Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

? Mystery SID ?

Status
Not open for further replies.

xjbone

MIS
Jun 8, 2005
6
US
What is the best tool/ method of discovering, identifying and deleting orphaned SID's from AD?

While broswing account permissions on my Exchange mailboxes, I noticed the permissions of EVERY mailbox had a rogue account listed with Full Access- nothing listed but a SID.

I want to get rid of this ASAP, both because it's a security risk, and it's polluting my AD.

Thanks.
 
I tried the above tool, but it could not resolve the SID to a name. Any other ideas?
 
I don't know an awfull lot about Exchange so it might be worth posting in the Exxhange forum forum955, it looks like an account that had access to all of the mailboxes has been removed so Exchange can no longer resolve it.

You didn't say if you had any trusts in the past.
 
Yes, there was a temporary trust in place that has since been removed.
 
If you have access to the other domain still then run Obj/Sid there and see if it finds the account, my guess is that is was a user account from the trusted domain that can no longer be found now the trust is gone.
 
OK, I fired up the old DC (the trusting domain), which is now offline, but that still didn't identify the SID.

However, I did discover that the SID in question it the Local Admin account of the Exchange server. Once I completely removed this security account from the Exchange database itself, my mystery SID disappeared from every mailbox.

Thanks for the help!
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top