[Okta Webinar] Learn how to a build a cloud-first strategyRegister Now

x
?
Solved

How to change local account SID

Posted on 2007-04-02
4
Medium Priority
?
617 Views
Last Modified: 2008-02-07
How do you edit the SID of a local account on a 2000 AD member server.  (built-in system accounts, IUSER_Machine and IWAM_Machine).
0
Comment
Question by:ksuchy
4 Comments
 
LVL 67

Accepted Solution

by:
sirbounty earned 1500 total points
ID: 18838918
You can't.  The built-in accounts are hard-coded and assigned the same SID.
0
 
LVL 10

Expert Comment

by:Phadke_hemant
ID: 18841441
you can use SID changer such as NewSID v4.06
http://www.sysinternals.com/SourceCode.html
0
 
LVL 66

Expert Comment

by:johnb6767
ID: 18854330
Why would you want to?
0
 

Author Comment

by:ksuchy
ID: 18858820
PREFACE:  This is part of the creation of a test lab scenario, in preparation for an enterprise level migration of a giant webserver to a new box, and from IIS 5 to 6.  
RESPONSE TO POSTS:  NewSID (SysInternals) will not work for this.  I think that it can be done, but rather than continue to work on this, we have decided to use another workaround.  I will thus grant the points to sirbounty, although I think he could be wrong (because he is the least wrong).
EXPLANATION: I wanted to avoid parsing NTFS on a couple hundred host-header web content folders, and writing a script to add all the correct permissions and remove all the old permissions for an IUSER on IIS 5 .  The old SID cannot be retrieved due to a long complex story; this is a test lab machine on a duplicate AD in the lab (same as production AD), but (a) the test lab IIS machine cannot be ghosted (no duplicate raid controller and similar-enough-hw is available),  (b) Sys State (and thus Metabase) cannot be restored/migrated respectively, ALTHOUGH (c) we were able to use tape restore of web content folders since that volume was separate from the 'c' (windows os) drive.  The folders have lots of other permissions which will need to remain, and the SIDs for those accounts are good AD SIDs which resolve just fine in the lab.  
SOLUTION:  We are just parsing all the NTFS folders with Cacls to add the new local IUSER account, and using iCacls to remove the local ISUR account SID of the production IIS server which cannot be resolved.
0

Featured Post

When ransomware hits your clients, what do you do?

MSPs: Endpoint security isn’t enough to prevent ransomware.
As the impact and severity of crypto ransomware attacks has grown, Webroot has fought back, not just by building a next-gen endpoint solution capable of preventing ransomware attacks but also by being a thought leader.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Tech spooks aren't just for those who are tech savvy, it also happens to those of us running a business. Check out the top tech spooks for business owners.
Phishing emails are a popular malware delivery vehicle for attack.  While there are many ways for an attacker to increase the chances of success for their phishing emails, one of the most effective methods involves spoofing the message to appear to …
The Email Laundry PDF encryption service allows companies to send confidential encrypted  emails to anybody. The PDF document can also contain attachments that are embedded in the encrypted PDF. The password is randomly generated by The Email Laundr…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…

872 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question