Solved

How to manually add SID History

Posted on 2006-11-15
1
4,556 Views
Last Modified: 2012-08-13
We have a user account that was deleted out of Active Directory. We didnt catch it until it had replicated through our domain. We have backups, but i really dont want to go through the process of doing an authoritative restore to pull back one user account (we actually bought Quests Recovery Manager but are still waiting for it to come in...)

As you can imagine, the user account was recreated, but now we are running into issues where emails are bouncing back and a slew of other problems. I was able to pull his string SID from a report of recently deleted users. I was able to convert his string SID into HEX using this site:

http://blogs.msdn.com/oldnewthing/archive/2004/03/15/89753.aspx

When i go into ADSI Edit to add this converted SID into the user accounts SIDHistory i get "Access is Denied". I read in a couple of forums that this is to be expected because of the potential security breaches that could occur, but i also found a link to a page on the MSDN site that outlined prerequisites that must be met before you could manually add the SID. Unfortunately that site has been moved or is no longer in the MSDN section. I am pretty sure that if i can reattach his old SID then all of his problems would be resolved (permissions, emails bouncing, etc). I dont know that i can use ADMT since i am not moving to another Domain, but i could be completely off on how that utility works. If any one could provide some insight on this issue i would greatly appreciate it.
0
Comment
Question by:aggiejon04
1 Comment
 
LVL 26

Accepted Solution

by:
Pber earned 500 total points
Comment Utility
You are right, you can't do it from ADSIedit, too much of a security hole.

Look for a file called sidhist.vbs that will be included in the 2003 support tools.  Just run the vbs file for the syntax.  It requires you to map it back to a specific user from the old domain, you can't just plug any old sid in there.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

The HP utility "HP Lights-Out Online Configuration Utility for Windows Server 2003/2008" could be of great use when it comes to remotely configure a HP servers ILO WITHOUT rebooting the server. We would only need to create and run scripts using thi…
I guess it is not common knowledge to most Wintel engineers/administrators: If you have an SNMP-based monitoring system in your environment (and it's common to have SNMP or Syslog) it's reasonably easy to enable monitoring of the Windows Event logs,…
This video gives you a great overview about bandwidth monitoring with SNMP and WMI with our network monitoring solution PRTG Network Monitor (https://www.paessler.com/prtg). If you're looking for how to monitor bandwidth using netflow or packet s…
This video demonstrates how to create an example email signature rule for a department in a company using CodeTwo Exchange Rules. The signature will be inserted beneath users' latest emails in conversations and will be displayed in users' Sent Items…

762 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

5 Experts available now in Live!

Get 1:1 Help Now