https://docs.microsoft.com/ko-kr/windows/security/identity-protection/access-control/security-identifiers
https://docs.microsoft.com/ko-kr/windows/security/threat-protection/security-policy-settings/user-rights-assignment
https://stackoverflow.com/questions/53755993/wmic-useraccount-list-full-and-nothing-happen
https://www.snoopybox.co.kr/1722
https://cafe.daum.net/candan/BLQD/57 이전글
wmic.exe useraccount where "localaccount=true" get name,sid,disabled
Disabled Name SID
TRUE Administrator S-1-5-21-27797481-235746463-772742770-500
FALSE Me-Admin S-1-5-21-27797481-235746463-772742770-1001
FALSE Me-NonAdmin S-1-5-21-27797481-235746463-772742770-1002
TRUE DefaultAccount S-1-5-21-27797481-235746463-772742770-503
TRUE Guest S-1-5-21-27797481-235746463-772742770-501
FALSE ToolBox S-1-5-21-27797481-235746463-772742770-1007
TRUE WDAGUtilityAccount S-1-5-21-27797481-235746463-772742770-504
TRUE 의 의미는 차단 되어 있다.
FALSE 활성화 되어 있다는 뜻이다.
모두 비활성화 되고 사용자만 활성화 되면 정상이다
끝 부분 1001이 사용자 계정이다.
그러무로
신뢰 할수 있는 보안 식별자는 사용자나 구릅에게 주면 해킹 당할수 있으니 최고 관리자에게만..
https://docs.microsoft.com/ko-kr/windows/security/threat-protection/security-policy-settings/access-credential-manager-as-a-trusted-caller
https://www.stigviewer.com/stig/microsoft_windows_server_2019/2021-03-05/finding/V-205749
SeTrustedCredManAccessPrivilege = *S-1-5-21-27797481-235746463-772742770-500
이렇게 될것 같다.