Re: ADMT - SID Histroy Problem

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: Chriss3 [MVP] (noSpamHere_at_chrisse.se)
Date: 12/03/04


Date: Fri, 3 Dec 2004 01:15:06 +0100

Hello,
Run the Service Translation Wizard in ADMTv2 to change SIDs on ACLs and
SACLs on migrated objects.

-- 
Regards
Christoffer Andersson
Microsoft MVP - Directory Services
No email replies please - reply in the newsgroup
------------------------------------------------
http://www.chrisse.se - Active Directory Tips
"Ed R." <Ed R.@discussions.microsoft.com> skrev i meddelandet 
news:7D006B1F-7A3A-48EE-A6A9-100450C80EB7@microsoft.com...
>I am migrating a NT 4.0 Domain to AD-2003 I enabled SID history during the
> migration and everything seemed to go fine.  If I run LDP I can see a 
> current
> SID and the old SID on user "x".  There is a directory on a server that 
> user
> "x" had access to from the old domain and they no longer have access to 
> that
> directory.  The permissions on that directory are user "x" gets full 
> control
> not a group he is a member of.  It appears that any groups that have
> permissions to the old domain work fine, just not individual permissions 
> of
> users to a resource.
>
> Thanks in advance,
> Ed 


Relevant Pages

  • Re: ADMT SID History Question ?
    ... I understand how SID history works ie the new user gets a copy of the ... resource knows to display the new migrated account. ... > Security translation is a function of ADMT 2.0 that updates access control ... > lists when migrating objects across domains. ...
    (microsoft.public.windows.server.migration)
  • Re: ADMT SID History Question ?
    ... I understand how SID history works ie the new user gets a copy of the ... resource knows to display the new migrated account. ... > Security translation is a function of ADMT 2.0 that updates access control ... > lists when migrating objects across domains. ...
    (microsoft.public.windows.server.migration)
  • Re: Migrate computer acounts and profiles
    ... is shown in the ACL editor on the file system the SID is used. ... ACL translation means replace the source SID (for the domain you are ... migrating from) by the target SID ... > Jorge what is meant by "when migrating the computers also translate the ...
    (microsoft.public.windows.server.active_directory)
  • ADMT - SID Histroy Problem
    ... I am migrating a NT 4.0 Domain to AD-2003 I enabled SID history during the ... If I run LDP I can see a current ... SID and the old SID on user "x". ... The permissions on that directory are user "x" gets full control ...
    (microsoft.public.windows.server.active_directory)
  • Re: ACLs and permissions viewed after Migrating from NT 4 domain... The twilight zone?
    ... the NT4 sid that was assigned to him was added ... it also checks the sid history when attempting to crack a sid to a user. ... > we're currently migrating our NT 4 domain to AD using ADMT from Microsoft. ...
    (microsoft.public.win2000.security)