Local Administrator account shows SID for domain members

Derek Chisholm 1 Reputation point
2020-09-22T17:50:16.663+00:00

I've seen this issue posted a handful of times but my issue seems to be unique compared to them.

On every virtual machine (Windows Server and Windows 10) in our domain, when viewing already present or adding users in the local administrators group, only account SIDs are listed. I've checked other local groups on them, like Remote Desktop Users, and they are listing the user names as expected; this only appears to affect the local administrators group.

A strange behavior I've discovered trying to troubleshoot this issue... If I add a domain user to another group on the computer, like Remote Desktop Users, and go back to the Administrators group, the user name is then listed. If I go back to the other group and remove that user, the user name is still listed in the Administrators group. Its like the Administrators group is unaware of user names until another group looks it up.

There are no domain related errors in Event Viewer, I'm able to lookup domain user names from SIDs from all affected machines, I've double and triple checked group policies aren't blocking translations, everything looks good.

Windows Server
Windows Server
A family of Microsoft server operating systems that support enterprise-level management, data storage, applications, and communications.
12,127 questions
Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,858 questions
{count} votes

2 answers

Sort by: Most helpful
  1. Dave Patrick 426.1K Reputation points MVP
    2020-09-22T19:40:03.023+00:00

    I'd check the domain controller and problem member both have the static ip address of DC listed for DNS and no others such as router or public DNS

    --please don't forget to Accept as answer if the reply is helpful--


  2. Hannah Xiong 6,231 Reputation points
    2020-09-23T02:40:17.847+00:00

    Hello,

    Thank you so much for posting here.

    According to our description, it sounds like DNS name resolution issue. Since only SIDs listed, the server is not able to resolve the user names from the domain. As Dave replied, we could run the commands to have a check of DNS configuration, DC and AD replication.

    Besides, as for our issue, we would like to know:

    1, Are all users from the same domain?

    2, All the member servers are affected?

    3, Is there duplication of VM? As per my research, someone had the similar problem due to duplication of VM. They did not sysprepped the additional VM. Once they sysprepped them, it solved the issue. We could kindly have a check about this.

    Similar case: https://social.technet.microsoft.com/Forums/ie/en-US/048cd9b2-5360-4873-bea6-c487aa61feb4/server-cant-determine-user-name-just-show-sid-and-then-disappear?forum=winserverDS

    4, Have we tried rejoin the computer to domain to see whether it could solve the issue?

    For any question, please feel free to contact us.

    Best regards,
    Hannah Xiong