get-wmiobject -class "win32_account" -namespace "root\cimv2" | sort caption | format-table domain,name, __CLASS, SID
DESKTOP-JHU119R Access Control Assistance Operators Win32_Group S-1-5-32-579
DESKTOP-JHU119R admin Win32_UserAccount S-1-5-21-2437496762-2379314466-1107088517-1001
DESKTOP-JHU119R Administrator Win32_UserAccount S-1-5-21-2437496762-2379314466-1107088517-500
DESKTOP-JHU119R Administrators Win32_Group S-1-5-32-544
DESKTOP-JHU119R ANONYMOUS LOGON Win32_SystemAccount S-1-5-7
DESKTOP-JHU119R Authenticated Users Win32_SystemAccount S-1-5-11
DESKTOP-JHU119R Backup Operators Win32_Group S-1-5-32-551
DESKTOP-JHU119R BATCH Win32_SystemAccount S-1-5-3
DESKTOP-JHU119R BUILTIN Win32_SystemAccount S-1-5-32
DESKTOP-JHU119R CREATOR GROUP Win32_SystemAccount S-1-3-1
DESKTOP-JHU119R CREATOR GROUP SERVER Win32_SystemAccount S-1-3-3
DESKTOP-JHU119R CREATOR OWNER Win32_SystemAccount S-1-3-0
DESKTOP-JHU119R CREATOR OWNER SERVER Win32_SystemAccount S-1-3-2
DESKTOP-JHU119R Cryptographic Operators Win32_Group S-1-5-32-569
DESKTOP-JHU119R DefaultAccount Win32_UserAccount S-1-5-21-2437496762-2379314466-1107088517-503
DESKTOP-JHU119R Device Owners Win32_Group S-1-5-32-583
DESKTOP-JHU119R DIALUP Win32_SystemAccount S-1-5-1
DESKTOP-JHU119R Distributed COM Users Win32_Group S-1-5-32-562
DESKTOP-JHU119R ENTERPRISE DOMAIN CONTROLLERS Win32_SystemAccount S-1-5-9
DESKTOP-JHU119R Event Log Readers Win32_Group S-1-5-32-573
DESKTOP-JHU119R Everyone Win32_SystemAccount S-1-1-0
DESKTOP-JHU119R Guest Win32_UserAccount S-1-5-21-2437496762-2379314466-1107088517-501
DESKTOP-JHU119R Guests Win32_Group S-1-5-32-546
DESKTOP-JHU119R Hyper-V Administrators Win32_Group S-1-5-32-578
DESKTOP-JHU119R IIS_IUSRS Win32_Group S-1-5-32-568
DESKTOP-JHU119R INTERACTIVE Win32_SystemAccount S-1-5-4
DESKTOP-JHU119R IUSR Win32_SystemAccount S-1-5-17
DESKTOP-JHU119R LOCAL Win32_SystemAccount S-1-2-0
DESKTOP-JHU119R LOCAL SERVICE Win32_SystemAccount S-1-5-19
DESKTOP-JHU119R NETWORK Win32_SystemAccount S-1-5-2
DESKTOP-JHU119R Network Configuration Operators Win32_Group S-1-5-32-556
DESKTOP-JHU119R NETWORK SERVICE Win32_SystemAccount S-1-5-20
DESKTOP-JHU119R OWNER RIGHTS Win32_SystemAccount S-1-3-4
DESKTOP-JHU119R Performance Log Users Win32_Group S-1-5-32-559
DESKTOP-JHU119R Performance Monitor Users Win32_Group S-1-5-32-558
DESKTOP-JHU119R Power Users Win32_Group S-1-5-32-547
DESKTOP-JHU119R PROXY Win32_SystemAccount S-1-5-8
DESKTOP-JHU119R Remote Desktop Users Win32_Group S-1-5-32-555
DESKTOP-JHU119R REMOTE INTERACTIVE LOGON Win32_SystemAccount S-1-5-14
DESKTOP-JHU119R Remote Management Users Win32_Group S-1-5-32-580
DESKTOP-JHU119R Replicator Win32_Group S-1-5-32-552
DESKTOP-JHU119R RESTRICTED Win32_SystemAccount S-1-5-12
DESKTOP-JHU119R SELF Win32_SystemAccount S-1-5-10
DESKTOP-JHU119R SERVICE Win32_SystemAccount S-1-5-6
DESKTOP-JHU119R SYSTEM Win32_SystemAccount S-1-5-18
DESKTOP-JHU119R System Managed Accounts Group Win32_Group S-1-5-32-581
DESKTOP-JHU119R TERMINAL SERVER USER Win32_SystemAccount S-1-5-13
DESKTOP-JHU119R Users Win32_Group S-1-5-32-545
DESKTOP-JHU119R WDAGUtilityAccount Win32_UserAccount S-1-5-21-2437496762-2379314466-1107088517-504