Re: Infrastructure Master FSMO role, Global Catalogs and Forest Trusts

Tech-Archive recommends: Fix windows errors by optimizing your registry



Joe,
I ran ADMT for the migration including the security translation wizard on my
resource machines (I did it to all workstations and servers) when the
migration was going on, so I don't believe there are any old sid's in the
acl's. I went back and looked to double check and I found none, but I might
just not be understanding the process.

I'm unclear about what you are referring to when you stated "I would look
through the groups for that FSP and when you find it, change to the user's
real object in the forest, then remove the FSP". I thought this was done
automagically via ADMT so I went through the group membership of groups and
all cn's pointed directly to the newly created users in there ou.

I know there is a lot of smoke and mirrors that went on during the migration
but I was hoping I only had to go back and clear the sidHistory attribute of
the migrated objects (Which I have held off doing so far) and the clean up
of the FSP objects but this is not my strong suit.

So question is how can I find any lingering objects because I don't think I
can have any. If not can I delete the FSP objects and clear the sidHistory?


--
Paul Bergson MCT, MCSE, MCSA, Security+, CNE, CNA, CCA
http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewsGroup

This posting is provided "AS IS" with no warranties, and confers no rights.

"Joe Richards [MVP]" <humorexpress@xxxxxxxxxxx> wrote in message
news:uRGJtBFoGHA.4248@xxxxxxxxxxxxxxxxxxxxxxx
Ah you have migrated the user principals into the domain. This simply
means you have SID History set for them and that is how the APIs are
resolving the SIDs.

Yeah in that case, if the readable name is in the same forest, I would
look through the groups for that FSP and when you find it, change to the
user's real object in the forest, then remove the FSP.

Then start cleaning up ACLs that reference the old SIDs (ACLs don't need
the DNs, just the SIDs) and once that is done, clear the SID Histories.

joe

--
Joe Richards Microsoft MVP Windows Server Directory Services
Author of O'Reilly Active Directory Third Edition
www.joeware.net


---O'Reilly Active Directory Third Edition now available---

http://www.joeware.net/win/ad3e.htm



Paul Bergson wrote:
I don't get it. I ran your sid to name and they resolve.

???



.



Relevant Pages

  • Re: ADMT V2.0 NT4.0 -> Windows 2003
    ... > So after the user and workstation accounts have been migrated with ADMT, ... >> The old sid is kept in the sidhistory and will remain there until you ... If you finished your migration and translated all permissions on ... >> user logs on he's getting a token with SIDs for himself, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Multiple DOMAINS - SINGLE SIGN ON
    ... on the data specifies the SIDs of the users in the OLD domain. ... What you need to do is to use ADMTv3 (Active Directory Migration Tool) ... After that you need to MIGRATE the data and reacl (also with ADMT) ... data you can cleanup SIDhistory ...
    (microsoft.public.win2000.active_directory)
  • Re: ADMT V2.0 NT4.0 -> Windows 2003
    ... > If you use ADMT the NT4 domain needs to be named differently than the new AD ... > The old sid is kept in the sidhistory and will remain there until you clean it ... If you finished your migration and translated all permissions on files, ... > user logs on he's getting a token with SIDs for himself, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Infrastructure Master FSMO role, Global Catalogs and Forest Trusts
    ... I'm going to remove the FSP NT group membership from the builtin groups, ... clean the sidHistory and purge the FSP objects. ... I ran ADMT v3 during the migration. ... clean up sIDHistory as well but that is another story. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Impact of AD Migration on Windows authenticated SQL user account
    ... This sounds like you are changing the domain as well during the migration. ... I believe in the documentation that SIDs are retained by ADMT, ... > Personally I doubt that ADMT does translate any SQL ... > Besides, I realized that from the Security, Logins folder ...
    (microsoft.public.sqlserver.server)