Every Windows or Active Directory user, group and computer gets one, unique and never handed out again. Windows puts it in a person's access token when they log on.
Also called security identifier.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains SID in context, with comparison tables and the common traps.
Terms in this definition
- AD
Short for Active Directory, the directory service built into Windows Server (AD DS). Entra Connect synchronises on-premises forests to Microsoft Entra ID.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Access token
A credential an application hands to an API or other resource to prove what it has been authorised to do for a signed-in user. It deals with permissions, unlike the ID token, which records the sign-in itself.
Related terms
- RID
The relative identifier: the final, unique portion of a SID. Each domain controller issues RIDs from a block allocated to it by the RID master.
- SID filtering
A trust feature that removes SIDs belonging to other domains, SID history included, from authentication traffic crossing the trust, stopping a trusted domain from claiming group memberships it has no right to.
- TGT
Kerberos clients present one of these when asking for service tickets. Microsoft Entra Kerberos can issue a Cloud version for cloud resources, and also a partial version, containing nothing but the user's SID, which on-premises DCs exchange for a complete ticket.
- Trusted domain object
Holds a trust's settings in the directory; with a forest trust it lists the other forest's SID namespaces and name suffixes.