你不能那样做。在您的特定机器上生成的任何 SID 都会颁发给该机器的本地安全机构。(好的,或者如果您在谈论域控制器,则为域安全机构)这意味着,它将始终具有
S-1-5-21<the machine LSA SID>-<random local identifier of the user/group>
.
This is because the structure of a SID is hierarchical. For instance, all SIDs under NT AUTHORITY
have the prefix S-1-5
, because that is NT AUTHORITY's SID. (e.g. NT AUTHORITY\SYSTEM
is S-1-5-18
) Your machine's LSA isn't allowed to issue a SID that doesn't belong under its authority, which is going to be the S-1-5-21<random number generated when Windows is installed>
SID.