After the entire migration has been completed, the ACL's for directories and shares on a migrated co (NETIQKB4322)

  • 7704322
  • 02-Feb-2007
  • 17-Apr-2008

Resolution

symptom
After the entire migration has been completed, the ACL's for directories and shares on a migrated computer contain unrecognized SID's, indicated by a question mark.

change
All domain controllers in the source domain have been decommissioned.

fix

Each unrecognized SID belongs to an account that is in the decommissioned source domain. Without a domain controller in the source domain, the SID cannot be resolved and therefore is indicated by a question mark.

The options that should be considered for removing these unrecognized SIDs at this point are:

  1. You can use the 'Translate Security Settings' wizard, with the 'Remove' option, to remove references to SIDs from the source domain. This wizard requires that a domain controller from the source domain be running in order to resolve the SIDs.
  2. If a source domain controller cannot be made available, then you can manually remove references to accounts from the source domain.
  3. If you are planning to remove these references, you may need to verify that none of your accounts are still accessing this resource via sidHistory.

 



note

The recommended practice for translating security in this scenario is to:

  1. After migrating users, groups, and computers, run the 'Translate Security Settings' wizard to translate security in Add mode.
  2. Verify that the new users have the correct access.
  3. While the source domain is still in operation, translate security again using the Remove option.
  4. If you have migrated any objects with SID History, run the 'Remove SID History' wizard.
  5. Verify that the new users have the correct access.
  6. Decommission the source domain.



Additional Information

Formerly known as NETIQKB4322