0% found this document useful (0 votes)
24 views6 pages

Object Picker UI in Windows 8.1 Guide

The document provides an overview of the Object Picker UI in Windows 8.1 and Windows Server 2012 R2, detailing various object types that can be selected for configuring access to computer objects. It explains how to use the Object Picker control to search for objects on the network or local computer, including built-in security principals, users, groups, and Active Directory objects. Additionally, it describes the attributes of these objects and their roles in network resource access and management.

Uploaded by

Shivam Sah
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
24 views6 pages

Object Picker UI in Windows 8.1 Guide

The document provides an overview of the Object Picker UI in Windows 8.1 and Windows Server 2012 R2, detailing various object types that can be selected for configuring access to computer objects. It explains how to use the Object Picker control to search for objects on the network or local computer, including built-in security principals, users, groups, and Active Directory objects. Additionally, it describes the attributes of these objects and their roles in network resource access and management.

Uploaded by

Shivam Sah
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PDF, TXT or read online on Scribd

12/5/25, 4:23 PM Object picker UI | Microsoft Learn

Object picker UI
Updated: July 3, 2014

Applies To: Windows 8.1, Windows RT 8.1, Windows Server 2012 R2

If you are trying to solve an issue with your personal computer, you should check the help page
at How can we help you?

This topic contains examples of object types that you can select when configuring access to
various types of computer objects (for example, ownership and permissions).

Use the Object Picker control to type the object names that you want to find on the network or
the local computer. You can search for multiple objects by separating each name with a
semicolon. For information about Active Directory objects that you can specify in this dialog
box when your computer is part of a domain, see Active Directory Domain Services objects
later in this topic.

ノ Expand table

Object Type Details Examples

Built-in Represents default built-in groups and security principals. Users:


security
principal To view built-in principals, type Users on the Start screen, click Administrator
Edit local users and groups, and then double-click Groups or
Users. Guest

Groups:

Administrators

Guests

Users

Power Users

Everyone

Authenticated
Users

Computer Represents a computer's access to network resources. CarrollB-


HomeComputer

[Link] 1/6
12/5/25, 4:23 PM Object picker UI | Microsoft Learn

Object Type Details Examples

The computer name was established when the operating


system was installed. The computer name is recorded on the
computer information page in Windows 8.1. To view it, type
System on the Start screen.

Group Can contain users, computers, and other groups as members. Client operating
system groups:
To view these security principals, type Groups on the Start
screen, click Edit local users and groups, and then double- Administrators
click Groups.
Users

Power Users

Guests

Server operating
system groups:

Administrators

System Operators

Users

Power Users

Everyone

Authenticated
Users

Anonymous
Logon

Guests

System

Users Allows people to access network resources. CarrollB

To view users who currently have accounts on this local HomeServer\CarrollB


computer, type Users on the Start screen, click Edit local users
and groups, and then double-click Users.

[Link] 2/6
12/5/25, 4:23 PM Object picker UI | Microsoft Learn

Object Type Details Examples

Contact Locates information about people. Contact objects cannot be Carroll Blythe
assigned permissions, and therefore, they do not have access
to network resources.

Local Contact objects can be found in the following directory


path on your computer: <drive>\Users\<user
name>\Contacts.

Other Can be created by applications. Specific for each


instance

Active Directory Domain Services objects


Real-world objects such as users and computers are represented as objects in Active Directory.
And these objects can be contained in other objects called container objects. Active
Directory Domain Services supports numerous object types, and each is represented by a
unique global identifier.

Each object has a set of attributes that best describe it. For example, consider a user object.
Each user can have attributes such as Name, Address, and Telephone number. The objects that
can be authenticated and to which permissions can be assigned are called security principals.
Each security principal object has a security identifier (SID) associated with it, in addition to the
global identifier (GUID).

ノ Expand table

Object Details Examples


Type

Built-in Represents default built-in groups and security Users:


security principals.
principal Administrator

Cert Publishers

Domain Guests

Guest

Groups:

Administrators

[Link] 3/6
12/5/25, 4:23 PM Object picker UI | Microsoft Learn

Object Details Examples


Type

Server Operators

Print Operators

Users

Hyper-V Administrators

Guests

Computer Represents a work station or a server in a CarrollB


network. A computer account helps in
authenticating and authorizing its access to [Link]
network resources.

[Link] 4/6
12/5/25, 4:23 PM Object picker UI | Microsoft Learn

Object Details Examples


Type

Group Represents a collection of user accounts, Client operating system groups:


computer accounts, contacts, and other groups
that can be managed as a single unit. Groups Administrators
facilitate role-based access to network resources.
There are two types of groups: Users

Security groups are mainly used for the Power Users


purpose of providing access to network
resources. Guests

Distribution groups are not security-


enabled and can be used only for Server operating system groups:
communication purposes. Groups can vary
Administrators
in scope, limiting their membership and
scope of operation.
System Operators

Users

Power Users

Everyone

Authenticated Users

Anonymous Logon

Guests

System

User Represents individuals who need access to the CarrollB


resources in a network. Each user account has a
user name and a password. The purpose behind Contoso\CarrollB
creating user accounts is to authenticate the
identity of the user and authorize the user's
access to network resources. Active Directory
supports two types of built-in user accounts:
Administrator and Guest.

[Link] 5/6
12/5/25, 4:23 PM Object picker UI | Microsoft Learn

Object Details Examples


Type

Contact Contains the contact information about people Carroll Blythe


who are associated with the organization but are
not part of it, for example, contractors or
suppliers. A contact object does not have a SID
associated with it, which prevents it from having
access to network resources.

Shared Used to share files across the network. It is <drive>:\Users\CarrollB\Public


folder mapped to a file share on a server.

In Active Directory, published shared folders are


located in an organizational unit.

Printer Corresponds to a printer resource in a network. Printer object naming is organization-


Printer objects are listed under the Domain specific, for example: 2012-ColorTone
Controllers container in Active Directory Users 200 Driver, which is a driver associated
and Computers. with Type of Printer.

See also
Security Principals Technical Overview

Security Identifiers Technical Overview

Active Directory Accounts

Active Directory Security Groups

Local Accounts

Last updated on 09/15/2014

[Link] 6/6

Common questions

Powered by AI

Security Identifiers (SID) are fundamental in Windows Server environments as they uniquely identify user, group, and computer accounts, ensuring precise and secure management of access to network resources . SIDs are integral to the security architecture, as access control lists (ACLs) rely on these identifiers to permit or deny access to resources, thereby maintaining the integrity of security protocols. Their unique nature prevents conflicts or unauthorized access, which is critical for maintaining secure and orderly access in complex IT infrastructures involving multiple users and systems .

Built-in security principals represent default groups and security entities with predefined roles and access rights within the Windows system, such as Administrator and Guest, which come with specific privileges and restrictions out-of-the-box . Regular user accounts, on the other hand, are created by the user or administrator for individuals needing access to network resources, and their permissions can be customized based on specific security needs . Built-in security principals are often tied to inherent system permissions that ensure key system operations can be conducted, while user account permissions are more flexible and context-driven.

The object picker UI is a tool used to configure access and permissions by allowing administrators to search and assign object names to network or local resources directly . This capability enhances system security by streamlining user and group management, reducing the risk of incorrect permissions due to manual configuration errors. It also improves manageability by providing a centralized interface for complex object types and Active Directory Domain Services integration, ensuring only authenticated and properly hashed identifiers manage access, thus reducing potential security breaches .

Changes in Windows operating system versions often involve updates to user account management structures to enhance security, streamline usability, and incorporate new technologies. For instance, updates in Windows 8.1 included improved access controls and integration with Microsoft accounts, allowing for more seamless access across devices and enhanced security features like password policies and multifactor authentication . This evolution reflects Microsoft's response to evolving cybersecurity threats and user demand for integrated, cloud-based identity management, emphasizing security and efficiency in access management .

Within Windows Active Directory, groups are categorized primarily as Security Groups and Distribution Groups. Security Groups are primarily used to provide access to network resources, enabling role-based access control, while Distribution Groups are used solely for communication purposes and lack security capabilities . Additionally, groups vary in scope: universal, global, and domain local, each defining how memberships are accepted and applied across different domains and forests, influencing access and communication capabilities within the Active Directory infrastructure.

You might also like