Machines With Same SID Joined To A Domain
I know someone who is cloning machines and adding them to a domain with no SID changing method. They state that this is ok due to the article:http://technet.microsoft.com/en-us/sysinternals/bb897418.aspx. If they are not using removable media with NTFS permissions assigned to local machine user accounts are there any issues which could arrise due to joining multiple machines with the same SID to a domain. Thank You, GregP.S. Please also see:http://www.techtalkz.com/windows-server-2003/130251-local-sid-v-domain-sid.html
March 25th, 2009 11:10pm

hi there, it is not a recommended the ACL on any OS uses SID , grant or access permissions depends on ACL which inturn uses the SID , with SID the group membership will be determined. Any access token will be having SID packaged in it. so if you have 2 Similar SID its a threat with which many of the application might not work, so microsoft always recommend you to change the SID and there are many tools to change it .but many of the imaging solutions wont do this.Yes you can still run those clients with out any problem, but you might never know how it gets affected.Microsoft has written an win32 app to changeSID called "NewSID"utillity.sainath Windows Driver Development
Free Windows Admin Tool Kit Click here and download it now
March 26th, 2009 10:19am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics