Link to home
Create AccountLog in
Avatar of jskfan
jskfanFlag for Cyprus

asked on

Active Directory Group SID

Active Directory Group SID

I have read online that SID  and GUID  are created whenever you create new object in Active Directory.
SID is only unique in its Domain , GUID unique in its forest and even world wide.
Not sure how GUID uniqueness is controlled world wide ?

For SID if it is user object and it is moved out of the domain, its SID will change.

What about the SID related to user Group, will that be changed if it is moved to another Domain ?

Thank you
ASKER CERTIFIED SOLUTION
Avatar of Michael B. Smith
Michael B. Smith
Flag of United States of America image

Link to home
membership
Create a free account to see this answer
Signing up is free and takes 30 seconds. No credit card required.
See answer
It doesn't matter of object class (user, group etc).
Object's SID is based on domain's SID + object's RID in current domain, and the object's SID will change when moving object to another domain
Object's previous SID is stored in SIDhistory attribute on object.
Avatar of jskfan

ASKER

Thank you