need ADAM to ignore sid history when using lsalookupsid



The NT domain user proxy is created for all users, but for those who
have been migrated to AD (they still reside on AD and the account is
disabled in AD until they are individually migrated) we need them to
continue to authenticate through the userproxy to the NT domain.
Unfortunatley, lsalookupsid looks at the objectSID AND the sid history.
It finds the NT domain SID in the sid history (from the migration),
and directs the userproxy to the new AD account. Basically, we need it
to ignore the sid history when creating a userproxy, and only use the
objectSID of the NT domain. Is their a way to get lsalookupsid to not
look at the sid history of the AD domain?

.



Relevant Pages

  • Re: SID Hitory Not Working after ADMT 3 Migration
    ... Global Groups which the user was a member of. ... change the NTFS permissions and give their account in the new domain ... Shouldn't their SID history give them ... SID Hitory Not Working after ADMT 3 Migration ...
    (microsoft.public.windows.server.migration)
  • Re: SID Hitory Not Working after ADMT 3 Migration
    ... Yes, the sid history also works for individual user account, but I'm not ... SID Hitory Not Working after ADMT 3 Migration ... access to their home directory. ...
    (microsoft.public.windows.server.migration)
  • Re: need ADAM to ignore sid history when using lsalookupsid
    ... it is assumed to be authoritative and the original account gone. ... continue to authenticate through the userproxy to the NT domain. ... lsalookupsid looks at the objectSID AND the sid history. ... It finds the NT domain SID in the sid history (from the migration), ...
    (microsoft.public.windows.server.active_directory)
  • RE: enable sid history on sbs 2003 r2
    ... So if I understood you correctly, the user and computer account migration ... including their SID-s between two Windows 2003 SBS R2 servers is supported? ... 4.If you are migrating SID history, ADMT adds the original SID of the user ...
    (microsoft.public.windows.server.sbs)
  • RE: ADMT v2.0 Database corruption question
    ... 2004-08-24 17:50:47 Active Directory Migration Tool, ... 2004-08-24 17:50:47 Starting Account Replicator. ... > Please retore the original database. ...
    (microsoft.public.windows.server.migration)

Loading