Does Directory and Resource Administrator honor SID History? (NETIQKB30055)

  • 7730055
  • 02-Feb-2007
  • 19-Jun-2007

Resolution

goal
Does Directory and Resource Administrator honor SID History?

fact
Directory and Resource Administrator 6.x

fact
Directory and Resource Administrator 7.x

fix

No, Directory and Resource Administrator (DRA) does not honor SID History.  If an Assistant Admin account was migrated from an NT4 domain along with SID History the new account from the Windows 2000 domain must be associated with the ActiveViews.

For Example:

If an NT4 user is assigned as an Assistant Admin to an ActiveView, DRA stores the assignment using user's SID. When the NT4 account is migrated, the old SID from the NT4 domain is written to the SID History and the new account in the Windows 2000 domain receives a new SID. When the user logs in using the new Windows 2000 account, he/she will be identified by the DRA server using the new SID and DRA will not find any matching ActiveView assigned to the user with the new SID.

An Enhancement Request has been opened with Development to include this functionality in a future version of Directory and Resource Administrator.



Additional Information

Formerly known as NETIQKB30055