SCOM and local sid for agent ,MS and gateways

Moataz Shaaban 1 Reputation point
2020-11-16T10:03:22.013+00:00

Hello,
While deploying SCOM servers,I found that all serves related to SCOM management servers, gateways and some agents are having the same local SID, is it possible it causes problems.

keep in mind some agents have the same SID as the management servers,also gateways are in different forest without trust so we are using certificate

In all these cases can we have any issue due to duplicate SID

Operations Manager
Operations Manager
A family of System Center products that provide infrastructure monitoring, help ensure the predictable performance and availability of vital applications, and offer comprehensive monitoring for datacenters and cloud, both private and public.
1,413 questions
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Leon Laude 85,651 Reputation points
    2020-11-16T11:30:50.92+00:00

    Hi @Moataz Shaaban ,

    What local SID are you referring to exactly? As long as the computer's GUIDs are not the same you should be fine.

    ----------

    (If the reply was helpful please don't forget to upvote or accept as answer, thank you)

    Best regards,
    Leon

    0 comments No comments

  2. Moataz Shaaban 1 Reputation point
    2020-11-16T11:32:44.037+00:00

    I mean computers machine Security Identifier (machine SID)


  3. Moataz Shaaban 1 Reputation point
    2020-11-16T11:39:25.033+00:00

    What about securing communication between gateway and SCOM management servers ?


  4. SChalakov 10,261 Reputation points MVP
    2020-11-16T16:03:54.077+00:00

    Hi @Moataz Shaaban ,

    You need to find the reason for the SID being duplicated accross your environment. One of the most common reasons is that the image has not been generalized.
    Now to your actual question: Is this a problem and is this a problem for SCOM?

    the answer to the second question is - "Most probably not". This can also be the answer to the first question, but it depends on other factors too. My sencere recommendation is to read the following blog post, wrtitten by Mark Russinovich and in particular the section "SID Duplication":

    The Machine SID Duplication Myth (and Why Sysprep Matters)
    https://techcommunity.microsoft.com/t5/windows-blog-archive/the-machine-sid-duplication-myth-and-why-sysprep-matters/ba-p/723859

    here you will find also more detailed info on SIDs:

    Security Identifiers - MS Docs

    When exactly a SID duplication can be a problem is described in the firts reference I've posted, but It is still very important that you indentify the source of the issue and ensure that the rest of the computers in your environments are installed from generalized (syspreped) image!

    I hope I could help!

    ----------

    (If the reply was helpful please don't forget to upvote or accept as answer, thank you)
    Regards,
    Stoyan

    0 comments No comments