Re: Active Directory

From: Steve Foster [SBS MVP] (steve.foster_at_picamar.co.uk)
Date: 05/15/04


Date: Sat, 15 May 2004 06:35:34 -0700

Haigy wrote:

> i have checked Active Directory users and computers and have noticed
> that under ForeginSecurityPrincipals there are items in there with a
> red arrow next to them and what looks like a SID number, some
> services are not starting due to authentication, could this be the
> problem
>
> i have installed sbs on another server and this container has nothing
> in it
>
> could this becausing some of the error problems
>
> thanks

The ForeignSecurityPrincipals folder is for external SIDs gathered from
trust relationships. Since SBS doesn't generally support trusts, this
would normally be empty.

I'm guessing that if you did a migration from an existing domain to
SBS2003, you might get some entries as a result.

I would doubt that entries here would have any impact on regular SBS
operations though. What problems are you having with services? Please
include event log messages and as much detail as possible.

-- 
Steve Foster [SBS MVP]
---------------------------------------
MVPs do not work for Microsoft. Please reply only to the newsgroups.


Relevant Pages

  • Re: Error Message About Domain Controller
    ... You cannot have a trust between an SBS domain and another domain (neither ... When a Windows Domain is created a random ... Windows knows them by their user SID. ...
    (microsoft.public.windows.server.sbs)
  • Re: Error Message About Domain Controller
    ... spoke to a network engineer last night and he basically told me the same ... > vanilla windows nor SBS). ... > alphanumeric sequence is created, this is the domain SID. ... I didn't have the DNS Pointing to the ...
    (microsoft.public.windows.server.sbs)
  • Re: New Server (Hardware Upgrade), SBS 2003 to SBS 2003 Same Domain Na
    ... as for the data transfer from one box to the other the OP is correct, having the same named (different SID) AD on two DCs on the same ethernet segment is bound to cause problems and in the better case of www.sbsmigration.com's Swing IT process where you migrate the domain you _really_ don't want to connect OriginSBS and TargetSBS to the same wire at any time, having two copies of a same named same SID AD on one wire is worse than the other. ... For data transfer either HDD or Tape is best. ... SBS remote support services. ... In either case, not only will it be the same domain when you're done, you'll have the same server name and everything else. ...
    (microsoft.public.windows.server.sbs)
  • Re: *Advise needed* Changing a SBS2000 to Win2003 ENT
    ... SBS limitations are plenty (no other DC's ... The problem I am struggling with is, with 40+ workstaions, what will ... personal preferences, without having to setup new accounts on the new ... I am thinking that re-using the 'old' domain name will create SID ...
    (microsoft.public.windows.server.setup)
  • Re: DNS & DHCP
    ... I have gone in to dns and just cleared out old or bad entries. ... has been done twice in 6 years of SBS and over 40 SBS installs. ... Jim B. SBS MVP ...
    (microsoft.public.backoffice.smallbiz2000)