Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations SkipVought on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

ADMT/sidHistory issues

Status
Not open for further replies.

unclerico

IS-IT--Management
Jun 8, 2005
2,738
0
0
US
I have a test environment set up with two 2003 forests;
abc.local and xyz.local. I have a two-way forest trust set up, I can perform all functions needed in both environments. I have migrated my groups, my users (disabled in this step), my profiles, my machines, and finally my users again (this time enabled and merged). All things are good, AD in my target domain is updated like it should be, profiles are translated like they should be. Everything is gravy, except I cannot access resources on the old domain. The ACL's on the resources are not set via well-known accounts (i.e. Domain Admins, Domain Users, etc.). I have verified that each user/group that was migrated has a sidhistory value via adsiedit. I have executed the following commands on both sides of the trust:
Code:
netdom trust <trustingdomain> /domain:<trusteddomain> /quarantine:no /usero:<username> /passwordo:*
I receive a response back saying that SIDFiltering is turned off
Code:
netdom trust <trusteddomain> /domain:<trustingdomain> /enabledsidhistory:yes
I receive back "Enabling SID history for this trust". I'm am totally stumped as to what else it could be. Anyone?
 
Ok, I solved the problem and it was a pretty easy one. First of all I had the syntax incorrect, it should be:
Code:
netdom trust <trustingdomain> /domain:<trusteddomain> /enablesidhistory:yes
I noticed that I could view the status of the sidhistory by simply omitting the flag from /enablesidhistory. Once I executed the command sans the flag, I found out that sid history was disabled for the trust. Executed the command the right way and bam, all is good in the hood.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top