| SDDL | Security Descriptor Flag Denoted |
| P | Protected |
| AR | Auto Inherit |
| AI | Auto Inherited |
| SDDL | Security Principal Denoted |
| AN | Anonymous Logon |
| AU | Authenticated Users |
| BA | Builtin Administrators |
| BO | Backup Operators |
| BU | Builtin Users |
| CA | Certificate Service Administrators |
| CD | Certificate Services DCOM Access |
| CG | Creator Group |
| CO | Creator Owner |
| DA | Domain Administrators |
| DC | Domain Computers |
| DD | Domain Domain Controllers |
| DG | Domain Guests |
| DU | Domain Users |
| EA | Enterprise Administrators |
| ED | Enterprise Domain Controllers |
| RO | Enterprise Read-Only Domain Controllers |
| WD | Everyone |
| PA | Group Policy Administrators |
| BG | Guests |
| HI | High Integrity Level |
| IU | Interactively Logged-On User |
| LA | Local Administrators |
| LG | Local Guest |
| LS | Local Service |
| SY | Local System |
| LW | Low Integrity Level |
| ME | Medium Integrity Level |
| NO | Network Configuration Operators |
| NU | Network Logon User |
| NS | Network Service |
| PS | Personal Self |
| PU | Power Users |
| RU | Pre-Windows 2000 Compatible Access |
| PO | Print Operators |
| RS | RAS Servers |
| RD | Remote Desktop |
| RE | Replicator |
| RC | Restricted Code |
| SA | Schema Administrators |
| SU | Service Logon User |
| SO | Server Operators |
| SI | System Integrity Level |
| SDDL | Security Principal Denoted |
| GA | Generic All |
| GR | Generic Read |
| GW | Generic Write |
| GX | Generic Execute |
| RC | Read Control |
| SD | Delete |
| WD | Write DACL |
| WO | Write Owner |
| RP | Read Property |
| WP | Write Property |
| CC | Create Child |
| DC | Delete Child |
| LC | List Child |
| SW | Self |
| LO | List Object |
| DT | Delete Tree |
| CR | Control Access |
| FA | All Access |
| FR | Generic Read |
| FW | Generic Write |
| FX | Generic Execute |
| KA | Key All Access |
| KR | Key Read |
| KW | Key Write |
| KX | Key Write |