the primary mechanism Windows uses for auth and access control
SIDs are globally totally unique and non reusable. used to identify security principals such as user accounts, computers, groups etc
when a security principal is created, the AD security auth issues it a unique SID wich is then stored in the security database. resources are linked to these SIDs
the SID is the same for all security principals within a particular domain but the Relative ID (RID) is unique for each individual security principal within the domain