Win32 API 日本語リファレンス
ホームSecurity › TOKEN_GROUPS

TOKEN_GROUPS

構造体
サイズx64: 24 バイト / x86: 12 バイト

サイズ=各フィールドのバイト数(x64/x86 で異なる場合は x64/x86 と併記)。x64/x86 列=フィールドのバイトオフセット(HSPで dupptr / lpoke / wpoke 等に使用)。

フィールド

フィールドサイズx64x86説明
GroupCountDWORD4+0+0アクセス トークン内のグループの数を指定します。
GroupsSID_AND_ATTRIBUTES16/8+8+4

一連の SID とそれに対応する属性を格納する SID_AND_ATTRIBUTES 構造体の配列を指定します。

SID_AND_ATTRIBUTES 構造体の Attributes メンバーには、次の値を指定できます。

意味
SE_GROUP_ENABLED
0x00000004L
SID はアクセス チェックで有効になっています。システムがアクセス チェックを実行すると、その SID に適用されるアクセス許可およびアクセス拒否のアクセス制御エントリ (ACE) を検査します。

この属性を持たない SID は、SE_GROUP_USE_FOR_DENY_ONLY 属性が設定されていない限り、アクセス チェック時に無視されます。

SE_GROUP_ENABLED_BY_DEFAULT
0x00000002L
SID は既定で有効になっています。
SE_GROUP_INTEGRITY
0x00000020L
SID は必須整合性 SID です。
SE_GROUP_INTEGRITY_ENABLED
0x00000040L
SID は必須整合性チェックで有効になっています。
SE_GROUP_LOGON_ID
0xC0000000L
SID は、アクセス トークンに関連付けられたログオン セッションを識別するログオン SID です。
SE_GROUP_MANDATORY
0x00000001L
この SID の SE_GROUP_ENABLED 属性は、 AdjustTokenGroups 関数の呼び出しによって解除することはできません。ただし、 CreateRestrictedToken 関数を使用すれば、必須 SID を拒否専用 SID に変換できます。
SE_GROUP_OWNER
0x00000008L
SID は、トークンのユーザーがそのグループの所有者となっているグループ アカウントを識別します。または、この SID をトークンやオブジェクトの所有者として割り当てることができます。
SE_GROUP_RESOURCE
0x20000000L
SID はドメイン ローカル グループを識別します。
SE_GROUP_USE_FOR_DENY_ONLY
0x00000010L
SID は 制限付きトークン内の拒否専用 SID です。システムがアクセス チェックを実行すると、その SID に適用されるアクセス拒否 ACE を検査し、その SID のアクセス許可 ACE は無視します。

この属性が設定されている場合、SE_GROUP_ENABLED は設定されず、SID を再び有効にすることはできません。

公式ドキュメント

TOKEN_GROUPS 構造体は、アクセス トークン内のグループ セキュリティ識別子 (SID) に関する情報を格納します。

出典・ライセンス: 上記「公式ドキュメント」の内容は Microsoft の Win32 API ドキュメント(MicrosoftDocs/sdk-api)を日本語に翻訳・改変したものです。© Microsoft Corporation. CC BY 4.0 で提供。
Microsoft 公式リファレンス: 英語 (en-us) · 日本語 (ja-jp) · 原文ソース (GitHub)

各言語での定義

#include <windows.h>

// SID_AND_ATTRIBUTES  (x64 16 / x86 8 バイト)
typedef struct SID_AND_ATTRIBUTES {
    PSID Sid;
    DWORD Attributes;
} SID_AND_ATTRIBUTES;

// TOKEN_GROUPS  (x64 24 / x86 12 バイト)
typedef struct TOKEN_GROUPS {
    DWORD GroupCount;
    SID_AND_ATTRIBUTES Groups[1];
} TOKEN_GROUPS;
using System;
using System.Runtime.InteropServices;

[StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)]
public struct SID_AND_ATTRIBUTES
{
    public IntPtr Sid;
    public uint Attributes;
}

[StructLayout(LayoutKind.Sequential, CharSet = CharSet.Unicode)]
public struct TOKEN_GROUPS
{
    public uint GroupCount;
    [MarshalAs(UnmanagedType.ByValArray, SizeConst = 1)] public SID_AND_ATTRIBUTES[] Groups;
}
Imports System.Runtime.InteropServices

<StructLayout(LayoutKind.Sequential, CharSet:=CharSet.Unicode)>
Public Structure SID_AND_ATTRIBUTES
    Public Sid As IntPtr
    Public Attributes As UInteger
End Structure

<StructLayout(LayoutKind.Sequential, CharSet:=CharSet.Unicode)>
Public Structure TOKEN_GROUPS
    Public GroupCount As UInteger
    <MarshalAs(UnmanagedType.ByValArray, SizeConst:=1)> Public Groups() As SID_AND_ATTRIBUTES
End Structure
import ctypes
from ctypes import wintypes

class SID_AND_ATTRIBUTES(ctypes.Structure):
    _fields_ = [
        ("Sid", ctypes.c_void_p),
        ("Attributes", wintypes.DWORD),
    ]

class TOKEN_GROUPS(ctypes.Structure):
    _fields_ = [
        ("GroupCount", wintypes.DWORD),
        ("Groups", SID_AND_ATTRIBUTES * 1),
    ]
#[repr(C)]
pub struct SID_AND_ATTRIBUTES {
    pub Sid: *mut core::ffi::c_void,
    pub Attributes: u32,
}

#[repr(C)]
pub struct TOKEN_GROUPS {
    pub GroupCount: u32,
    pub Groups: [SID_AND_ATTRIBUTES; 1],
}
import "golang.org/x/sys/windows"

type SID_AND_ATTRIBUTES struct {
	Sid uintptr
	Attributes uint32
}

type TOKEN_GROUPS struct {
	GroupCount uint32
	Groups [1]SID_AND_ATTRIBUTES
}
type
  SID_AND_ATTRIBUTES = record
    Sid: Pointer;
    Attributes: DWORD;
  end;

  TOKEN_GROUPS = record
    GroupCount: DWORD;
    Groups: array[0..0] of SID_AND_ATTRIBUTES;
  end;
const SID_AND_ATTRIBUTES = extern struct {
    Sid: ?*anyopaque,
    Attributes: u32,
};

const TOKEN_GROUPS = extern struct {
    GroupCount: u32,
    Groups: [1]SID_AND_ATTRIBUTES,
};
type
  SID_AND_ATTRIBUTES {.bycopy.} = object
    Sid: pointer
    Attributes: uint32

  TOKEN_GROUPS {.bycopy.} = object
    GroupCount: uint32
    Groups: array[1, SID_AND_ATTRIBUTES]
struct SID_AND_ATTRIBUTES
{
    void* Sid;
    uint Attributes;
}

struct TOKEN_GROUPS
{
    uint GroupCount;
    SID_AND_ATTRIBUTES[1] Groups;
}

HSP用 定義

HSP3.7/3.8 は構造体機能が無いため4byte整数配列(dim)+peek/poke で操作(32/64bitでサイズ・位置が異なる場合はタブで分割)。IronHSP は NSTRUCT(#defstruct/stdim/->)で32/64bit共通。

; HSP3.7/3.8 は構造体機能が無いため、4byte整数の配列変数で操作します。(x86 レイアウト)
; TOKEN_GROUPS サイズ: 12 バイト(x86)
dim st, 3    ; 4byte整数×3(構造体サイズ 12 / 4 切り上げ)
; GroupCount : DWORD (+0, 4byte)  st.0 = 値  /  値 = st.0   (lpoke/lpeek も可)
; Groups : SID_AND_ATTRIBUTES (+4, 8byte)  varptr(st)+4 を基点に操作(8byte:入れ子/配列)
; ※4byte境界の整数は添字 st.N(N=オフセット/4)で読み書き可。それ以外は peek/poke 系を使用。
; HSP3.7/3.8 は構造体機能が無いため、4byte整数の配列変数で操作します。(x64 レイアウト)
; TOKEN_GROUPS サイズ: 24 バイト(x64)
dim st, 6    ; 4byte整数×6(構造体サイズ 24 / 4 切り上げ)
; GroupCount : DWORD (+0, 4byte)  st.0 = 値  /  値 = st.0   (lpoke/lpeek も可)
; Groups : SID_AND_ATTRIBUTES (+8, 16byte)  varptr(st)+8 を基点に操作(16byte:入れ子/配列)
; ※4byte境界の整数は添字 st.N(N=オフセット/4)で読み書き可。それ以外は peek/poke 系を使用。
; IronHSP は NSTRUCT(構造体)をサポート。32bit/64bit どちらでも同じコードで動作します。
; ※GUID・入れ子構造体はデフォルト型でないため、依存する #defstruct を先に定義(下記に同梱)。
#defstruct global SID_AND_ATTRIBUTES
    #field intptr Sid
    #field int Attributes
#endstruct

#defstruct global TOKEN_GROUPS
    #field int GroupCount
    #field SID_AND_ATTRIBUTES Groups 1
#endstruct

stdim st, TOKEN_GROUPS        ; NSTRUCT 変数を確保
st->GroupCount = 100
mes "GroupCount=" + st->GroupCount