The security IDs for built-in domain groups are filtered in Windows Server 2003 (893191)
The information in this article applies to:
- Microsoft Windows Server 2003, Enterprise Edition
- Microsoft Windows Server 2003, Standard Edition
SYMPTOMSAfter you migrate a built-in domain group, such as the Domain Users group or the Domain Admins group, while you are using security ID (SID) history, you receive the following error message: Access is denied. This symptom occurs if the following conditions are true: - You try to access a resource in a Microsoft Windows Server 2003 trusting domain.
- The resource that you try to access has permissions that are defined by using the built-in group that you migrated.
Note You cannot use the Active Directory Migration Tool (ADMT) version 2.0 to migrate SID history for built-in LOCAL groups or built-in domain global groups. Built-in LOCAL groups include the Administrators group, the Users group and the Power Users group. Built-in domain global groups include Domain Admins or Domain Users. The behavior with built-in domain local groups occurs because the built-in account SIDs are the same in every domain. Therefore, if you migrate these accounts to a destination domain, duplicate SIDs exist in the destination domain. However, while you cannot use ADMT version 2.0 to migrate SID history for built-in GLOBAL groups such as Domain Admins or the Domain users group, you can migrate the SID history by using either of the following methods: - Use a third-party tool such as NetIQ.
- Use the Sidhist.vbs Visual Basic script that is included with the ClonePrincipal Windows Server 2003 Support Tool.
CAUSEThis issue occurs if the following conditions are true: - The access token of a security principal from a trusted domain passes a SID that matches a SID in the local domain.
- That SID is the SID of a built-in group.
In this scenario, Windows Server 2003 removes this SID from the access token. This SID removal is known as SID filtering. In a migration scenario where the source domain is a Windows Server 2003 domain, users from a trusted domain cannot access resources in that source domain if those resources have only the following access control entries (ACLs) defined: Source_domain_name\built-in_group_name
Modification Type: | Major | Last Reviewed: | 2/24/2006 |
---|
Keywords: | kbenv kberrmsg kbhowto kbinfo KB893191 kbAudITPRO |
---|
|