Solved

I need a script to remove the "Unknown Accounts" SID history from accounts that have been migrated.

Posted on 2014-01-20
2
1,735 Views
Last Modified: 2014-01-21
We did a cross forest migration using ADMT tool.
I need a script to remove the "Unknown Accounts" SID history from accounts that have been migrated.

So, when I open the security tab on the property of any account we migrated, I see the following:

Account Unknown(S-1-5-21-etc
Account Unknown(S-1-5-21-etc
Account Unknown(S-1-5-80-etc

Please let me know.
Thank you
0
Comment
Question by:claudiamcse
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
2 Comments
 
LVL 4

Accepted Solution

by:
tmx84 earned 250 total points
ID: 39794631
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 250 total points
ID: 39794664
You can use powershell to accomplish this. Use the below syntax...

import-module activedirectory
Get-ADUser –filter * -properties * | ? {$_,SIDHistory -like "*"} | foreach {Set-ADUser $_ -remove @{sidhistory=$_.sidhistory.value}}

Open in new window


This will find all of the user accounts with Sid History value and remove it from the account.

There is also another good function/cmdlet that was created called SID-History. This is another way to get the information you are looking for. Check the link below...

SID History

Will.
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A hard and fast method for reducing Active Directory Administrators members.
Unified and professional email signatures help maintain a consistent company brand image to the outside world. This article shows how to create an email signature in Exchange Server 2010 using a transport rule and how to overcome native limitations …
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

630 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question