When you use the Exchange Server Administrator program to view the properties of a server that is using KMS, you receive the "No mapping between account names and security IDs was done" error message (827213)



The information in this article applies to:

  • Microsoft Exchange Server 5.5


SYMPTOMS

When you use the Microsoft Exchange Server Administrator program to view the properties of a server that is using Key Management Service (KMS), you receive the following error message:
No mapping between account names and security IDs was done. Microsoft Windows NT ID no: 0xc0020534
Additionally, the following event messages may be logged in the Application log:
  • Event Type: Warning
    Event Source: MSExchangeKMS
    Event Category: None
    Event ID: 5257
    Description: KMS has failed processing a request from KMS admin "computer name\Administrator". It is likely that the KMS admin password was not entered correctly.
  • Event Type: Warning
    Event Source: MSExchangeKMS
    Event Category: None
    Event ID: 5258
    Description: KMS admin "computer name\Administrator" failed to get extended details.

CAUSE

This problem occurs if the KMS database contains a Microsoft Windows NT Security Identifier (SID) that is not mapped. An SID may not be mapped if the Windows NT user account that is associated with the SID has been deleted from the domain, but the SID still exists in the cryptographic service provider (CSP) database of KMS. Generally, this problem occurs if the Windows NT user account of a user who is a KMS administrator is deleted before the KMS Administrator permissions are removed from this user account.

MORE INFORMATION

Cumulative update information

To resolve this problem, obtain the November 2004 update rollup for Microsoft Exchange Server 5.5.

For more information, click the following article number to view the article in the Microsoft Knowledge Base:

841765 November 2004 Update Rollup for Exchange Server 5.5

Hotfix information

A supported feature that modifies the product's default behavior is now available from Microsoft, but it is only intended to modify the behavior that this article describes. Apply it only to systems that specifically require it. This feature may receive additional testing. Therefore, if the system is not severely affected by the lack of this feature, we recommend that you wait for the next Microsoft Exchange Server 5.5 service pack that contains this feature.

To obtain this feature immediately, contact Microsoft Product Support Services. For a complete list of Microsoft Product Support Services telephone numbers and information about support costs, visit the following Microsoft Web site: The English version of this hotfix has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time tool in Control Panel.
   Date         Time   Version            Size    File name
   --------------------------------------------------------------
   09-Sep-2003  11:48  5.5.2657.65     2,509,584  Admin.exe 
Note Because of file dependencies, this software update requires Microsoft Exchange Server 5.5 Service Pack 4. For more information, click the following article number to view the article in the Microsoft Knowledge Base:

191014 How to obtain the latest Exchange Server 5.5 service pack


Modification Type:MinorLast Reviewed:7/25/2006
Keywords:kbHotfixServer kbQFE kbHotfixServer kbQFE kbinfo kbQFE kbfix kbbug kbpubtypekc KB827213 kbAudITPRO