migrated W2k3 account's access to old NT4 resources



Hello,

We have migrated some users from an NT4 domain into a new w2k3 AD. We have
brought the SID history across during the migration. A lot of the data which
the users need to access still sits on servers which are members of the old
NT domain. When an administrator from the NT domain wishes to grant
permission for the new w2k3 account to access an NT share, they put the old
NT account into an NT group which has permissions on the share. However,
this does not seem to be working and the migrated user account cannot access
the data.

I thought that when the old user account was added to a group, then this
should allow the new account access to the data, because the old NT SID is
attached to the new account?

Thanks in advance for any help.

.



Relevant Pages

  • Re: SID Hitory Not Working after ADMT 3 Migration
    ... Global Groups which the user was a member of. ... change the NTFS permissions and give their account in the new domain ... Shouldn't their SID history give them ... SID Hitory Not Working after ADMT 3 Migration ...
    (microsoft.public.windows.server.migration)
  • Re: SID Hitory Not Working after ADMT 3 Migration
    ... Yes, the sid history also works for individual user account, but I'm not ... SID Hitory Not Working after ADMT 3 Migration ... access to their home directory. ...
    (microsoft.public.windows.server.migration)
  • Re: need ADAM to ignore sid history when using lsalookupsid
    ... it is assumed to be authoritative and the original account gone. ... continue to authenticate through the userproxy to the NT domain. ... lsalookupsid looks at the objectSID AND the sid history. ... It finds the NT domain SID in the sid history (from the migration), ...
    (microsoft.public.windows.server.active_directory)
  • RE: enable sid history on sbs 2003 r2
    ... So if I understood you correctly, the user and computer account migration ... including their SID-s between two Windows 2003 SBS R2 servers is supported? ... 4.If you are migrating SID history, ADMT adds the original SID of the user ...
    (microsoft.public.windows.server.sbs)
  • need ADAM to ignore sid history when using lsalookupsid
    ... The NT domain user proxy is created for all users, ... lsalookupsid looks at the objectSID AND the sid history. ... It finds the NT domain SID in the sid history (from the migration), ... and directs the userproxy to the new AD account. ...
    (microsoft.public.windows.server.active_directory)