Solved

Computer sids

Posted on 2013-01-25
5
380 Views
Last Modified: 2013-02-09
I have a problem, I have been asked to look and imaging as the company I'm working for as issues with there many W7 master images..

I have noticed that some PCs are reporting duplicat sids  

If I run PSgetsid on 3 PCs I get these returns..

SID for \\PC1:
S-1-5-21-1305255674-1099027245-2674484874

SID for \\PC2:
S-1-5-21-1305255674-1099027245-2674484874

SID for \\PC3:
S-1-5-21-4098788176-3130592841-3952154111

This would seem to say I have a duplicate on PC 1and PC2

However If I run NTDSutl, on the DC I get no duplicates

and is I run ADfind  

I get


PC1
S-1-5-21-2208487660-598541723-662457061-14148
PC2
S-1-5-21-2208487660-598541723-662457061-14157
PC3
S-1-5-21-2208487660-598541723-662457061-12099

So the DC looks good

So my questing is what am I missing?

The reason I'm looking at this as we are getting some pcs drop off the domain and there are big question around the current images and WSUS


Thanks in advance
0
Comment
Question by:Nytram
  • 2
  • 2
5 Comments
 
LVL 9

Expert Comment

by:TazDevil1674
ID: 38818445
If you clone XP/W7 machines, you end up with duplicate SIDs, when they joing a Domain they are given a unique Domain SID.

If they are cloned after joining a Domain, they will get a new Domain SID if you leaft and rejoin the Domain.

The only thing that doesnt automatically update is the WSUS Unique ID which can be done by deleting a reg key and WSUS will issue a new one...

Hope this helps
0
 

Author Comment

by:Nytram
ID: 38818459
The 3 PCs

SID for \\PC1:
S-1-5-21-1305255674-1099027245-2674484874

SID for \\PC2:
S-1-5-21-1305255674-1099027245-2674484874

SID for \\PC3:
S-1-5-21-4098788176-3130592841-3952154111

Are on the domain the local sid is different to the one in AD, is this correct?

Martyn
0
 
LVL 9

Accepted Solution

by:
TazDevil1674 earned 500 total points
ID: 38818475
0
 
LVL 47

Expert Comment

by:Donald Stewart
ID: 38819070
Also look over

Resolving the duplicate SUSClientID issue, or “Why don’t all my clients show up in the WSUS console?”

http://blogs.technet.com/b/sus/archive/2009/05/05/resolving-the-duplicate-susclientid-issue-or-why-don-t-all-my-clients-show-up-in-the-wsus-console.aspx
0
 

Author Closing Comment

by:Nytram
ID: 38870963
As this Organisation is Migrating domains they are going to take the approach of Refreshing the image as there are many issues with the existing one... its will slow down the Migration but the org will be in a better place afterwards..
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
While working, an annoying popup showing below will come and we cannot cancel or close it form the screen. The error message will come again and again.
This Micro Tutorial will teach you how to change your appearance and customize your Windows 7 interface to your unique preference. This will be demonstrated using Windows 7 operating system.
This Micro Tutorial will give you a introduction in two parts how to utilize Windows Live Movie Maker to its maximum capability. This will be demonstrated using Windows Live Movie Maker on Windows 7 operating system.

810 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question