/
/
News
Important news about past or upcoming events
table of Contents
Need licensing information or access to our products?

Active Directory Privileged Accounts

High Privileged Default Security Principals

NameComments
Account Operators
AdministratorRelative Identifier -500
AdministratorDSRM Mode. S-500
Administrators
Backup Operators
Domain Admins
Domain Controllers
Enterprise Admins
Enterprise Key Admins
Key Admins
krbtgtUser Class
Print Operators
Read-Only Domain Controllers
Replicator
Schema Admins
Server Operators

Other Security Principals with High Privileges

Service Accounts may be granted High Privileges on Domain Root Object, Group Policy Objects and other critical objects such as adminSDHolder must be flagged as Security Principals with High Privileges and monitored.

PermissionsComments
Replicate Directory Changes All
Reset PasswordApplied to or Inherited by High Privileged Security Principals (User)
Write MemberApplied to or Inherited by High Privileged Security Principals (Group)
Create Computer
Create User
Write Permissions
Write Owner
October 20, 2025

Have a question?
Send us a message

By submitting, I agree to the use of my personal data in accordance with the OPTAGUARD Privacy Policy.