Solved

I need a script to remove the "Unknown Accounts" SID history from accounts that have been migrated.

Posted on 2014-01-20
2
1,662 Views
Last Modified: 2014-01-21
We did a cross forest migration using ADMT tool.
I need a script to remove the "Unknown Accounts" SID history from accounts that have been migrated.

So, when I open the security tab on the property of any account we migrated, I see the following:

Account Unknown(S-1-5-21-etc
Account Unknown(S-1-5-21-etc
Account Unknown(S-1-5-80-etc

Please let me know.
Thank you
0
Comment
Question by:claudiamcse
2 Comments
 
LVL 4

Accepted Solution

by:
tmx84 earned 250 total points
ID: 39794631
0
 
LVL 53

Assisted Solution

by:Will Szymkowski
Will Szymkowski earned 250 total points
ID: 39794664
You can use powershell to accomplish this. Use the below syntax...

import-module activedirectory
Get-ADUser –filter * -properties * | ? {$_,SIDHistory -like "*"} | foreach {Set-ADUser $_ -remove @{sidhistory=$_.sidhistory.value}}

Open in new window


This will find all of the user accounts with Sid History value and remove it from the account.

There is also another good function/cmdlet that was created called SID-History. This is another way to get the information you are looking for. Check the link below...

SID History

Will.
0

Featured Post

Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Following basic email etiquette rules will help you write a professional email and achieve a good, lasting impression with your contacts.
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
In this video we show how to create a Resource Mailbox in Exchange 2013. We show this process by using the Exchange Admin Center. Log into Exchange Admin Center.: Navigate to the Recipients >> Resources tab.: "Recipients" is our default selection …
how to add IIS SMTP to handle application/Scanner relays into office 365.

920 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

11 Experts available now in Live!

Get 1:1 Help Now