Solved

How to manually add SID History

Posted on 2006-11-15
1
4,721 Views
Last Modified: 2012-08-13
We have a user account that was deleted out of Active Directory. We didnt catch it until it had replicated through our domain. We have backups, but i really dont want to go through the process of doing an authoritative restore to pull back one user account (we actually bought Quests Recovery Manager but are still waiting for it to come in...)

As you can imagine, the user account was recreated, but now we are running into issues where emails are bouncing back and a slew of other problems. I was able to pull his string SID from a report of recently deleted users. I was able to convert his string SID into HEX using this site:

http://blogs.msdn.com/oldnewthing/archive/2004/03/15/89753.aspx

When i go into ADSI Edit to add this converted SID into the user accounts SIDHistory i get "Access is Denied". I read in a couple of forums that this is to be expected because of the potential security breaches that could occur, but i also found a link to a page on the MSDN site that outlined prerequisites that must be met before you could manually add the SID. Unfortunately that site has been moved or is no longer in the MSDN section. I am pretty sure that if i can reattach his old SID then all of his problems would be resolved (permissions, emails bouncing, etc). I dont know that i can use ADMT since i am not moving to another Domain, but i could be completely off on how that utility works. If any one could provide some insight on this issue i would greatly appreciate it.
0
Comment
Question by:aggiejon04
1 Comment
 
LVL 26

Accepted Solution

by:
Pber earned 500 total points
ID: 18019988
You are right, you can't do it from ADSIedit, too much of a security hole.

Look for a file called sidhist.vbs that will be included in the 2003 support tools.  Just run the vbs file for the syntax.  It requires you to map it back to a specific user from the old domain, you can't just plug any old sid in there.
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Organizations create, modify, and maintain huge amounts of data to help their businesses earn money and generally function.  Typically every network user within an organization has a bit of disk space to store in process items and personal files.   …
Scenerio: You have a server running Server 2003 and have applied a retail pack of Terminal Server Licenses.  You want to change servers or your server has crashed and you need to reapply the Terminal Server Licenses. When you enter the 16-digit lic…
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
Finds all prime numbers in a range requested and places them in a public primes() array. I've demostrated a template size of 30 (2 * 3 * 5) but larger templates can be built such 210  (2 * 3 * 5 * 7) or 2310  (2 * 3 * 5 * 7 * 11). The larger templa…

820 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question