Monday, March 7, 2011

Verify sIDHistory and Identify the Source User Account

Here is a simple procedure which you can use to verify the sIDHistory and identify the corresponding source object.  

Step #1 – Get the sIDHistory of the migrated Object

You can use QSQuery command to generate the sIDHistory.  Here is an example. On the target domain, run the following command to get the sIDHistory value: 

dsquery * -Filter "(samaccountname=santhosh)" -Attr  sIDHistory

Step #2 – Compare this sIDHistory value against the source account. 

When a User object migrated from one domain to another, a new SID must be generated for the user account and stored in the ObjectSID property.  Before the new value is written to the property, the previous value (ObjectSID from source domain) is copied to another property of a User object, sIDHistory in the Target domain. So you can use the sIDHistory value to search the Source domain using the ObjectSID attributes to identify the corresponding user in the Source domain.  In other words, the sIDHistory value will be  equal to the source ObjectSID. 

So in the source Domain, you can perform a custom LDAP search using sIDHistroy  to identify the corresponding source object.  Here is an example:

[image[3].png]

The output of this LDAP query will be the corresponding object in the source domain. 

image_thumb29


Other Related Blogs and Articles:

Active Directory Migration Using ADMT - http://www.sivarajan.com/admt.html

Computer Migration - Things to Consider - http://www.sivarajan.com/cm.html

User Account Migration and Merging Using ADMT - http://www.sivarajan.com/

ADMT Include File - http://portal.sivarajan.com/2011/06/admt-include-file.html

User Migration and Input File Format - http://portal.sivarajan.com/2010/12/user-migration-and-input-file-format.html

ObjectSID Vs sIDHistory - http://sivarajan.com/forum/viewthread.php?tid=8

Identify SID Using DSQUEY Command - http://portal.sivarajan.com/2010/06/identify-sid-using-dsquey-command.html

PowerShell Script - Search Active Directory and Generate SIDHistory Report - http://portal.sivarajan.com/2010/12/powershell-script-search-active.html

SID Filtering – Access is denied - http://portal.sivarajan.com/2009/06/sid-filtering-access-is-denied.html

ADMT SID Mapping File Generation Using DSQUERY Command - http://portal.sivarajan.com/2011/04/admt-sid-mapping-file-generation-using.html

siDHistory Report - with Multi Value Support - http://portal.sivarajan.com/2011/04/sidhistory-report-with-multi-value.html

ObjectSID and Active Directory - http://portal.sivarajan.com/2011/09/objectsid-and-active-directory.html


0 comments:

Post a Comment

Popular Posts

Share

Twitter Delicious Facebook Digg Stumbleupon Favorites More