Sidhistory of Migrated Domain Local group

G-ONE 166 Reputation points
2021-01-31T11:10:56.797+00:00

Hello Tech Guys,

Let's consider if Domain Local group of Source Domain is migrated to Domain Local group of Target Domain with Sidhistory. It means Target Domain Local group sidhistory attribute having value: <Sid of Source Domain Local group>.

Target Domain user is member of Target Domain local group. Target Domain user login to Target Domain joined workstation.

So my question is:

What Sids will be showing in target user's access token?

Sid of target domain local group + Sidhistory both

OR

Only Sid of target domain local group

Please answer specific to question with Microsoft support article that validates the answer.

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
Windows for business | Windows Server | Devices and deployment | Set up, install, or upgrade
Windows for business | Windows Server | User experience | Other
{count} votes

Accepted answer
  1. Thameur-BOURBITA 36,261 Reputation points Moderator
    2021-01-31T12:22:20.94+00:00

    Hi,

    What Sids will be showing in target user's access token?

    The answer is Sid of target domain local group + Sidhistory both
    A Windows security token can hold a maximum of 1,023 sIDs, including sIDHistory and group sIDs.
    You can refer to the following article for more details:

    Using SID History to Preserve Resource Access
    inter-forest-sidhistory-migration-with-admt

    ----------

    Please don't forget to mark helpful reply as answer

    0 comments No comments

0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.