?
Solved

Computer sids

Posted on 2013-01-25
5
Medium Priority
?
384 Views
Last Modified: 2013-02-09
I have a problem, I have been asked to look and imaging as the company I'm working for as issues with there many W7 master images..

I have noticed that some PCs are reporting duplicat sids  

If I run PSgetsid on 3 PCs I get these returns..

SID for \\PC1:
S-1-5-21-1305255674-1099027245-2674484874

SID for \\PC2:
S-1-5-21-1305255674-1099027245-2674484874

SID for \\PC3:
S-1-5-21-4098788176-3130592841-3952154111

This would seem to say I have a duplicate on PC 1and PC2

However If I run NTDSutl, on the DC I get no duplicates

and is I run ADfind  

I get


PC1
S-1-5-21-2208487660-598541723-662457061-14148
PC2
S-1-5-21-2208487660-598541723-662457061-14157
PC3
S-1-5-21-2208487660-598541723-662457061-12099

So the DC looks good

So my questing is what am I missing?

The reason I'm looking at this as we are getting some pcs drop off the domain and there are big question around the current images and WSUS


Thanks in advance
0
Comment
Question by:Nytram
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
  • 2
5 Comments
 
LVL 9

Expert Comment

by:TazDevil1674
ID: 38818445
If you clone XP/W7 machines, you end up with duplicate SIDs, when they joing a Domain they are given a unique Domain SID.

If they are cloned after joining a Domain, they will get a new Domain SID if you leaft and rejoin the Domain.

The only thing that doesnt automatically update is the WSUS Unique ID which can be done by deleting a reg key and WSUS will issue a new one...

Hope this helps
0
 

Author Comment

by:Nytram
ID: 38818459
The 3 PCs

SID for \\PC1:
S-1-5-21-1305255674-1099027245-2674484874

SID for \\PC2:
S-1-5-21-1305255674-1099027245-2674484874

SID for \\PC3:
S-1-5-21-4098788176-3130592841-3952154111

Are on the domain the local sid is different to the one in AD, is this correct?

Martyn
0
 
LVL 9

Accepted Solution

by:
TazDevil1674 earned 2000 total points
ID: 38818475
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 38819070
Also look over

Resolving the duplicate SUSClientID issue, or “Why don’t all my clients show up in the WSUS console?”

http://blogs.technet.com/b/sus/archive/2009/05/05/resolving-the-duplicate-susclientid-issue-or-why-don-t-all-my-clients-show-up-in-the-wsus-console.aspx
0
 

Author Closing Comment

by:Nytram
ID: 38870963
As this Organisation is Migrating domains they are going to take the approach of Refreshing the image as there are many issues with the existing one... its will slow down the Migration but the org will be in a better place afterwards..
0

Featured Post

U.S. Department of Agriculture and Acronis Access

With the new era of mobile computing, smartphones and tablets, wireless communications and cloud services, the USDA sought to take advantage of a mobilized workforce and the blurring lines between personal and corporate computing resources.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Had a business requirement to store the mobile number in an environmental variable. This is just a quick article on how this was done.
This process allows computer passwords to be managed and secured without using LAPS. This is an improvement on an existing process, enhanced to store password encrypted, instead of clear-text files within SQL
If you’ve ever visited a web page and noticed a cool font that you really liked the look of, but couldn’t figure out which font it was so that you could use it for your own work, then this video is for you! In this Micro Tutorial, you'll learn yo…
Sometimes it takes a new vantage point, apart from our everyday security practices, to truly see our Active Directory (AD) vulnerabilities. We get used to implementing the same techniques and checking the same areas for a breach. This pattern can re…
Suggested Courses
Course of the Month13 days, 10 hours left to enroll

801 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question