Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Authenticated Users is a Windows special security identity with the well-known SID S-1-5-11. It matches security principals that Windows has successfully authenticated, including users and computers and, subject to trust and resource context, identities from trusted domains. It is not a manually maintained Active Directory group, and it does not grant permission by itself.

Use it when the requirement truly is “any authenticated identity may access this resource.” For sensitive data, write access, or human-only access, a dedicated security group is usually safer.

What Authenticated Users means

Windows uses Authenticated Users as a well-known identity that can appear in access-control entries. Its SID is S-1-5-11. Membership is determined when Windows builds an access token for a logon; administrators do not populate it in Active Directory Users and Computers.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Property Value
Display name Authenticated Users
SID S-1-5-11
Type Special identity / well-known security principal
Membership Calculated by Windows from the authentication context
Common uses File, share, printer, service, application, user-rights and policy permissions

Microsoft documents the SID and scope in its security-identifier reference and describes special identities in its special-identities guide.

Is it a real Active Directory group?

It behaves like a group during an access check, and ACL editors display it as NT AUTHORITYAuthenticated Users. However, it is not an ordinary AD security group with a member list that administrators can edit. Special identities are not managed through the normal ADUC group-membership workflow; Microsoft explains this limitation in its troubleshooting guidance.

Who is included?

Domain users

A user who successfully authenticates to Active Directory normally receives S-1-5-11 in the resulting token.

Local users

A local account that successfully authenticates to a Windows computer can match Authenticated Users on that computer. Its effective rights still depend on local groups, ACLs, logon type, remote-account restrictions and other policy. Local-account scope is described in Microsoft’s local-account documentation.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Computer accounts

Windows authenticates computers as well as people. A computer account can therefore match an ACL on a remote share, service or other network resource. This is a common reason a permission intended for “users” is broader than expected.

Service accounts and scheduled-task identities

A service or scheduled task may receive Authenticated Users when it authenticates normally, but its token is not necessarily the same as an interactive administrator’s token. Check the account configured for the service, task or application pool.

Identities from trusted domains

Authenticated Users is not automatically limited to the current domain. Authenticated principals from trusted domains can qualify, depending on the trust, authentication method, SID handling and resource-server context.

Who is excluded?

Anonymous Logon

Anonymous Logon is the separate identity S-1-5-7. A connection that supplies no authenticated identity does not become Authenticated Users. Do not confuse a web site’s “anonymous access” setting with the Windows Anonymous Logon SID.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Guest

Windows explicitly excludes the built-in Guest identity from Authenticated Users, even where Guest can authenticate in a particular configuration. The exclusion is specified in Microsoft’s well-known SID specification.

Authenticated Users compared with similar identities

Identity What it represents Anonymous included? Guest included? Computer accounts?
Authenticated Users Security principals successfully authenticated No No Yes
Everyone Broad Windows identity for interactive, network, dial-up and authenticated contexts Not by default on modern Windows Yes, according to Microsoft’s special-groups documentation Broad enough to cover many computer access contexts
Anonymous Logon Unauthenticated access identity (S-1-5-7) Itself No No
Users A particular local built-in group No Only if explicitly a member Not generally
Domain Users Active Directory group containing domain user accounts No Only if explicitly a member Not generally
Administrators Membership in an administrative group No No normal assumption Only where explicitly a member

Microsoft notes that modern Windows no longer includes Anonymous Logon in Everyone by default; legacy systems and unusual policy configurations should be evaluated separately. Authenticated Users is generally narrower than Everyone, but it is still not a human-only or single-domain boundary.

Authentication is not authorization

Authentication answers “Who are you?” Authorization answers “What may that identity do?” The presence of S-1-5-11 proves only that Windows accepted an identity. Access still depends on the target ACL, inherited entries, explicit allow and deny ACEs, user-rights assignments, application checks and the authentication context. Microsoft’s overview of Windows access control explains this separation.

An ACL entry for Authenticated Users might allow read, modify, execute, network logon, printer use or application access. It grants none of those rights unless the resource’s authorization system references the identity.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to verify the identity in a token

Run these commands in the session that is actually accessing the resource:

whoami
whoami /user
whoami /groups
whoami /all

whoami /all displays the current account, SIDs, group memberships and privileges. Look for an entry similar to:

NT AUTHORITYAuthenticated Users
S-1-5-11

The output describes one logon token. After a group or policy change, sign out and sign in again, restart the relevant service, or create a new session before testing; existing process tokens are not automatically rebuilt.

How to inspect a resource ACL

PowerShell

Get-Acl -Path 'C:DataExample' | Format-List

Get-Acl reads the security descriptor. Inspect explicit and inherited rules and identify entries for Authenticated Users or NT AUTHORITYAuthenticated Users.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Graphical interface

  1. Right-click the file or folder and select Properties.
  2. Open Security, then select Advanced.
  3. Review explicit and inherited entries, including both allow and deny rules.
  4. Confirm which object types child objects inherit the permission.

Effective-permission testing

accesschk.exe -nobanner "NT AUTHORITYAuthenticated Users" C:DataExample

Microsoft Sysinternals AccessChk can inspect effective permissions on files, directories, registry keys, services and other objects. For remote resources, evaluate the token in the resource-server context; Microsoft documents pitfalls in its remote access-check guidance.

When using Authenticated Users is appropriate

  • Read-only internal documentation intended for every authenticated employee or device.
  • A common software-distribution location containing non-sensitive content.
  • Baseline configuration or utility access for all authenticated clients.
  • A printer or service deliberately available to all authenticated identities.

State the intended population explicitly. “Any authenticated identity” may include machines, service accounts, local accounts and trusted-domain principals.

When it is too broad

Use a dedicated security group when access should be limited to a department, project, application role, administrator set, one domain, or human users only. Names such as Finance-Read, App-Operators and ProjectX-Contributors make the authorization decision reviewable and maintainable.

Be especially cautious with broad Modify, Write, service-control or executable permissions. An authenticated but compromised account, service identity or computer can otherwise gain a path to alter content or influence other systems.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

IIS, SMB and service-specific edge cases

IIS anonymous access

IIS anonymous authentication may run filesystem access under an account such as IUSR_computer-name. That account is different from the Windows Anonymous Logon identity, and the filesystem decision may be made for the IIS account rather than the browser visitor.

SMB shares

For a network file share, evaluate both share permissions and NTFS permissions. The effective result is constrained by the two layers, and the connecting identity may be a user, computer or service rather than the person at the keyboard.

Services and scheduled tasks

Identify the configured service, task or application-pool account before diagnosing access. Testing with your interactive token can produce a false conclusion.

Why access can still be denied

  1. Confirm the identity actually making the request.
  2. Run whoami /all in that identity’s session and check for S-1-5-11.
  3. Inspect the target ACL and inheritance.
  4. For SMB, inspect both share and NTFS permissions.
  5. Check applicable deny ACEs and user-rights assignments for the logon type.
  6. Verify the account authenticated to the expected computer or domain and that the required trust exists.
  7. Check whether IIS, a service, task or application performs the operation under another identity.
  8. Reauthenticate after membership or policy changes.
  9. Review authentication and security events if Kerberos, NTLM or another provider is failing.
  10. Use AccessChk or the Advanced Security Effective Access view for a reproducible test.

Kerberos and NTLM are authentication protocols, not alternate names for Authenticated Users. Windows can use either depending on the scenario; the resulting token and subsequent authorization checks determine access. See Microsoft’s NTLM overview and authentication-policy documentation.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Practical decision rule

  • Choose Authenticated Users when the deliberate requirement is broad access for every qualifying authenticated principal.
  • Choose Domain Users only when domain-user membership, rather than computer or trusted-domain identity, is the intended boundary.
  • Choose a purpose-built security group when access has business significance or must exclude machines, services, local accounts or external trusted identities.
  • Never interpret “authenticated” as “trusted,” “authorized,” “human” or “safe.”

Frequently Asked Questions

Is Authenticated Users the same as Domain Users?

No. Domain Users is an Active Directory group of domain user accounts; Authenticated Users is the Windows identity S-1-5-11 and can also match computers, service identities, local accounts and qualifying principals from trusted domains.

Can I add or remove members?

No. Windows determines membership in each access token; manage the ACL or use a separate security group when you need a controlled membership list.

Does it grant administrator access?

No. It grants nothing unless an ACL, user right or application rule assigns permission to the identity.

Does IIS anonymous access count as Authenticated Users?

Not necessarily. IIS may perform filesystem access under a configured account such as IUSR; that account is distinct from Windows Anonymous Logon and from the end visitor.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The Bottom Line

Authenticated Users (S-1-5-11) is a convenient authentication-status identity, not a security boundary. It can include people, computers, services, local accounts and trusted-domain principals. Grant it only the permissions that every such authenticated identity is genuinely meant to receive; otherwise use a narrowly defined security group.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.