I need a script to remove the "Unknown Accounts" SID history from accounts that have been migrated.

We did a cross forest migration using ADMT tool.
I need a script to remove the "Unknown Accounts" SID history from accounts that have been migrated.

So, when I open the security tab on the property of any account we migrated, I see the following:

Account Unknown(S-1-5-21-etc
Account Unknown(S-1-5-21-etc
Account Unknown(S-1-5-80-etc

Please let me know.
Thank you
claudiamcseAsked:
Who is Participating?
 
Will SzymkowskiConnect With a Mentor Senior Solution ArchitectCommented:
You can use powershell to accomplish this. Use the below syntax...

import-module activedirectory
Get-ADUser –filter * -properties * | ? {$_,SIDHistory -like "*"} | foreach {Set-ADUser $_ -remove @{sidhistory=$_.sidhistory.value}}

Open in new window


This will find all of the user accounts with Sid History value and remove it from the account.

There is also another good function/cmdlet that was created called SID-History. This is another way to get the information you are looking for. Check the link below...

SID History

Will.
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.