Solved

How to verify SID history?

Posted on 2012-03-12
2
969 Views
Last Modified: 2012-06-27
Hi,


I have a user who is migrated to different domain with his SID history. The same user can't acces to old server which is still on old domain but another user can.
How can I verify a user SID history and make sure he still has the old SID link to his AD account?

For Exemple: Windows 2003 and AD 2003

UserX.domain1.com
UserY.domain1.com

Server1.doamin1.com


Both users are migrated to domain2.com so: UserX.domain2.com et UserY.domain2.com

UserY.domain2.com can still access to Server1.doamin1.com but not UserX.domain2.com


How can't I verify the SID history of old account is still linked to UserX.domain2.com?
0
Comment
Question by:SAM2009
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 6

Accepted Solution

by:
dave_it earned 500 total points
ID: 37715184
Using a program like LDP or ADSIEdit, look at the sIDHistory attribute on the user for any SIDs.  From there, if you know the format of the SID for the old directory, you should be able to quickly determine if a SID from that old domain is attached to the user account in question.
0
 
LVL 1

Author Closing Comment

by:SAM2009
ID: 37723341
Thank you!
0

Featured Post

Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
In this article, I am going to show you how to simulate a multi-site Lab environment on a single Hyper-V host. I use this method successfully in my own lab to simulate three fully routed global AD Sites on a Windows 10 Hyper-V host.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question