Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A SID is a Windows Security Identifier: a variable-length value that identifies a user, group, computer, service, process, thread, or logon session. Windows puts SIDs in access tokens and security descriptors, then compares them with ACL entries to decide whether an operation is allowed. “Security ID” is common shorthand, but Microsoft’s formal term is Security Identifier.

What does SID stand for?

In Windows documentation, SID stands for Security Identifier. It is an identity value, not a password, authentication token, or permission level. A SID identifies a security principal—the entity Windows can authenticate and authorize—or a security group. See Microsoft’s Security Identifiers documentation.

How Windows uses a SID

The authorization process is easier to understand as a chain:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. You sign in, and Windows creates an access token.
  2. The token contains your user SID, group SIDs, logon-session information, privileges, and other security data.
  3. Processes run with a primary token describing their security context.
  4. A protected file, registry key, share, or other object has a security descriptor containing an owner SID, primary-group SID, and access-control lists.
  5. The DACL’s access-control entries (ACEs) name trustees by SID and specify allowed or denied rights. Windows compares those SIDs with the token during an access check.

The result is allow or deny, subject to deny entries, ACL ordering, privileges, integrity controls, and other Windows security rules. A SID by itself never means “read” or “administrator”; the surrounding token and ACL determine the effective access. See access tokens and the Windows security model.

#1 Best Overall
Klein Tools VDV526-200 LAN Scout Jr Cable Tester Ethernet Cable Tester Kit
  • VERSATILE CABLE TESTING: Cable tester for data (RJ45) terminated cables and patch cords, ensuring comprehensive testing capabilities
  • LARGE BACKLIT LCD: Backlit LCD display enables easy reading of pin-to-pin wiremap results, even in low-lit areas
  • COMPREHENSIVE FAULT DETECTION: Test for Open, Short, Miswire, Split-Pair faults, Cross-over, and Shield, providing thorough fault detection
  • INTUITIVE USER INTERFACE: User-friendly interface with three buttons and simple, easy-to-identify test responses, ensuring a smooth testing experience
  • MULTIPLE TONE GENERATOR STYLES: Tone on a single wire, wire pair, or all 8 conductor wires using the multiple style tone generator (solid/warble); requires probe Cat. No. VDV500-123 (sold separately)

What a SID looks like

S-1-5-21-1463437245-1224812800-863842198-1105

The hyphenated text is a readable representation of a binary, variable-length SID. In this example:

Part Example Meaning
Prefix S String representation of a SID
Revision 1 SID structure revision
Identifier authority 5 Windows NT authority in common Windows SIDs
Base subauthorities 21-1463437245-1224812800-863842198 Domain or computer scope issued by a security authority
RID 1105 Relative identifier for an account or group in that scope

Not every SID has this exact number of sections. SIDs can contain different numbers of subauthorities; the SID structure is variable-length.

Domain SID, machine SID, and RID

A domain SID is the common base used for domain accounts and groups. A particular object receives a RID appended to that base:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Domain SID: S-1-5-21-1463437245-1224812800-863842198
User SID:   S-1-5-21-1463437245-1224812800-863842198-1105

Local users and groups receive SIDs from the local computer’s security authority and commonly share a computer-specific base. A RID is meaningful only together with its issuing authority and base SID; the final number alone is not a globally identifying user ID. For example, a final RID of 500 is associated with the built-in Administrator in common Windows account structures, but the complete SID and scope still matter.

SID versus username

Account name SID
Human-readable Primarily machine-readable
Can normally be renamed Normally remains unchanged when the name changes
Can be reused for another account A recreated account receives a different SID
May be ambiguous across domains or computers Identifies the principal within its issuing scope

Windows permissions are tied to SIDs, not display names. Renaming an account normally preserves its SID and therefore its existing permissions. Deleting it and creating a new account with the same name creates a new SID, so old permissions do not automatically follow.

Rank #2
Sale
Klein Tools VDV501-851 Scout Pro 3 Tester Starter Set Cable Tester
  • VERSATILE CABLE TESTING: Cable tester tests voice (RJ11/12), data (RJ45), and video (coax F-connector) terminated cables, providing clear results for comprehensive testing on unenergized Ethernet cables (not designed to test PoE)
  • EXTENDED CABLE LENGTH MEASUREMENT: Measure cable length up to 2000 feet (610 m), allowing for precise cable length determination
  • COMPREHENSIVE FAULT DETECTION: Test for Open, Short, Miswire, or Split-Pair faults, ensuring thorough fault detection and identification
  • BACKLIT LCD DISPLAY: Backlit LCD screen displays cable length, wiremap, cable ID, and test results, ensuring easy readability in various lighting conditions
  • EFFICIENT CABLE TRACING: Trace cables, wire pairs, and individual conductor wires using the multiple style tone generator (requires analog probe Cat. No. VDV500-123, sold separately), simplifying cable tracing tasks

Why SIDs matter to ACLs

A file or other securable object has a security descriptor. Its major components can include an owner SID, primary-group SID, discretionary access control list (DACL), and system access control list (SACL). DACL entries identify trustees by SID and contain their rights. In security-descriptor string notation, these sections are represented by O:, G:, D:, and S:; see Microsoft’s security descriptor format.

If an account is deleted, its SID can remain in a file ACL. Windows may then show Account Unknown (S-1-5-21-…). That usually means the SID cannot currently be translated into a name—not that the entry is automatically malicious or invalid.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Rename, delete, recreate, or migrate an account

Action SID result Typical permission result
Rename account Usually unchanged Existing permissions generally continue to work
Delete account Directory object is removed; SID may remain in ACLs Entry can become unresolved
Recreate the same name New SID (and normally a new directory-object GUID) Old ACLs do not automatically apply
Move to another domain New domain SID; old SID may be retained in SIDHistory Old access can continue during a supported migration

What is SIDHistory?

SIDHistory is an Active Directory attribute used during domain migrations and mergers. A migrated user or group can retain a previous SID in its access token, allowing ACLs that reference the old SID to continue working. It is not a general-purpose manual permission-transfer mechanism. Because an unexpected historical SID can preserve access associated with a formerly privileged identity, administrators should tightly control and audit it. Read the migration context in Microsoft’s SID guidance.

Common well-known SIDs

Well-known SIDs have predefined values for generic users or groups. Their meaning depends on the relevant Windows security model and operating-system context.

SID Name Meaning
S-1-0-0 Null SID No security principal or unknown SID
S-1-1-0 Everyone (World) All users represented by that group
S-1-2-0 Local Users who signed in locally
S-1-3-0 Creator Owner Placeholder for the creator’s SID in inherited permissions
S-1-5-2 Network Users accessing through the network
S-1-5-6 Service Accounts logged on as a service
S-1-5-11 Authenticated Users Users authenticated by the system
S-1-5-18 Local System Windows Local System account
S-1-5-32-544 Built-in Administrators Built-in local Administrators group

Microsoft distinguishes universal well-known SIDs, Windows-specific values, and domain-specific SIDs. Consult the well-known SID specifications when an exact value matters.

Rank #3
NOYAFA NF-8508 Network Cable Tester with Optical Power Meter
  • Multifunctional NOYAFA NF-8508 Network Cable Tester: There are nine features to meet your needs. Continuity Testing, Cable Scan, Port Flash, Length Measurement, POE Power Supply Test, QC testing, Optical Power Meter, VFL and NVC function.It is perfectly suited for various engineering cabling projects, network troubleshooting, network equipment maintenance and testing scenarios. Its precise cable scanning and fault localization capabilities help you effortlessly pinpoint the root cause of issues.
  • 7 WAVELENGTHS OPTICAL POWER METER: NF-8508 network cable tester can measure 7 standard wavelengths, 850/1300/1310/1490/1550/1625/1650, power detecting range(dBm): -70 ~ +10. Its power detection range spans from -70 dBm to +10 dBm, supporting FC/SC/ST connectors. It enables precise fiber optic power measurement, helping users efficiently assess fiber signal strength and ensure healthy fiber link operation. It effortlessly detects attenuation issues within fibers, thereby safeguarding fiber network stability.
  • High Efficiency Visual Fault Locator: Easy identification of fiber breakpoints, poor connections, bending or cracking. Excellent for finding the right fiber to splice or quickly finding a break. Emmiting Energy: standard wavelenth: 650nm. Fast flashing, slow flashing, high precison.The built-in self-calibration ensures stable long-term performance, and Class IIIa laser (output<5mW) ensures safe daily operation.
  • PORT FLASHING:The indicator light on the connection port in the NF-8508 device flashes to help accurately locate the cable. Displays port information, including operating speed, duplex mode, and negotiation settings. Port lights flash on the same screen to show the port's operating speed, making it easy to pinpoint lines and ports.
  • PoE Testing and Cable Length Test: PoE testing can check cable mapping polarity and voltage of PoE network switches, withstand 60VDC. Automatically detects and switches between 10M/100M/1000M modes, Includes cable tracking, short circuit test, interruption of circuit test and etc The RJ45 cable tester can quickly measure the length of the cable with a range of 200m. Not only network cables, but also phone lines and BNC cables.

Where SIDs are stored

Local account and group identities are managed by the local security authority and Security Accounts Manager. Domain account and group SIDs are attributes of objects in Active Directory Domain Services. Object security descriptors store owner, group, and ACL trustee SIDs. Avoid editing the registry or directory database directly; use supported Windows and Active Directory administration tools.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How to find a SID

Current account: Command Prompt

whoami /user

This displays the signed-in account and its SID. To display the complete current token, including group SIDs and privileges, run:

whoami /all

Microsoft documents both options in the whoami command reference.

Local accounts: PowerShell

Get-LocalUser | Select-Object Name, SID

This uses the Microsoft.PowerShell.LocalAccounts module and is intended for local accounts. The module may be unavailable in 32-bit PowerShell on a 64-bit system. Domain lookups require domain-capable tools or directory queries, and resolution can fail when an account is deleted, a domain is unreachable, or the SID belongs to another trust boundary.

Name-to-SID and SID-to-name lookup

Microsoft Sysinternals PsGetSid can translate in either direction:

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #4
Sale
iMBAPrice - RJ45 Network Cable Tester for Lan Phone RJ45/RJ11/RJ12/CAT5/CAT6/CAT7 UTP Wire Test Tool
  • Automatically runs all tests and checks for continuity, open, shorted and crossed wire pairs. Visible LED status display.
  • Cable state testing (2-wire): Line DC detecting, anode and cathode determination,Ringing signal detecting open, short and cross circuit testing
  • Cable Type: RJ11 Telephone cable and RJ45 LAN cable
  • Connectors: Ethernet Cat 5, Ethernet Cat 5e, Ethernet Cat 6, Ethernet Cat 7, RJ11 6P and RJ45 8P
  • Power Source: DC9V Battery Required (not included)
psgetsid
psgetsid administrator
psgetsid S-1-5-21-1463437245-1223435678-2345678901-1105

It can also query remote computers, subject to authentication and permissions. The cited PsGetSid release lists client support beginning with Windows 8.1 and server support beginning with Windows Server 2012.

Diagnosing “Account Unknown (SID)”

Common causes include a deleted account, a migration to another domain, temporary domain or trust failure, an ACL imported from another computer or backup, or an orphaned old permission.

  1. Copy the complete SID, including every component.
  2. Confirm the computer is online and connected to the relevant domain.
  3. Try a trusted lookup such as PsGetSid.
  4. Check whether the original account was renamed, deleted, or migrated.
  5. Review the ACL and business requirement before removing or replacing the entry.

Removing an unresolved entry may remove access, but it does not repair a migration or identity-history problem. Preserve evidence first when investigating a security incident.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Are SIDs secret?

Generally, no. SIDs appear in ACLs, access tokens, event logs, and security descriptors, and a SID alone does not authenticate anyone or grant privileges. Nevertheless, SIDs reveal account or domain context, and an unexpected SID in an ACL, token, or SIDHistory attribute can be important during a security review.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a SID can—and cannot—prove in an investigation

A SID identifies the security principal associated with a permission or event record; it does not by itself prove who performed an action. Investigators should also examine the event ID, timestamp, logon ID, source workstation or IP, process and token context, group membership, account changes, name-resolution status, and any SIDHistory.

Best Value
Network Ethernet Cable Tester for LAN RJ45 RJ11 CAT5 CAT5E CAT6 CAT6A CAT7, Ethernet Wire Tester Tool UTP/STP Continuity Test for Telephone Line Finder Home Repair (HT812A)
  • Multi-Function Network Cable Tester: Supports RJ45 (CAT5, CAT5e, CAT6, CAT6A, CAT7) and RJ11 telephone cables. Quickly detects continuity, short circuits, open wires, miswiring, and cable shielding status, ensuring your LAN or phone lines are correctly wired and ready to use.
  • Fast/Slow Mode with LED Indicators: Switch between fast and slow scan speeds to identify wiring issues more precisely. LED lights on both master and remote units show wire order, making it easy to spot errors like open pairs or misaligned pins at a glance.
  • Split-Type Design for Long-Distance Testing: Master and remote units can be detached and used separately, allowing you to test both ends of a long cable run, ideal for wall-mounted ports, long runs, or structured cabling. Perfect for home, office, or professional IT setups.
  • Compact, Lightweight & Durable: Ergonomically designed with sturdy ABS housing, this pocket-sized tester is ideal for on-the-go network engineers, DIYers, and electricians. It’s your go-to toolkit for cable maintenance, upgrades, or new installations.
  • Safe & Easy to Use: Simple one-button operation makes testing quick and hassle-free. LED indicators clearly show wiring status, while the G light instantly identifies shielded (FTP/STP) or unshielded (UTP) cables. Supports safe testing of telephone lines with typical voltages under 48-72V, ideal for both home and professional use.

SID, GUID, password, and access token: the distinction

  • SID: Identifier used directly by Windows authorization.
  • GUID: A different identifier often used for an Active Directory object; it does not replace a SID in an ACL.
  • Password or credential: Secret used for authentication, not an identity value.
  • Access token: The complete security context containing a user SID, group SIDs, privileges, logon data, and other attributes.

Common misconceptions

  • “Every SID is globally unique.” Uniqueness is described within the relevant local computer, domain, enterprise, and issuing-authority scope.
  • “The final number identifies the user worldwide.” It is a RID whose meaning depends on the full SID.
  • “An unknown SID is malicious.” It often reflects deletion, migration, offline domain services, or an imported ACL.
  • “Duplicate machine SIDs always break a network.” That is an outdated oversimplification; behavior depends on Windows version, deployment method, local accounts, imaging, and domain membership.
  • “Changing a SID is a normal fix.” Do not manually alter SIDs. Correct the account, migration, or ACL through supported administration procedures.

Frequently Asked Questions

Does renaming a Windows user change its SID?

Normally no. The name changes, but the SID remains the same, so existing permissions generally continue to apply.

Does deleting and recreating an account preserve its permissions?

No. The recreated account receives a new SID. Old ACL entries reference the deleted account’s SID unless a supported migration uses SIDHistory.

Is a SID the same as a username?

No. A username is a display and logon name; the SID is the identity value Windows uses for authorization.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Can I change a SID manually?

Do not manually edit SIDs. Use supported Windows or Active Directory account, migration, and ACL tools.

The Bottom Line

Bottom line: Names are for people; SIDs are what Windows uses to enforce identity-based access. When a name changes, the SID usually does not. When an account is recreated, the SID changes—and permissions tied to the old identity do not automatically follow.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.