Security Account Manager - Local

Security Account Manager: local accounts

The Security Account Manager (SAM) maintains local users, groups, policy, and
password verifiers. It does not store a user's plaintext password. A workstation
or member server uses its local SAM when validating a local account; domain
account validation normally goes to a domain controller.

Storage and protection

The live registry hive is backed by:

%SystemRoot%\System32\config\SAM

The SAM hive is locked while Windows is running and protected so ordinary users
cannot read it. Material in the SYSTEM hive participates in protecting SAM
secrets, which is why defensive incident response treats unauthorized access to
either hive as sensitive.

%SystemRoot%\System32\config\RegBack\SAM should not be treated as a reliable
backup. Automatic registry backups to RegBack stopped by default beginning
with Windows 10 version 1803, and the files can be zero bytes.

Defensive validation

Operational credential extraction belongs in the authorized RTO playbooks. The
platform-internals concern is where local validation data lives, which security
boundary protects it, and what evidence access generates.

References