与新本地用户关联的默认组(Windows 10.0.17763)

与新本地用户关联的默认组(Windows 10.0.17763)

我正在使用独立的 Windows 10.0.17763(无 AD)

C:\Windows\system32>systeminfo | findstr /B /C:"OS Name" /C:"OS Version"
OS Name:                   Microsoft Windows 10 Enterprise N
OS Version:                10.0.17763 N/A Build 17763

我想知道哪个(以及在哪里)策略将默认组分配给新创建的“本地用户”。

我正在使用如下的“net add”命令。

c:\Windows\System32>net user theuser P@ssw0rd /add
The command completed successfully.

这些是分配给用户的默认组。

C:\Windows\system32>whoami /all

USER INFORMATION
----------------

User Name             SID
===================== =============================================
win10n-devenv\theuser S-1-5-21-3355217364-1844382339-729736612-1002


GROUP INFORMATION
-----------------

Group Name                             Type             SID          Attributes
====================================== ================ ============ ==================================================
Everyone                               Well-known group S-1-1-0      Mandatory group, Enabled by default, Enabled group
BUILTIN\Users                          Alias            S-1-5-32-545 Mandatory group, Enabled by default, Enabled group
BUILTIN\Performance Log Users          Alias            S-1-5-32-559 Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\INTERACTIVE               Well-known group S-1-5-4      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Authenticated Users       Well-known group S-1-5-11     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\This Organization         Well-known group S-1-5-15     Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\Local account             Well-known group S-1-5-113    Mandatory group, Enabled by default, Enabled group
LOCAL                                  Well-known group S-1-2-0      Mandatory group, Enabled by default, Enabled group
NT AUTHORITY\NTLM Authentication       Well-known group S-1-5-64-10  Mandatory group, Enabled by default, Enabled group
Mandatory Label\Medium Mandatory Level Label            S-1-16-8192

奇怪!例如,“BUILTIN\Performance Log Users”来自哪里?来自哪个配置策略?

相关内容