AD Grupları ve Yetkileri

Active Directory groups and permissons,

Active Directory’de bulunan grupların yetkileri ve genel özellikleri ile ilgili bilgiler aşağıdaki tabloda bulunmaktadır.

Account or GroupDefault Container, Group Scope and TypeDescription and Default User Rights
Access Control Assistance Operators (Active Directory in Windows Server 2012)Built-in containerMembers of this group can remotely query authorization attributes and permissions for resources on this computer.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Account OperatorsBuilt-in containerMembers can administer domain user and group accounts.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Administrator accountUsers containerBuilt-in account for administering the domain.
  
Not a groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Adjust memory quotas for a process
  
 Allow log on locally
  
 Allow log on through Remote Desktop Services
  
 Back up files and directories
  
 Bypass traverse checking
  
 Change the system time
  
 Change the time zone
  
 Create a pagefile
  
 Create global objects
  
 Create symbolic links
  
 Debug programs
  
 Enable computer and user accounts to be trusted for delegation
  
 Force shutdown from a remote system
  
 Impersonate a client after authentication
  
 Increase a process working set
  
 Increase scheduling priority
  
 Load and unload device drivers
  
 Log on as a batch job
  
 Manage auditing and security log
  
 Modify firmware environment values
  
 Perform volume maintenance tasks
  
 Profile single process
  
 Profile system performance
  
 Remove computer from docking station
  
 Restore files and directories
  
 Shut down the system
  
 Take ownership of files or other objects
Administrators groupBuilt-in containerAdministrators have complete and unrestricted access to the domain.
  
Domain-local security groupDirect user rights:
  
 Access this computer from the network
  
 Adjust memory quotas for a process
  
 Allow log on locally
  
 Allow log on through Remote Desktop Services
  
 Back up files and directories
  
 Bypass traverse checking
  
 Change the system time
  
 Change the time zone
  
 Create a pagefile
  
 Create global objects
  
 Create symbolic links
  
 Debug programs
  
 Enable computer and user accounts to be trusted for delegation
  
 Force shutdown from a remote system
  
 Impersonate a client after authentication
  
 Increase scheduling priority
  
 Load and unload device drivers
  
 Log on as a batch job
  
 Manage auditing and security log
  
 Modify firmware environment values
  
 Perform volume maintenance tasks
  
 Profile single process
  
 Profile system performance
  
 Remove computer from docking station
  
 Restore files and directories
  
 Shut down the system
  
 Take ownership of files or other objects
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Allowed RODC Password Replication GroupUsers containerMembers in this group can have their passwords replicated to all read-only domain controllers in the domain.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Backup OperatorsBuilt-in containerBackup Operators can override security restrictions for the sole purpose of backing up or restoring files.
  
Domain-local security groupDirect user rights:
  
 Allow log on locally
  
 Back up files and directories
  
 Log on as a batch job
  
 Restore files and directories
  
 Shut down the system
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Cert PublishersUsers containerMembers of this group are permitted to publish certificates to the directory.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Certificate Service DCOM AccessBuilt-in containerIf Certificate Services is installed on a domain controller (not recommended), this group grants DCOM enrollment access to Domain Users and Domain Computers.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Cloneable Domain Controllers (AD DS in Windows Server 2012AD DS)Users containerMembers of this group that are domain controllers may be cloned.
  
Global security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Cryptographic OperatorsBuilt-in containerMembers are authorized to perform cryptographic operations.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Debugger UsersThis is neither a default nor a built-in group, but when present in AD DS, is cause for further investigation.The presence of a Debugger Users group indicates that debugging tools have been installed on the system at some point, whether via Visual Studio, SQL, Office, or other applications that require and support a debugging environment. This group allows remote debugging access to computers. When this group exists at the domain level, it indicates that a debugger or an application that contains a debugger has been installed on a domain controller.
Denied RODC Password Replication GroupUsers containerMembers in this group cannot have their passwords replicated to any read-only domain controllers in the domain.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
DHCP AdministratorsUsers containerMembers of this group have administrative access to the DHCP Server service.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
DHCP UsersUsers containerMembers of this group have view-only access to the DHCP Server service.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Distributed COM UsersBuilt-in containerMembers of this group are allowed to launch, activate, and use distributed COM objects on this computer.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
DnsAdminsUsers containerMembers of this group have administrative access to the DNS Server service.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
DnsUpdateProxyUsers containerMembers of this group are DNS clients who are permitted to perform dynamic updates on behalf of clients that cannot themselves perform dynamic updates. Members of this group are typically DHCP servers.
  
Global security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Domain AdminsUsers containerDesignated administrators of the domain; Domain Admins is a member of every domain-joined computer’s local Administrators group and receives rights and permissions granted to the local Administrators group, in addition to the domain’s Administrators group.
  
Global security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Adjust memory quotas for a process
  
 Allow log on locally
  
 Allow log on through Remote Desktop Services
  
 Back up files and directories
  
 Bypass traverse checking
  
 Change the system time
  
 Change the time zone
  
 Create a pagefile
  
 Create global objects
  
 Create symbolic links
  
 Debug programs
  
 Enable computer and user accounts to be trusted for delegation
  
 Force shutdown from a remote system
  
 Impersonate a client after authentication
  
 Increase a process working set
  
 Increase scheduling priority
  
 Load and unload device drivers
  
 Log on as a batch job
  
 Manage auditing and security log
  
 Modify firmware environment values
  
 Perform volume maintenance tasks
  
 Profile single process
  
 Profile system performance
  
 Remove computer from docking station
  
 Restore files and directories
  
 Shut down the system
  
 Take ownership of files or other objects
Domain ComputersUsers containerAll workstations and servers that are joined to the domain are by default members of this group.
  
Global security groupDefault direct user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Domain ControllersUsers containerAll domain controllers in the domain. Note: Domain controllers are not a member of the Domain Computers group.
  
Global security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Domain GuestsUsers containerAll guests in the domain
  
Global security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Domain UsersUsers containerAll users in the domain
  
Global security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Enterprise Admins (exists only in forest root domain)Users containerEnterprise Admins have permissions to change forest-wide configuration settings; Enterprise Admins is a member of every domain’s Administrators group and receives rights and permissions granted to that group.
  
Universal security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Adjust memory quotas for a process
  
 Allow log on locally
  
 Allow log on through Remote Desktop Services
  
 Back up files and directories
  
 Bypass traverse checking
  
 Change the system time
  
 Change the time zone
  
 Create a pagefile
  
 Create global objects
  
 Create symbolic links
  
 Debug programs
  
 Enable computer and user accounts to be trusted for delegation
  
 Force shutdown from a remote system
  
 Impersonate a client after authentication
  
 Increase a process working set
  
 Increase scheduling priority
  
 Load and unload device drivers
  
 Log on as a batch job
  
 Manage auditing and security log
  
 Modify firmware environment values
  
 Perform volume maintenance tasks
  
 Profile single process
  
 Profile system performance
  
 Remove computer from docking station
  
 Restore files and directories
  
 Shut down the system
  
 Take ownership of files or other objects
Enterprise Read-only Domain ControllersUsers containerThis group contains the accounts for all read-only domain controllers in the forest.
  
Universal security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Event Log ReadersBuilt-in containerMembers of this group in can read the event logs on domain controllers.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Group Policy Creator OwnersUsers containerMembers of this group can create and modify Group Policy Objects in the domain.
  
Global security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
GuestUsers containerThis is the only account in an AD DS domain that does not have the Authenticated Users SID added to its access token. Therefore, any resources that are configured to grant access to the Authenticated Users group will not be accessible to this account. This behavior is not true of members of the Domain Guests and Guests groups, however- members of those groups do have the Authenticated Users SID added to their access tokens.
  
Not a groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Bypass traverse checking
  
 Increase a process working set
GuestsBuilt-in containerGuests have the same access as members of the Users group by default, except for the Guest account, which is further restricted as described earlier.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Hyper-V Administrators (Windows Server 2012)Built-in containerMembers of this group have complete and unrestricted access to all features of Hyper-V.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
IIS_IUSRSBuilt-in containerBuilt-in group used by Internet Information Services.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Incoming Forest Trust Builders (exists only in forest root domain)Built-in containerMembers of this group can create incoming, one-way trusts to this forest. (Creation of outbound forest trusts is reserved for Enterprise Admins.)
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
KrbtgtUsers containerThe Krbtgt account is the service account for the Kerberos Key Distribution Center in the domain. This account has access to all accounts’ credentials stored in Active Directory. This account is disabled by default and should never be enabled
  
Not a groupUser rights: N/A
Network Configuration OperatorsBuilt-in containerMembers of this group are granted privileges that allow them to manage configuration of networking features.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Performance Log UsersBuilt-in containerMembers of this group can schedule logging of performance counters, enable trace providers, and collect event traces locally and via remote access to the computer.
  
Domain-local security groupDirect user rights:
  
 Log on as a batch job
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Performance Monitor UsersBuilt-in containerMembers of this group can access performance counter data locally and remotely.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Pre-Windows 2000 Compatible AccessBuilt-in containerThis group exists for backward compatibility with operating systems prior to Windows 2000 Server, and it provides the ability for members to read user and group information in the domain.
  
Domain-local security groupDirect user rights:
  
 Access this computer from the network
  
 Bypass traverse checking
  
 Inherited user rights:
  
 Add workstations to domain
  
 Increase a process working set
Print OperatorsBuilt-in containerMembers of this group can administer domain printers.
  
Domain-local security groupDirect user rights:
  
 Allow log on locally
  
 Load and unload device drivers
  
 Shut down the system
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
RAS and IAS ServersUsers containerServers in this group can read remote access properties on user accounts in the domain.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
RDS Endpoint Servers (Windows Server 2012)Built-in containerServers in this group run virtual machines and host sessions where users RemoteApp programs and personal virtual desktops run. This group needs to be populated on servers running RD Connection Broker. RD Session Host servers and RD Virtualization Host servers used in the deployment need to be in this group.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
RDS Management Servers (Windows Server 2012)Built-in containerServers in this group can perform routine administrative actions on servers running Remote Desktop Services. This group needs to be populated on all servers in a Remote Desktop Services deployment. The servers running the RDS Central Management service must be included in this group.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
RDS Remote Access Servers (Windows Server 2012)Built-in containerServers in this group enable users of RemoteApp programs and personal virtual desktops access to these resources. In Internet-facing deployments, these servers are typically deployed in an edge network. This group needs to be populated on servers running RD Connection Broker. RD Gateway servers and RD Web Access servers used in the deployment need to be in this group.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Read-only Domain ControllersUsers containerThis group contains all read-only domain controllers in the domain.
  
Global security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Remote Desktop UsersBuilt-in containerMembers of this group are granted the right to log on remotely using RDP.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Remote Management Users (Windows Server 2012)Built-in containerMembers of this group can access WMI resources over management protocols (such as WS-Management via the Windows Remote Management service). This applies only to WMI namespaces that grant access to the user.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
ReplicatorBuilt-in containerSupports legacy file replication in a domain.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Schema Admins (exists only in forest root domain)Users containerSchema admins are the only users who can make modifications to the Active Directory schema, and only if the schema is write-enabled.
  
Universal security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Server OperatorsBuilt-in containerMembers of this group can administer domain servers.
  
Domain-local security groupDirect user rights:
  
 Allow log on locally
  
 Back up files and directories
  
 Change the system time
  
 Change the time zone
  
 Force shutdown from a remote system
  
 Restore files and directories
  
 Shut down the system
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
Terminal Server License ServersBuilt-in containerMembers of this group can update user accounts in Active Directory with information about license issuance, for the purpose of tracking and reporting TS Per User CAL usage
  
Domain-local security groupDefault direct user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
UsersBuilt-in containerUsers have permissions that allow them to read many objects and attributes in Active Directory, although they cannot change most. Users are prevented from making accidental or intentional system-wide changes and can run most applications.
  
Domain-local security groupDirect user rights:
  
 Increase a process working set
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
Windows Authorization Access GroupBuilt-in containerMembers of this group have access to the computed tokenGroupsGlobalAndUniversal attribute on User objects
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set
WinRMRemoteWMIUsers_ (Windows Server 2012)Users containerMembers of this group can access WMI resources over management protocols (such as WS-Management via the Windows Remote Management service). This applies only to WMI namespaces that grant access to the user.
  
Domain-local security groupDirect user rights: None
  
 Inherited user rights:
  
 Access this computer from the network
  
 Add workstations to domain
  
 Bypass traverse checking
  
 Increase a process working set

Kaynak: https://docs.microsoft.com/en-us/windows-server/identity/ad-ds/plan/security-best-practices/appendix-b–privileged-accounts-and-groups-in-active-directory