Improve company productivity with a Business Account.Sign Up

x
?
Solved

How to manually add SID History

Posted on 2006-11-15
1
Medium Priority
?
5,333 Views
Last Modified: 2012-08-13
We have a user account that was deleted out of Active Directory. We didnt catch it until it had replicated through our domain. We have backups, but i really dont want to go through the process of doing an authoritative restore to pull back one user account (we actually bought Quests Recovery Manager but are still waiting for it to come in...)

As you can imagine, the user account was recreated, but now we are running into issues where emails are bouncing back and a slew of other problems. I was able to pull his string SID from a report of recently deleted users. I was able to convert his string SID into HEX using this site:

http://blogs.msdn.com/oldnewthing/archive/2004/03/15/89753.aspx

When i go into ADSI Edit to add this converted SID into the user accounts SIDHistory i get "Access is Denied". I read in a couple of forums that this is to be expected because of the potential security breaches that could occur, but i also found a link to a page on the MSDN site that outlined prerequisites that must be met before you could manually add the SID. Unfortunately that site has been moved or is no longer in the MSDN section. I am pretty sure that if i can reattach his old SID then all of his problems would be resolved (permissions, emails bouncing, etc). I dont know that i can use ADMT since i am not moving to another Domain, but i could be completely off on how that utility works. If any one could provide some insight on this issue i would greatly appreciate it.
0
Comment
Question by:aggiejon04
1 Comment
 
LVL 27

Accepted Solution

by:
Pber earned 1000 total points
ID: 18019988
You are right, you can't do it from ADSIedit, too much of a security hole.

Look for a file called sidhist.vbs that will be included in the 2003 support tools.  Just run the vbs file for the syntax.  It requires you to map it back to a specific user from the old domain, you can't just plug any old sid in there.
0

Featured Post

Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

Join & Write a Comment

I've always wanted to allow a user to have a printer no matter where they login. The steps below will show you how to achieve just that. In this Article I'll show how to deploy printers automatically with group policy and then using security fil…
Learn about cloud computing and its benefits for small business owners.
Free Data Recovery software is an advanced solution from Kernel Tools to recover data and files such as documents, emails, database, media and pictures, etc. It supports recovery from physical & logical drive after a hard disk crash, accidental/inte…
To export Lotus Notes to Outlook PST or Exchange and Domino Server files to Exchange Server or PST files with ease, go for Kernel for Lotus Notes to Outlook conversion tool. Through the video, you can watch the conversion process. A common user with…

606 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question