NT AUTHORITYAuthenticated Users" C:DataExample
Microsoft Sysinternals AccessChk can inspect effective permissions on files, directories, registry keys, services and other objects. For remote resources, evaluate the token in the resource-server context; Microsoft documents pitfalls in its remote access-check guidance.
When using Authenticated Users is appropriate
- Read-only internal documentation intended for every authenticated employee or device.
- A common software-distribution location containing non-sensitive content.
- Baseline configuration or utility access for all authenticated clients.
- A printer or service deliberately available to all authenticated identities.
State the intended population explicitly. “Any authenticated identity” may include machines, service accounts, local accounts and trusted-domain principals.
When it is too broad
Use a dedicated security group when access should be limited to a department, project, application role, administrator set, one domain, or human users only. Names such as Finance-Read, App-Operators and ProjectX-Contributors make the authorization decision reviewable and maintainable.
Be especially cautious with broad Modify, Write, service-control or executable permissions. An authenticated but compromised account, service identity or computer can otherwise gain a path to alter content or influence other systems.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →IIS, SMB and service-specific edge cases
IIS anonymous access
IIS anonymous authentication may run filesystem access under an account such as IUSR_computer-name. That account is different from the Windows Anonymous Logon identity, and the filesystem decision may be made for the IIS account rather than the browser visitor.
Best Value
SMB shares
For a network file share, evaluate both share permissions and NTFS permissions. The effective result is constrained by the two layers, and the connecting identity may be a user, computer or service rather than the person at the keyboard.
Services and scheduled tasks
Identify the configured service, task or application-pool account before diagnosing access. Testing with your interactive token can produce a false conclusion.
Why access can still be denied
- Confirm the identity actually making the request.
- Run
whoami /allin that identity’s session and check forS-1-5-11. - Inspect the target ACL and inheritance.
- For SMB, inspect both share and NTFS permissions.
- Check applicable deny ACEs and user-rights assignments for the logon type.
- Verify the account authenticated to the expected computer or domain and that the required trust exists.
- Check whether IIS, a service, task or application performs the operation under another identity.
- Reauthenticate after membership or policy changes.
- Review authentication and security events if Kerberos, NTLM or another provider is failing.
- Use AccessChk or the Advanced Security Effective Access view for a reproducible test.
Kerberos and NTLM are authentication protocols, not alternate names for Authenticated Users. Windows can use either depending on the scenario; the resulting token and subsequent authorization checks determine access. See Microsoft’s NTLM overview and authentication-policy documentation.
Practical decision rule
- Choose Authenticated Users when the deliberate requirement is broad access for every qualifying authenticated principal.
- Choose Domain Users only when domain-user membership, rather than computer or trusted-domain identity, is the intended boundary.
- Choose a purpose-built security group when access has business significance or must exclude machines, services, local accounts or external trusted identities.
- Never interpret “authenticated” as “trusted,” “authorized,” “human” or “safe.”
Frequently Asked Questions
Is Authenticated Users the same as Domain Users?
No. Domain Users is an Active Directory group of domain user accounts; Authenticated Users is the Windows identity S-1-5-11 and can also match computers, service identities, local accounts and qualifying principals from trusted domains.
Can I add or remove members?
No. Windows determines membership in each access token; manage the ACL or use a separate security group when you need a controlled membership list.
Does it grant administrator access?
No. It grants nothing unless an ACL, user right or application rule assigns permission to the identity.
Does IIS anonymous access count as Authenticated Users?
Not necessarily. IIS may perform filesystem access under a configured account such as IUSR; that account is distinct from Windows Anonymous Logon and from the end visitor.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteThe Bottom Line
Authenticated Users (S-1-5-11) is a convenient authentication-status identity, not a security boundary. It can include people, computers, services, local accounts and trusted-domain principals. Grant it only the permissions that every such authenticated identity is genuinely meant to receive; otherwise use a narrowly defined security group.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

