Account Unknown
When viewing the mailbox rights of a number of our users there is an entry
for 'Account Unknown (S-1-5-21-59991277-438593048-1990678075-3689)'.
This, I believe, is a hang over from migration from w2k to w2k3 servers with
new names - a group/user? that doesn't exist in the new schema.
If I try to remove this entry I get an error telling me that this is
inherited and must be removed from the parent. Problem is that I can't find
any object with that SID in any of the parent objects or anywhere else in
the AD schema.
I have used ADSIEDIT to try to find an object with this SID without success.
Can anyone suggest a way that I can remove this invalid SID?
--
-----------------------------------------------------------------------------------------------------------------------
This message has been checked for all known viruses.
The information contained in this e-mail and any attachments is confidential
and may be the subject of legal, professional or other privilege. It is
intended for the named addressee only and may not be disclosed to any other
parties without the prior permission of the originator.
.
Relevant Pages
- Re: ADAM bindable object question
... and have done in the past when an auxiliary object class ... We made an exception for bindProxy objects -- the SID can only be ... for an existing entry of *arbitrary* object ... >> SDE, Active Directory Core ... (microsoft.public.windows.server.active_directory) - Re: ADAM bindable object question
... As for the non-comformant schema, ... and have done in the past when an auxiliary object class ... for an existing entry of *arbitrary* object ... >> The problem I'm seeing is when i try to add these object classes ... (microsoft.public.windows.server.active_directory) - Re: Bye SiD
... The decision to remove SID is in response to the issues now outlined ... On SID people create their own entries and are responsible for keeping their entry up to date and each County is supposed to have a local administrator who can make amendments. ... Secondly if the concern is SPAM from harvesting addresses then that has not been solved at all by doing this as by leaving the database in situ and only changing the front page they have done nothing to change the situation. ... If they really are concerned about SID and committed to a replacement they it wouldn't take long to replace it by incorporating it into Membership Services. ... (uk.rec.scouting) - ADPrep /forestprep fails - Note for Bob Qin
... find the CN=labeledURI entry. ... modifying the CN=labeledURI entry. ... can I do an authoritative restore of the system state? ... authoritative restore restore the schema changes? ... (microsoft.public.windows.server.migration) - [Z/EVES] A Relation domain checking problem (but FuzZ is ok)
... Map: \bag Entry ... I want to explicitly say that an Entry must not ... Does anyone have an idea to domain check this schema operator? ... (comp.specification.z) |
|