Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Does Active Directory users have unique IDs?

Posted on 2009-05-19
7
Medium Priority
?
553 Views
Last Modified: 2013-11-05
hi, does Active Directory users have unique IDs? if so what the name of this property?
0
Comment
Question by:Abdu_Allah
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
7 Comments
 
LVL 1

Assisted Solution

by:systemagic
systemagic earned 100 total points
ID: 24426244
All Active directory objects have unique security identifiers which are referred to as SID numbers.
0
 
LVL 3

Assisted Solution

by:Cameron_S
Cameron_S earned 100 total points
ID: 24426309
Systemagic is correct. Also, sAMAccountName is the unique name (login name, essentially) specifically to users, if you needed a logical reference outside a numerical one.
0
 
LVL 57

Assisted Solution

by:Mike Kline
Mike Kline earned 200 total points
ID: 24426346
Yes a SID is the name, every user has one, there are also well known SIDs. More on that here
http://support.microsoft.com/kb/243330
Well-known security identifiers in Windows operating systems
Want to quickly find the SID of a user object.  Use adfind by MVP Joe Richards
http://www.joeware.net/freetools/tools/adfind/index.htm
use one of the shortcuts Joe has provided for a user
adfind -sc u:USERNAME objectsid
Thanks
Mike

adfind-SID.jpg
0
Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
LVL 71

Assisted Solution

by:Chris Dent
Chris Dent earned 1600 total points
ID: 24429900

These are the unique properties:

objectGUID - Unique within a Forest. Cannot be changed.

sAMAccountName - Unique within a Domain. Can be changed.

sID (Security Identifier) - Unique within a Forest. Cannot be changed, may have an additional entry in sIDHistory.

userPrincipalName - Unique within a Forest. Can be changed.

There are a few others, but those are the most reliable. Depending on your goal the objectGUID may be the best for a couple of reasons:

1. It never changes unless the account object is destroyed (rename or move the account and it'll still be there)
2. You can bind to an account using the GUID

Chris
0
 
LVL 3

Author Comment

by:Abdu_Allah
ID: 24430788
And how do I retreive this sID using scripts?
Point raised to 500
0
 
LVL 3

Author Comment

by:Abdu_Allah
ID: 24430797
ASP or ASP.NET script please.
0
 
LVL 71

Accepted Solution

by:
Chris Dent earned 1600 total points
ID: 24431147

For the SID in ASP .NET using DirectoryServices this example is good enough:

http://www.netomatix.com/getusersid.aspx

If you look at the code for "ConvertByteToStringSid" you'll see that it isn't a pleasant field to work with. The same can be said of objectGUID to an extent, but it has some converters...

VB .NET:

Dim adUser As New DirectoryEntry("LDAP://CN=Some users,OU=Somewhere,DC=domain,DC=com")
Dim objectGUID As Byte() = adUser.Properties("objectGuid").Value
Dim GUID As New System.Guid(objectGUID)
' GUID String is held in:
' GUID.ToString()

Chris
0

Featured Post

Get your Conversational Ransomware Defense e‑book

This e-book gives you an insight into the ransomware threat and reviews the fundamentals of top-notch ransomware preparedness and recovery. To help you protect yourself and your organization. The initial infection may be inevitable, so the best protection is to be fully prepared.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

After seeing many questions for JRNL_WRAP_ERROR for replication failure, I thought it would be useful to write this article.
A bad practice commonly found during an account life cycle is to set its password to an initial, insecure password. The Password Reset Tool was developed to make the password reset process easier and more secure.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

636 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question