Say, if I have a DACL for a process that I need to show for an end-user. I can convert it to string representation with ConvertSecurityDescriptorToStringSecurityDescriptor. I then need to make it a little bit more manageable for the user by removing "crazy" local SIDs from it. Here's an example:
D:(A;;0x1fffff;;;S-1-5-21-2301966995-2804055512-1978750589-1002)(A;;0x1fffff;;;SY)(A;;0x121411;;;S-1-5-5-0-1207601)(A;;0x1fffff;;;S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708)
For instance, the resulting string may include a user SID (or S-1-5-21-2301966995-2804055512-1978750589-1002 in the case above), which I can convert to a user name with LookupAccountName, but I can't seem to find a way to convert AppContainer SIDs into AppContainer name.
In this case, S-1-15-2-155514346-2573954481-755741238-1654018636-1233331829-3075935687-2861478708 stands for Microsoft.Windows.ShellExperienceHost.
There's an API that can convert the latter into the former, called DeriveAppContainerSidFromAppContainerName.
But I'm curious how do I convert AppContainerSid into AppContainerName?