Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more

The Security Accounts Manager (SAM) is the Windows database that stores local user accounts and groups. Microsoft’s own definition reads: “The Security Accounts Manager (SAM) is a database that stores local user accounts and groups” (Microsoft Learn, Credentials Processes in Windows Authentication). Each Windows computer has its own SAM, so the accounts it holds apply to that computer. Domain accounts are managed differently, in Active Directory.

What SAM holds

SAM tracks two kinds of security principals: user accounts and groups. Microsoft’s auditing documentation names the SAM object types that appear in the database, including SAM_USER for user accounts, SAM_GROUP for groups, and SAM_ALIAS for local groups. The database supports creating, reading, updating, and deleting this security-principal information.

Why local accounts stay on one computer

Microsoft’s protocol overview explains that each Windows computer has its own local account database. Identities from that database generally remain local because computers do not trust one another’s account information by default. A local account created on one workstation therefore cannot be used to sign in to another workstation through that account store.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

SAM versus Active Directory

The difference comes down to where an account is managed and how far it reaches. The table below compares the two account stores using Microsoft’s account-scope and authentication descriptions.

Property Local SAM account Domain account
Where it is managed In the SAM database on the individual computer In Active Directory, on domain controllers
Scope The computer where it was created The domain
Credential check in the standard path Validated against the local SAM Validated against Active Directory through the Windows logon path
Trust between computers Not trusted by default, so the identity generally stays local Recognised across the domain through Active Directory

Joining a computer to a domain does not, according to these sources, remove every local account. Microsoft’s material describes the two account stores and their scope. It does not describe what happens to existing local accounts when a computer joins a domain, so do not assume that outcome.

Where SAM is stored in the registry

SAM is represented in the registry as the hive HKEY_LOCAL_MACHINESAM. The hive’s supporting files are named Sam, Sam.log, and Sam.sav. Microsoft’s authentication overview states that a copy of the SAM database is stored in the registry and is system-accessible and write-protected.

Because the hive is write-protected, account changes should be made through Windows account management tools rather than by editing these registry keys directly.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

How SAM fits into sign-in and password storage

Local account password hashes

On workstations and domain members, the password hashes for local user accounts are stored in the local SAM database. The database does not hold users’ passwords in plain text.

Domain cached credentials

Domain users rely on a separate mechanism. Cached credentials let a domain user sign in when a domain controller cannot be reached. These are not local accounts in SAM, and they are not the same thing as the password hashes stored there.

The role of the Local Security Authority

The Local Security Authority (LSA) is the protected subsystem involved in local logon and security policy. For a local account, Windows validates the credentials against the local SAM. A domain-joined computer validates domain credentials against Active Directory through the Windows logon path.

Auditing SAM

Microsoft’s Audit SAM guidance covers auditing attempts to access SAM objects, including users, groups, aliases, domain objects, and server objects. Account changes are also tracked under Account Management auditing. However, a sufficiently privileged user can alter account or password files in a way that bypasses those events, so the audit log is not a complete record of changes.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Two cautions apply. The guidance does not recommend SAM-level auditing in general. It suggests enabling it only when you know exactly what you need to monitor, and it reports high event volume on domain controllers. The page was last updated on 5 September 2021, so check these details against your Windows version and current audit policy before relying on them.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Checking local accounts on a Windows computer

To see the local accounts and groups on a single computer, open Command Prompt and run the following commands. The output reflects only that computer’s SAM, not Active Directory.

  • net user lists the local user accounts.
  • net localgroup lists the local groups.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.