| Member Name | Description | 
|---|---|
| AdjustDefault |   The user can change the default owner, primary group, or discretionary access control list (DACL) of the token. | 
| AdjustGroups |   The user can change the attributes of the groups in the token. | 
| AdjustPrivileges |   The user can enable or disable privileges in the token. | 
| AdjustSessionId |   The user can adjust the session identifier of the token. | 
| AllAccess |   The user has all possible access to the token. | 
| AssignPrimary |   The user can attach a primary token to a process. | 
| Duplicate |   The user can duplicate the token. | 
| Impersonate |   The user can impersonate a client. | 
| MaximumAllowed |   The maximum value that can be assigned for the System.Security.Principal.TokenAccessLevels enumeration. | 
| Query |   The user can query the token. | 
| QuerySource |   The user can query the source of the token. | 
| Read |   The user has standard read rights and the TokenAccessLevels.Query privilege for the token. | 
| Write |   The user has standard write rights and the System.Security.Principal.TokenAccessLevels.AdjustPrivileges, F:System.Security.Principal.TokenAccessLevels.AdjustGroups, and TokenAccessLevels.AdjustDefault privileges for the token. |