Re: Unknown SID in Exchange 2003



Use ADSI Edit to browse down through the Exchange configuration settings in the Forest Config container. The DN will be something like cn=<orgname>,CN=Microsoft Exchange,CN=Services,CN=Configuration,<forest root DN>.

Once you find where the ACE for the unknown SID was applied, you can remove it from there.


-- Joe Richards Microsoft MVP Windows Server Directory Services www.joeware.net


DoA User wrote:
Good day,

Some time ago, as a test, I installed Exchange 2003 on a server in a child domain of my production domain. This server became the third Exchange server in my Exchange organization and the administrator of the child domain was a full Exchange administrator in the organization.

After conducting my tests, I removed the child domain Exchange server and then soon after, removed the entire child domain from AD. However, there are some remnants of the old child domain administrator account in my Exchange org. Only, because it's no longer "real", I see the account listed as an unresolved SID (S-1-5-21-12XXX...-116) in the security properties of the Exchange's administrative group.

I can't simply remove the SID account listing because I get: You cannot remove S-1-5... because this object is inheriting permissions from its parent. The parent of the Administrative Group is the Exchange organization--right??--and that SID account is not listed.

I'm assuming that in order to remove this SID, I have to edit the AD directly. What can I do about removing all traces of this account?

Thanks.
.



Relevant Pages

  • Re: password expiration policy for admin and system accounts ?
    ... > scheduled tasks that use various administrative accounts. ... > administrative account which starts several key exchange services. ... > Thus every time the exchange server was rebooted several exchange services ... >> JJ wrote:>>> Our auditors are objecting to our having Domain Administrator and domain>>> system accounts with passwords that never expire. ...
    (microsoft.public.security)
  • Re: password expiration policy for admin and system accounts ?
    ... > scheduled tasks that use various administrative accounts. ... > administrative account which starts several key exchange services. ... > Thus every time the exchange server was rebooted several exchange services ... >> JJ wrote:>>> Our auditors are objecting to our having Domain Administrator and domain>>> system accounts with passwords that never expire. ...
    (microsoft.public.win2000.security)
  • RE: reset administrator password - strange problems
    ... privileges and reinstalling exchange with /domainprep. ... > I understand that you have manually changed the Directory Services Password ... > Restore Mode Password on the SBS 2K3 server. ... If the Administrator ...
    (microsoft.public.windows.server.sbs)
  • Re: Rename Domain
    ... offices acting as DC, DNS, DHCP, FS and PS. ... Renaming a domain with Exchange in the picture is not a pretty thing and I ... Why a child domain, just out of curiosity? ... How will this affect the exchange server? ...
    (microsoft.public.exchange.admin)
  • Re: domain migration issue
    ... Made the server that was failing in the RUS connection into a GC. ... ipconfig /all from the DC's in root and child domain. ... Doing the exchange domainprep worked fine. ... from the exchange in the root domain just fine and also nslookup is ...
    (microsoft.public.windows.server.active_directory)

Loading