Account Operators | Members can add, change, or delete user and
group accounts. |
Administrators | Members can perform all administrative tasks on
the computer. The built-in Administrator account that is created
when the operating system is installed is a member of the
group. When a member server or a client running Windows
Vista, Windows XP Professional, or Windows 2000 Professional
joins a domain, the Domain Admins group is made part of this
group. |
Allowed RODC Password Replication
Group | Members can have their passwords replicated to
all Read-Only Domain Controllers (RODC). |
Backup Operators | Members can log on to the computer, back up and
restore the computer’s data, and shut down the computer.
Members cannot change security settings but can override
them for purposes of backup and restore. |
Cert Publishers | Members are allowed to publish certificates to
the directory. |
Certificate Service DCOM Access | Members can connect to Certificate
Authorities. |
Cryptographic Operators | Members can perform cryptographic
procedures. |
Denied RODC Password Replication
Group | Members of this group cannot have their
passwords replicated to an RODC. Default members are Cert
Publishers, Domain Admins, Domain Controllers, Enterprise
Admins, Group Policy Creator Owners, Read-Only Domain
Controllers, and Schema Admins. |
Distributed COM Users | Members can activate, launch, and use
Distributed COM objects on this computer. |
DnsAdmins | Members are DNS administrators. No default
members. |
Event Log Readers | Members can read event logs from local
computers. |
Guests | Members have the same access as members of the
Users group. The Guest account has fewer rights and is a
default member of this group. |
IIS_IUSRS | Used by Internet Information Services
(IIS). |
Incoming Forest Trust Builders | Members can create incoming one-way trusts.
This group is an anomaly in SBS because SBS doesn’t support
trusts. |
Network Configuration Operators | Users can have access to managing some network
configurations. |
Performance Log Users | Members can schedule some performance
counters. |
Performance Monitor Users | Provides backward compatibility to allow
members access to performance counters locally and
remotely. |
Pre–Windows 2000 Compatible Access | A backward-compatibility group to allow read
access on all users and groups in the domain. |
Print Operators | Members can manage printers and print queues on
domain printers. |
RAS And IAS Servers | Servers in this group can access remote access
properties of users. |
Remote Desktop Users | Members are allowed to connect remotely. This
group does not control who has access
via Remote Web Workplace. |
Replicator | Supports file replication in a domain. Do not
add user accounts of actual users to this group. If
necessary, you can add a “dummy” user account to this group
to permit you to log on to Replicator services on a domain
controller and manage replication of files and
directories. |
Server Operators | Members can administer servers. |
Terminal Server License Servers | Members can update user accounts in Active
Directory to track and report Terminal Server per user
Client Access Licenses usage. |
Users | Members can log on to the computer, access the
network, save documents, and shut down the computer. Members
cannot install programs or make system changes.
Authenticated Users and Domain Users are members by
default. |
Windows Authorization Access
Group | Members have access to the computed
tokenGroupsGlobal AndUniversal
attribute on User
objects. |