Go Back   TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory
Become a Member!
Forgot your username/password?
Register Tags Active Topics RSS Search Mark Forums Read SiteMap

Tags: ,

Sponsored Links



Unknown SID in ForeignSecurityPrincipals...

Active Directory


Reply
 
Thread Tools Search this Thread
  #1  
Old 03-06-2009
Claude Lachapelle
 
Posts: n/a
Unknown SID in ForeignSecurityPrincipals...

Hi!

I identified a lot of SID contained in the ForeignSecurityPrincipals (from
others trusted domains), but I have somes for which I could not find them, do
they could came from other than "trusted" domains?

If not, could we delete them without problem?

I'm asking that since the Administrators group contain two of them
(finishing with -500, -512) and I would like to remove them (always getting
error message when enumerating that group).

Thanks.

Claude Lachapelle
Systems Administrator, MCSE
Reply With Quote
  #2  
Old 03-06-2009
Meinolf Weber [MVP-DS]
 
Posts: n/a
Re: Unknown SID in ForeignSecurityPrincipals...

Hello Claude,

If you remove a trust the old SIDs are not deleted there. You can delte them
manual if youa re sure they are not longer used. In your won domain there
are still some listed there starting with NTAuthority\xxx as readable name.
You can compare the complete shown SID with the objectSID to control if the
object belongs to your domain or a removed trusted domain. ADSIEdit.msc will
help you to find the correct objectSIDs used in your domain.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


> Hi!
>
> I identified a lot of SID contained in the ForeignSecurityPrincipals
> (from others trusted domains), but I have somes for which I could not
> find them, do they could came from other than "trusted" domains?
>
> If not, could we delete them without problem?
>
> I'm asking that since the Administrators group contain two of them
> (finishing with -500, -512) and I would like to remove them (always
> getting error message when enumerating that group).
>
> Thanks.
>
> Claude Lachapelle
> Systems Administrator, MCSE



Reply With Quote
Reply

  TechArena Community > Technical Support > Computer Help > Windows Server > Active Directory


Thread Tools Search this Thread
Search this Thread:

Advanced Search


Similar Threads for: "Unknown SID in ForeignSecurityPrincipals..."
Thread Thread Starter Forum Replies Last Post
Seagate Hdd unknown Flacos Hardware Peripherals 3 13-11-2009 05:05 PM
ForeignSecurityPrincipals aconti Active Directory 2 21-10-2009 12:23 PM
WMP 11 Unknown album/song(unknown file) krillar Windows Software 2 18-01-2008 10:59 PM
USB Hub - Unknown device Chris Windows XP Support 2 15-09-2007 03:10 PM
Translate ForeignSecurityPrincipals to user friendly names Santa Active Directory 3 10-04-2007 03:55 PM


All times are GMT +5.5. The time now is 09:11 PM.