ADMT SID History Question ?

From: Burnsie (stuartdavidburns_at_hotmail.com)
Date: 02/07/05


Date: 7 Feb 2005 02:10:28 -0800

Do i need to run the Security Translation Wizard / Exchange Directory
Migration Wizard after i have migrated accounts including SID history
??

I am testing this in a lab and my view is no i don't have to run these
tools as SID history will have taken care of access to resources. (If
i'm wrong please explain why !)

Here is the setup :

NT4Domain - NT4 source domain
two way tust between domains
2k3Domain - 2003 AD target domain (2003 func level)

User accounts to be migrated are in NT4 domain.
Resources (file shares & exchange5.5 mailboxes) are in 2k3domain

I have migrated the user accounts with SID history and when i view
permissions on the resources they appear as the new account ie
2k3domain\miguser (without using any of the security translation wizard
/ exchange tools.) In which case why do i have to run these tools as
the permissions are the way i want them ?

If someone could expalin how SIDs are resolved this would probably help
explain it. ie when a resource has a ACE (SID) in a DACL where doe it
look to findout who owns the SID? does it look in its own domain first
then query trusted domains ?

My view is that you only need to run the sec trans wiz & exch dir mig
wiz if you are not using SID history ????



Relevant Pages

  • Re: SID Hitory Not Working after ADMT 3 Migration
    ... As you said "Which is located on the user accounts profile tab", ... SID Hitory Not Working after ADMT 3 Migration ... Sid history via groups is working. ...
    (microsoft.public.windows.server.migration)
  • Re: exchange 5.5 test lab
    ... Is SID history a requirement when migrating NT4.0 accts to a new ... this would be consider as an inter-org migration since an exchange org ... Hope I am not making this too difficult but perhaps my migration path should ... | migration tool NetIQ to migrate all our NT accounts to win2003. ...
    (microsoft.public.exchange.admin)
  • Interorg Mailbox Migration
    ... the other - some accounts have been migrated with SID history into the EX2003 ... in the new forest. ... I match an X.500 address on those accounts and use the mailbox migration tool ...
    (microsoft.public.exchange.admin)
  • RE: SID History Not working after migration
    ... since it is a duplicate thread. ... SID History Not working after migration ... Do not expire source account ...
    (microsoft.public.windows.server.migration)
  • Re: exchange 5.5 test lab
    ... We are in the process of performing an intra-org migration however we have ... environment and requirement there is no need for SID history since all data ... Install and run Exdeploy tools on the new exchange 2003 server ... Exchange Server 5.5 Directory Service and Exchange Server 2003 AD. ...
    (microsoft.public.exchange.admin)

Loading