Directory Services

Security Principals

In Windows® 2000, a security principal is a user, group, or computer — an entity that the security system recognizes. This includes human users as well as autonomous processes. Strictly speaking, the security system cannot tell the difference between users who are logged in and processes running on the computer. It sees both as security principals with security principal names.

Users, groups, and computers are created and stored as objects in Active Directory®. There are also well-known security principals that represent special identities defined by the Windows 2000 security system, such as Everyone, Local System, Principal Self, Authenticated User, Creator Owner, and so on. Objects representing the well-known security principals, such as Anonymous Logon, are stored in the WellKnown Security Principals container beneath the Configuration container.