The account database in Windows. Older Windows clients log on with the SAM account name, and Defender for Identity once queried local admins over the SAM-R protocol to map lateral movement paths, stopping that in mid-May 2025.
Also called Security Account Manager.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SAM in context, with comparison tables and the common traps.
Terms in this definition
- Schema
The middle part of a Unity Catalog name (
catalog.schema.table), grouping tables, views, volumes, functions and models inside a catalog. A grant on it covers everything in it now and later, and nothing inside can be reached withoutUSE SCHEMA. - Defender for Identity
Microsoft Defender service that detects attacks on identities, using sensors on on-premises Active Directory servers plus signals from Microsoft Entra ID and other identity providers; it does no access reviews or identity governance.
- LSDOU
The sequence in which Group Policy is processed: the local policy first, followed by site, domain and organisational unit policies. The nearest, last-processed setting takes effect unless Enforced or Block Inheritance alters that.
- OVER
Gives a T-SQL window function its window: PARTITION BY, ORDER BY and, if wanted, a ROWS or RANGE frame. Rankings and running totals can then be worked out while every row is kept.
- Lateral movement paths
Microsoft Defender for Identity maps these for you: chains of shared logins and permissions that would let an intruder holding an ordinary account work their way up to privileged ones.
Related terms
- Delegated Login Identity
When single sign-on uses Kerberos Constrained Delegation through application proxy and a user's cloud name doesn't match their on-premises name, this option picks the identity the connector requests a Kerberos ticket for. Choices include the UPN and the on-premises SAM account name.