RE: The SID question?!



From my experience it's a fairly academic consideration. If you are
concerned, then run Sysinternals' NewSID on all of the desktops.

Though, there are more serious security concerns in the domain model. For
example, that of 'administrative shares' giving access to ANY HD on the LAN
when logged-on to any desktop as a Domain-Admin user.

--------------------------
"This is a wonderful computer. It''s 20yrs old and absolutely reliable.
And, in all that time it''s only had four mobos, six processors, two cases,
seven OS''s ...."


"UselessUser" wrote:

Hi,

We have a few computers in a workgroup that were cloned via Ghost from
bootfloppy. Ghostwalker etc was not used. I am trying to understand now we
are going to go down the domain route what exactly happens regarding the
SID's?

The computer from which the image was taken was joined to the domain and
then disjoined and rebooted before being ghosted. Once each machine is
ghosted it is joined to the domain. This does not seem to have caused any
problems.. I guess my main questions are:

Is there just one computer sid or is there a computer sid and a domain sid

If there is just one SID does this get changed when you join the domain etc
- (hence why my setup is working - and if this is the case how do local user
account ntfs permissions for example still work as surely the SID is not the
same?)

Does the SID problem only occur if I pulled down a image that was still
joined to a domain and then just rename the PC and then try to join? Getting
a bit confused about this topic as you can tell?
.



Relevant Pages

  • Re: Imaging with Ghost
    ... Most likely they where referring to the SID. ... The latest version of the deployment tools for ... > We are in the middle of deploying several HP desktops in our Win2k ... Rather than configuring software and settings on each one ...
    (microsoft.public.win2000.general)
  • Re: lost computer account
    ... I believe this is a sid problem. ... same Security Identifier and as far as the domain knows they are all ... Paul Bergson MCT, MCSE, MCSA, CNE, CNA, CCA ...
    (microsoft.public.windows.server.active_directory)
  • Re: lost computer account
    ... I did not walk the sid. ... > I believe this is a sid problem. ... > same Security Identifier and as far as the domain knows they are all ...
    (microsoft.public.windows.server.active_directory)
  • MVPs II: Back into the domain (and thread) using the same SID
    ... This involves an XP machine that has an SID created on a Win2K ... proper IP address, is getting the proper domain name suffix, but has ... the SID problem should go away. ... It's almost like I'm seeing that the SID doesn't belong to the user ...
    (microsoft.public.win2000.dns)
  • The SID question?!
    ... bootfloppy. ... Ghostwalker etc was not used. ... Is there just one computer sid or is there a computer sid and a domain sid ... Does the SID problem only occur if I pulled down a image that was still ...
    (microsoft.public.windowsxp.security_admin)