Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.
A SID is a Windows Security Identifier: a variable-length value that identifies a user, group, computer, service, process, thread, or logon session. Windows puts SIDs in access tokens and security descriptors, then compares them with ACL entries to decide whether an operation is allowed. “Security ID” is common shorthand, but Microsoft’s formal term is Security Identifier.
What does SID stand for?
In Windows documentation, SID stands for Security Identifier. It is an identity value, not a password, authentication token, or permission level. A SID identifies a security principal—the entity Windows can authenticate and authorize—or a security group. See Microsoft’s Security Identifiers documentation.
How Windows uses a SID
The authorization process is easier to understand as a chain:
Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchWindows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstall- You sign in, and Windows creates an access token.
- The token contains your user SID, group SIDs, logon-session information, privileges, and other security data.
- Processes run with a primary token describing their security context.
- A protected file, registry key, share, or other object has a security descriptor containing an owner SID, primary-group SID, and access-control lists.
- The DACL’s access-control entries (ACEs) name trustees by SID and specify allowed or denied rights. Windows compares those SIDs with the token during an access check.
The result is allow or deny, subject to deny entries, ACL ordering, privileges, integrity controls, and other Windows security rules. A SID by itself never means “read” or “administrator”; the surrounding token and ACL determine the effective access. See access tokens and the Windows security model.
#1 Best Overall
- VERSATILE CABLE TESTING: Cable tester for data (RJ45) terminated cables and patch cords, ensuring comprehensive testing capabilities
- LARGE BACKLIT LCD: Backlit LCD display enables easy reading of pin-to-pin wiremap results, even in low-lit areas
- COMPREHENSIVE FAULT DETECTION: Test for Open, Short, Miswire, Split-Pair faults, Cross-over, and Shield, providing thorough fault detection
- INTUITIVE USER INTERFACE: User-friendly interface with three buttons and simple, easy-to-identify test responses, ensuring a smooth testing experience
- MULTIPLE TONE GENERATOR STYLES: Tone on a single wire, wire pair, or all 8 conductor wires using the multiple style tone generator (solid/warble); requires probe Cat. No. VDV500-123 (sold separately)
What a SID looks like
S-1-5-21-1463437245-1224812800-863842198-1105
The hyphenated text is a readable representation of a binary, variable-length SID. In this example:
| Part | Example | Meaning |
|---|---|---|
| Prefix | S |
String representation of a SID |
| Revision | 1 |
SID structure revision |
| Identifier authority | 5 |
Windows NT authority in common Windows SIDs |
| Base subauthorities | 21-1463437245-1224812800-863842198 |
Domain or computer scope issued by a security authority |
| RID | 1105 |
Relative identifier for an account or group in that scope |
Not every SID has this exact number of sections. SIDs can contain different numbers of subauthorities; the SID structure is variable-length.
Domain SID, machine SID, and RID
A domain SID is the common base used for domain accounts and groups. A particular object receives a RID appended to that base:
Domain SID: S-1-5-21-1463437245-1224812800-863842198
User SID: S-1-5-21-1463437245-1224812800-863842198-1105
Local users and groups receive SIDs from the local computer’s security authority and commonly share a computer-specific base. A RID is meaningful only together with its issuing authority and base SID; the final number alone is not a globally identifying user ID. For example, a final RID of 500 is associated with the built-in Administrator in common Windows account structures, but the complete SID and scope still matter.
SID versus username
| Account name | SID |
|---|---|
| Human-readable | Primarily machine-readable |
| Can normally be renamed | Normally remains unchanged when the name changes |
| Can be reused for another account | A recreated account receives a different SID |
| May be ambiguous across domains or computers | Identifies the principal within its issuing scope |
Windows permissions are tied to SIDs, not display names. Renaming an account normally preserves its SID and therefore its existing permissions. Deleting it and creating a new account with the same name creates a new SID, so old permissions do not automatically follow.
Rank #2
- VERSATILE CABLE TESTING: Cable tester tests voice (RJ11/12), data (RJ45), and video (coax F-connector) terminated cables, providing clear results for comprehensive testing on unenergized Ethernet cables (not designed to test PoE)
- EXTENDED CABLE LENGTH MEASUREMENT: Measure cable length up to 2000 feet (610 m), allowing for precise cable length determination
- COMPREHENSIVE FAULT DETECTION: Test for Open, Short, Miswire, or Split-Pair faults, ensuring thorough fault detection and identification
- BACKLIT LCD DISPLAY: Backlit LCD screen displays cable length, wiremap, cable ID, and test results, ensuring easy readability in various lighting conditions
- EFFICIENT CABLE TRACING: Trace cables, wire pairs, and individual conductor wires using the multiple style tone generator (requires analog probe Cat. No. VDV500-123, sold separately), simplifying cable tracing tasks
Why SIDs matter to ACLs
A file or other securable object has a security descriptor. Its major components can include an owner SID, primary-group SID, discretionary access control list (DACL), and system access control list (SACL). DACL entries identify trustees by SID and contain their rights. In security-descriptor string notation, these sections are represented by O:, G:, D:, and S:; see Microsoft’s security descriptor format.
If an account is deleted, its SID can remain in a file ACL. Windows may then show Account Unknown (S-1-5-21-…). That usually means the SID cannot currently be translated into a name—not that the entry is automatically malicious or invalid.
Rename, delete, recreate, or migrate an account
| Action | SID result | Typical permission result |
|---|---|---|
| Rename account | Usually unchanged | Existing permissions generally continue to work |
| Delete account | Directory object is removed; SID may remain in ACLs | Entry can become unresolved |
| Recreate the same name | New SID (and normally a new directory-object GUID) | Old ACLs do not automatically apply |
| Move to another domain | New domain SID; old SID may be retained in SIDHistory |
Old access can continue during a supported migration |
What is SIDHistory?
SIDHistory is an Active Directory attribute used during domain migrations and mergers. A migrated user or group can retain a previous SID in its access token, allowing ACLs that reference the old SID to continue working. It is not a general-purpose manual permission-transfer mechanism. Because an unexpected historical SID can preserve access associated with a formerly privileged identity, administrators should tightly control and audit it. Read the migration context in Microsoft’s SID guidance.
Common well-known SIDs
Well-known SIDs have predefined values for generic users or groups. Their meaning depends on the relevant Windows security model and operating-system context.
| SID | Name | Meaning |
|---|---|---|
S-1-0-0 |
Null SID | No security principal or unknown SID |
S-1-1-0 |
Everyone (World) | All users represented by that group |
S-1-2-0 |
Local | Users who signed in locally |
S-1-3-0 |
Creator Owner | Placeholder for the creator’s SID in inherited permissions |
S-1-5-2 |
Network | Users accessing through the network |
S-1-5-6 |
Service | Accounts logged on as a service |
S-1-5-11 |
Authenticated Users | Users authenticated by the system |
S-1-5-18 |
Local System | Windows Local System account |
S-1-5-32-544 |
Built-in Administrators | Built-in local Administrators group |
Microsoft distinguishes universal well-known SIDs, Windows-specific values, and domain-specific SIDs. Consult the well-known SID specifications when an exact value matters.
Rank #3
- Multifunctional NOYAFA NF-8508 Network Cable Tester: There are nine features to meet your needs. Continuity Testing, Cable Scan, Port Flash, Length Measurement, POE Power Supply Test, QC testing, Optical Power Meter, VFL and NVC function.It is perfectly suited for various engineering cabling projects, network troubleshooting, network equipment maintenance and testing scenarios. Its precise cable scanning and fault localization capabilities help you effortlessly pinpoint the root cause of issues.
- 7 WAVELENGTHS OPTICAL POWER METER: NF-8508 network cable tester can measure 7 standard wavelengths, 850/1300/1310/1490/1550/1625/1650, power detecting range(dBm): -70 ~ +10. Its power detection range spans from -70 dBm to +10 dBm, supporting FC/SC/ST connectors. It enables precise fiber optic power measurement, helping users efficiently assess fiber signal strength and ensure healthy fiber link operation. It effortlessly detects attenuation issues within fibers, thereby safeguarding fiber network stability.
- High Efficiency Visual Fault Locator: Easy identification of fiber breakpoints, poor connections, bending or cracking. Excellent for finding the right fiber to splice or quickly finding a break. Emmiting Energy: standard wavelenth: 650nm. Fast flashing, slow flashing, high precison.The built-in self-calibration ensures stable long-term performance, and Class IIIa laser (output<5mW) ensures safe daily operation.
- PORT FLASHING:The indicator light on the connection port in the NF-8508 device flashes to help accurately locate the cable. Displays port information, including operating speed, duplex mode, and negotiation settings. Port lights flash on the same screen to show the port's operating speed, making it easy to pinpoint lines and ports.
- PoE Testing and Cable Length Test: PoE testing can check cable mapping polarity and voltage of PoE network switches, withstand 60VDC. Automatically detects and switches between 10M/100M/1000M modes, Includes cable tracking, short circuit test, interruption of circuit test and etc The RJ45 cable tester can quickly measure the length of the cable with a range of 200m. Not only network cables, but also phone lines and BNC cables.
Where SIDs are stored
Local account and group identities are managed by the local security authority and Security Accounts Manager. Domain account and group SIDs are attributes of objects in Active Directory Domain Services. Object security descriptors store owner, group, and ACL trustee SIDs. Avoid editing the registry or directory database directly; use supported Windows and Active Directory administration tools.
Quick wins for a faster PC:
Repair Windows errors before they cause bigger problemsFix Now →Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →How to find a SID
Current account: Command Prompt
whoami /user
This displays the signed-in account and its SID. To display the complete current token, including group SIDs and privileges, run:
whoami /all
Microsoft documents both options in the whoami command reference.
Local accounts: PowerShell
Get-LocalUser | Select-Object Name, SID
This uses the Microsoft.PowerShell.LocalAccounts module and is intended for local accounts. The module may be unavailable in 32-bit PowerShell on a 64-bit system. Domain lookups require domain-capable tools or directory queries, and resolution can fail when an account is deleted, a domain is unreachable, or the SID belongs to another trust boundary.
Name-to-SID and SID-to-name lookup
Microsoft Sysinternals PsGetSid can translate in either direction:
Free tools Windows power users keep installed
One-click scans. No signup required.
Rank #4
- Automatically runs all tests and checks for continuity, open, shorted and crossed wire pairs. Visible LED status display.
- Cable state testing (2-wire): Line DC detecting, anode and cathode determination,Ringing signal detecting open, short and cross circuit testing
- Cable Type: RJ11 Telephone cable and RJ45 LAN cable
- Connectors: Ethernet Cat 5, Ethernet Cat 5e, Ethernet Cat 6, Ethernet Cat 7, RJ11 6P and RJ45 8P
- Power Source: DC9V Battery Required (not included)
psgetsid
psgetsid administrator
psgetsid S-1-5-21-1463437245-1223435678-2345678901-1105
It can also query remote computers, subject to authentication and permissions. The cited PsGetSid release lists client support beginning with Windows 8.1 and server support beginning with Windows Server 2012.
Diagnosing “Account Unknown (SID)”
Common causes include a deleted account, a migration to another domain, temporary domain or trust failure, an ACL imported from another computer or backup, or an orphaned old permission.
- Copy the complete SID, including every component.
- Confirm the computer is online and connected to the relevant domain.
- Try a trusted lookup such as PsGetSid.
- Check whether the original account was renamed, deleted, or migrated.
- Review the ACL and business requirement before removing or replacing the entry.
Removing an unresolved entry may remove access, but it does not repair a migration or identity-history problem. Preserve evidence first when investigating a security incident.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Are SIDs secret?
Generally, no. SIDs appear in ACLs, access tokens, event logs, and security descriptors, and a SID alone does not authenticate anyone or grant privileges. Nevertheless, SIDs reveal account or domain context, and an unexpected SID in an ACL, token, or SIDHistory attribute can be important during a security review.
Do these 3 things before closing this tab:
1Clear out junk files and repair common Windows errors2Fix the driver behind crashes, sound loss and screen glitches3Repair Windows errors before they cause bigger problemsWhat a SID can—and cannot—prove in an investigation
A SID identifies the security principal associated with a permission or event record; it does not by itself prove who performed an action. Investigators should also examine the event ID, timestamp, logon ID, source workstation or IP, process and token context, group membership, account changes, name-resolution status, and any SIDHistory.
Best Value
- Multi-Function Network Cable Tester: Supports RJ45 (CAT5, CAT5e, CAT6, CAT6A, CAT7) and RJ11 telephone cables. Quickly detects continuity, short circuits, open wires, miswiring, and cable shielding status, ensuring your LAN or phone lines are correctly wired and ready to use.
- Fast/Slow Mode with LED Indicators: Switch between fast and slow scan speeds to identify wiring issues more precisely. LED lights on both master and remote units show wire order, making it easy to spot errors like open pairs or misaligned pins at a glance.
- Split-Type Design for Long-Distance Testing: Master and remote units can be detached and used separately, allowing you to test both ends of a long cable run, ideal for wall-mounted ports, long runs, or structured cabling. Perfect for home, office, or professional IT setups.
- Compact, Lightweight & Durable: Ergonomically designed with sturdy ABS housing, this pocket-sized tester is ideal for on-the-go network engineers, DIYers, and electricians. It’s your go-to toolkit for cable maintenance, upgrades, or new installations.
- Safe & Easy to Use: Simple one-button operation makes testing quick and hassle-free. LED indicators clearly show wiring status, while the G light instantly identifies shielded (FTP/STP) or unshielded (UTP) cables. Supports safe testing of telephone lines with typical voltages under 48-72V, ideal for both home and professional use.
SID, GUID, password, and access token: the distinction
- SID: Identifier used directly by Windows authorization.
- GUID: A different identifier often used for an Active Directory object; it does not replace a SID in an ACL.
- Password or credential: Secret used for authentication, not an identity value.
- Access token: The complete security context containing a user SID, group SIDs, privileges, logon data, and other attributes.
Common misconceptions
- “Every SID is globally unique.” Uniqueness is described within the relevant local computer, domain, enterprise, and issuing-authority scope.
- “The final number identifies the user worldwide.” It is a RID whose meaning depends on the full SID.
- “An unknown SID is malicious.” It often reflects deletion, migration, offline domain services, or an imported ACL.
- “Duplicate machine SIDs always break a network.” That is an outdated oversimplification; behavior depends on Windows version, deployment method, local accounts, imaging, and domain membership.
- “Changing a SID is a normal fix.” Do not manually alter SIDs. Correct the account, migration, or ACL through supported administration procedures.
Frequently Asked Questions
Does renaming a Windows user change its SID?
Normally no. The name changes, but the SID remains the same, so existing permissions generally continue to apply.
Does deleting and recreating an account preserve its permissions?
No. The recreated account receives a new SID. Old ACL entries reference the deleted account’s SID unless a supported migration uses SIDHistory.
Is a SID the same as a username?
No. A username is a display and logon name; the SID is the identity value Windows uses for authorization.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Can I change a SID manually?
Do not manually edit SIDs. Use supported Windows or Active Directory account, migration, and ACL tools.
The Bottom Line
Bottom line: Names are for people; SIDs are what Windows uses to enforce identity-based access. When a name changes, the SID usually does not. When an account is recreated, the SID changes—and permissions tied to the old identity do not automatically follow.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

