question

KacperGie-5063 avatar image
0 Votes"
KacperGie-5063 asked ·

Access Denied during SidHistory clone

Hi, I've got two domians in two forest: abc.local and contoso.xyz.local - bidirectional transitive trust between abc.local and xyz.local. I'm trying to make clone of sid for user TestUser from contoso.xyz.local to abc.local, using SidCloner.dll ([GreyCorbel.SidCloner]::CloneSid() - load assembly and use in Powershell). Everything works correctly in this direction. I've received "Access Denied" when I'm trying to do the same but in the opposite direction (from abc.local to contoso.xyz.local). To perform this operation I'm using domain admins user from both domains. I was try temporary grant full control for domain for each user but no result. Does anyone have any idea what else to check ? Thank you.

windows-active-directory
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

1 Answer

FanFan-MSFT avatar image
0 Votes"
FanFan-MSFT answered ·

Hi,
I found a article for this ,It seems we need to some requirements for the migration, just for your reference:
https://migration-blog.com/2013/11/05/how-to-write-or-migrate-sidhistory-with-powershell-2/

You may try use ADMT to migrate sidhistory.
Following links for your reference:
https://blog.thesysadmins.co.uk/admt-series-1-preparing-active-directory.html
https://docs.microsoft.com/en-us/previous-versions/windows/it-pro/windows-server-2008-R2-and-2008/cc974332(v=ws.10)
This response contains a third-party link. We provide this link for easy reference. Microsoft cannot guarantee the validity of any information and content in this link.
Best Regards,


·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.