Security Account Manager - Local
Security Account Manager: local accounts
The Security Account Manager (SAM) maintains local users, groups, policy, and
password verifiers. It does not store a user's plaintext password. A workstation
or member server uses its local SAM when validating a local account; domain
account validation normally goes to a domain controller.
Storage and protection
The live registry hive is backed by:
%SystemRoot%\System32\config\SAM
The SAM hive is locked while Windows is running and protected so ordinary users
cannot read it. Material in the SYSTEM hive participates in protecting SAM
secrets, which is why defensive incident response treats unauthorized access to
either hive as sensitive.
%SystemRoot%\System32\config\RegBack\SAM should not be treated as a reliable
backup. Automatic registry backups to RegBack stopped by default beginning
with Windows 10 version 1803, and the files can be zero bytes.
Defensive validation
- Monitor access and backup operations involving the SAM and SYSTEM hives.
- Review unexpected use of registry-save utilities and remote administration
tools under elevated accounts. - Protect local administrator credentials with Windows LAPS and restrict who
can retrieve or decrypt the managed password. - Use an approved forensic acquisition process when hive collection is required.
Operational credential extraction belongs in the authorized RTO playbooks. The
platform-internals concern is where local validation data lives, which security
boundary protects it, and what evidence access generates.