Re: Cannot access NT 4 domain after user accounts migration

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance



Hi,

Thanks for helping me,
This is a 2-way trust and it is still active.
How to compare the sIDHistory attribute against
the source SID?

Alex

"Paul Williams [MVP]" wrote:

> If you compared the SIDs they will be different. As the new user objects
> have new SIDs. Their old SID is stored in an attribute called sIDHistory,
> which is also built into the access token at logon. Therefore a SID
> comparison won't help in this instance (a SID is the domain SID with the RID
> appended to the end). You need to compare the sIDHistory attribute against
> the source SID.
>
> Re. the access.
>
> What kind of trust in place? One way or two way? Is it still active? Have
> you decommissioned anything yet?
>
> --
> Paul Williams
> Microsoft MVP - Windows Server - Directory Services
> http://www.msresource.net | http://forums.msresource.net
>
>
>
.



Relevant Pages

  • list users
    ... I thougt to use the lengt of the sid, because all the new accounts have ... But I can't the length in bytes of the sids to compare, ... I'm new on scripting so I thing I'm doing a basic question error, ... Anyone knows how can I list the users or get the sidlenght for making a ...
    (microsoft.public.scripting.vbscript)
  • Re: Check Permission On File/Folder For a Given User
    ... >> then compare it with the SID in the list of ACE in DACL for the ... >> ACEs in DACL, rather the SID of the group he belongs to. ... >> Instead of going through the groups the user is member of to compare the ...
    (microsoft.public.dotnet.security)
  • Re: Check SID for GROUP membership
    ... elif PrimSID memberof SecondSID ... But you ask that you seek a way to compare SID, ...
    (microsoft.public.win2000.security)
  • Re: Cannot access NT 4 domain after user accounts migration
    ... I have to migrate global group before user accounts. ... "Alex" wrote: ... Their old SID is stored in an attribute called sIDHistory, ... You need to compare the sIDHistory attribute against ...
    (microsoft.public.windows.server.active_directory)
  • Re: sidHistory and Groups
    ... external trust --> sid filtering by default enabled, sidhistory does NOT works ... SOURCEUSER is member of SOURCEGROUP ... SOURCEUSER is migrated to TARGETDOMAIN and becomes TARGETUSER with sid of SOURCEUSER in sidhistory and is member of TARGETGROUP ...
    (microsoft.public.windows.server.migration)