Home › Active Directory users and groups › Step 8
Special identities in Windows and AD DS
Step 8 of 9 in Active Directory users and groups · video 3:02
What you will learn
- How special identities differ from ordinary security groups
- Everyone, Authenticated Users and Anonymous Logon compared
- Granting access by connection type with Interactive and Network
- Using Creator Owner for home directory permissions
About this lesson
Special identities look like groups, but Windows decides who belongs to them from the way a user connects, not from a membership list. They do not appear in Active Directory Users and Computers, and their membership cannot be viewed, edited or nested into other groups, yet they can be used when granting rights and permissions. The lesson describes the important ones: Anonymous Logon, which has not been part of Everyone since Windows Server 2003; Authenticated Users, which leaves out the Guest account; Everyone, which covers authenticated users plus Guest; Interactive, for people signed in on the computer itself, including through Remote Desktop; Network, for access across the network; and Creator Owner, which stands for whoever created an object. Two practical cases show why this matters: a folder readable only when signed in locally, built with the Interactive identity, and home folders where Creator Owner gives each user full control of the subfolder they created.
Check yourself
1. What is the difference between Everyone and Authenticated Users?
Everyone includes authenticated users and also the Guest account. Authenticated Users leaves out Guest, even if the Guest account has a password, so it is the safer choice when you mean real signed-in accounts.
2. Can you add a user to the Interactive identity, or nest Network inside another group?
No. The operating system controls the membership of special identities, so they cannot be edited or added to other groups. You can only use them in rights and permission entries.
3. Users should be able to open a folder when signed in at the server itself but not through a mapped drive. Which special identity helps?
Interactive. Grant the permission to Interactive rather than to the users' accounts: people signed in locally (or through Remote Desktop) match it, while the same people connecting over the network match Network instead and get no access.
4. Why is Creator Owner used on the root folder that holds users' home directories?
Permissions granted to Creator Owner on the root are applied to whoever creates a subfolder. Each user who creates their home directory therefore gets full control of it without the administrator setting permissions folder by folder.
Go deeper
This lesson comes from the course below - with the full set of lessons, demonstrations and practice.