Outdated Drivers Are Slowing You Down
One free scan finds every outdated or missing driver and matches the right update for your exact hardware.Free scan · exact hardware matchPC Slower Than It Used to Be?
A free scan shows the junk files, broken settings and background clutter dragging Windows down - then fixes them in one click.Free scan · Windows 10 & 11iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
The Security Accounts Manager (SAM) is the Windows database that stores local user accounts and groups. Microsoft’s own definition reads: “The Security Accounts Manager (SAM) is a database that stores local user accounts and groups” (Microsoft Learn, Credentials Processes in Windows Authentication). Each Windows computer has its own SAM, so the accounts it holds apply to that computer. Domain accounts are managed differently, in Active Directory.
What SAM holds
SAM tracks two kinds of security principals: user accounts and groups. Microsoft’s auditing documentation names the SAM object types that appear in the database, including SAM_USER for user accounts, SAM_GROUP for groups, and SAM_ALIAS for local groups. The database supports creating, reading, updating, and deleting this security-principal information.
Why local accounts stay on one computer
Microsoft’s protocol overview explains that each Windows computer has its own local account database. Identities from that database generally remain local because computers do not trust one another’s account information by default. A local account created on one workstation therefore cannot be used to sign in to another workstation through that account store.
Quick wins for a faster PC:
Scan for outdated or missing drivers - takes under a minuteDriver Scan →Clear out junk files and repair common Windows errorsFree Scan →Fix the driver behind crashes, sound loss and screen glitchesFind Drivers →SAM versus Active Directory
The difference comes down to where an account is managed and how far it reaches. The table below compares the two account stores using Microsoft’s account-scope and authentication descriptions.
#1 Best Overall
| Property | Local SAM account | Domain account |
|---|---|---|
| Where it is managed | In the SAM database on the individual computer | In Active Directory, on domain controllers |
| Scope | The computer where it was created | The domain |
| Credential check in the standard path | Validated against the local SAM | Validated against Active Directory through the Windows logon path |
| Trust between computers | Not trusted by default, so the identity generally stays local | Recognised across the domain through Active Directory |
Joining a computer to a domain does not, according to these sources, remove every local account. Microsoft’s material describes the two account stores and their scope. It does not describe what happens to existing local accounts when a computer joins a domain, so do not assume that outcome.
Where SAM is stored in the registry
SAM is represented in the registry as the hive HKEY_LOCAL_MACHINESAM. The hive’s supporting files are named Sam, Sam.log, and Sam.sav. Microsoft’s authentication overview states that a copy of the SAM database is stored in the registry and is system-accessible and write-protected.
Rank #2
Because the hive is write-protected, account changes should be made through Windows account management tools rather than by editing these registry keys directly.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Clear out junk files and repair common Windows errors3Scan for outdated or missing drivers - takes under a minuteHow SAM fits into sign-in and password storage
Local account password hashes
On workstations and domain members, the password hashes for local user accounts are stored in the local SAM database. The database does not hold users’ passwords in plain text.
Rank #3
Domain cached credentials
Domain users rely on a separate mechanism. Cached credentials let a domain user sign in when a domain controller cannot be reached. These are not local accounts in SAM, and they are not the same thing as the password hashes stored there.
The role of the Local Security Authority
The Local Security Authority (LSA) is the protected subsystem involved in local logon and security policy. For a local account, Windows validates the credentials against the local SAM. A domain-joined computer validates domain credentials against Active Directory through the Windows logon path.
Auditing SAM
Microsoft’s Audit SAM guidance covers auditing attempts to access SAM objects, including users, groups, aliases, domain objects, and server objects. Account changes are also tracked under Account Management auditing. However, a sufficiently privileged user can alter account or password files in a way that bypasses those events, so the audit log is not a complete record of changes.
Two cautions apply. The guidance does not recommend SAM-level auditing in general. It suggests enabling it only when you know exactly what you need to monitor, and it reports high event volume on domain controllers. The page was last updated on 5 September 2021, so check these details against your Windows version and current audit policy before relying on them.
Best Value
Checking local accounts on a Windows computer
To see the local accounts and groups on a single computer, open Command Prompt and run the following commands. The output reflects only that computer’s SAM, not Active Directory.
Quick Recap
net userlists the local user accounts.net localgrouplists the local groups.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

