Solved

SID appearing not user / group name in security window

Posted on 2004-10-01
2
1,070 Views
Last Modified: 2010-08-05
My domain consists of 3 Windows 2000 domain controllers, 1 NT 4.0 member server acting as an Exchange 5.5 server and 10 other Windows 2000 member servers.  The domain was recently upgraded from an NT 4.0 domain.  Even though I am not running any NT BDC's I am still running in Mixed mode.  Will be making the change soon.  Just wanted to make sure everything is running fine w/ the 2000 domain.

Only minor Issue I am seeing relates to file / folder permissions at the server level.  Once and a while if I look at the properties of a file or folder, and goto the security tab, I may see 1 or 2 SID's (along with Domain users and domain groups)  Are these SIDs that are not being removed when accounts are removed from the domain?  (Employee quits / get fired, his account is removed)  My thought is that the SID is associated with the folder or file, but when it looks to active directory to resolve the sid to an account / group name, it cannot be found.  Am I correct?  Has anyone seen this before.

Thanks
0
Comment
Question by:chadd25
2 Comments
 
LVL 2

Expert Comment

by:dev8
ID: 12203661
0
 
LVL 82

Accepted Solution

by:
oBdA earned 125 total points
ID: 12204378
Those are ACEs from accounts that have been deleted or can otherwise not be resolved to their name (for example an account from a former trusted domain).
Sid2Name won't help you anything, because this does nothing else than what the OS tries.
On another note, when you say "along with Domain users", you've probably set your permissions incorrectly. Unless for home drives, don't assign permissions to user accounts; this will end up in a mess. The way according to MS's gospel is AGLP: *A*ccounts go into *G*lobal groups. Global groups go into *L*ocal groups (on the server that hosts the share). *P*ermissions are assigned to the local groups. On W2k AD running in native mode, you can use domain local groups instead of "real" local groups.
0

Featured Post

Free Gift Card with Acronis Backup Purchase!

Backup any data in any location: local and remote systems, physical and virtual servers, private and public clouds, Macs and PCs, tablets and mobile devices, & more! For limited time only, buy any Acronis backup products and get a FREE Amazon/Best Buy gift card worth up to $200!

Join & Write a Comment

Suggested Solutions

Title # Comments Views Activity
Making a spare domain pc 12 319
Norton Ghost for Windows NT 5 1,440
Windows 2000, Ghost 2003, disk1 disk 2 mirroring 17 338
windows explorer 21 171
NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
We have come a long way with backup and data protection — from backing up to floppies, external drives, CDs, Blu-ray, flash drives, SSD drives, and now to the cloud.
Illustrator's Shape Builder tool will let you combine shapes visually and interactively. This video shows the Mac version, but the tool works the same way in Windows. To follow along with this video, you can draw your own shapes or download the file…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

707 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

14 Experts available now in Live!

Get 1:1 Help Now