Article ID: 893191 - Last Review: November 5, 2009 - Revision: 5.0 The security IDs for built-in domain groups are filtered in Windows Server 2003SYMPTOMSAfter you migrate a built-in domain group, such as the Domain Users group or the Domain Admins group, while you are using security ID (SID) history, you receive the following error message: Access is denied.
CAUSEThe SID filtering mechanism was changed between Microsoft Windows 2000 and Windows Server 2003. In Windows 2000, turning off SID filtering on a trust turns it off for all SIDs.
In Windows Server 2003, SID filtering cannot be turned off for built-in groups, even if it is turned off on the trust.
This issue occurs if the following conditions are true:
Source_domain_name\built-in_group_name To use the SID history between domains, you must enable the SID filtering to allow for the trust between the source domain and the resource domain.
If you disable the SID filtering for a trust, there are security implications that are described in Microsoft Security Bulletin MS02-001.
To reduce the security implications caused by disabling the SID filtering, the behavior of the SID filtering has changed between Windows 2000 Server and Windows Server 2003. In Windows 2000 Server, the SID filtering functionality is either enabled or disabled for all SIDs on a particular trust. Additionally, the built-in group SIDs are not filtered when the SID filtering is disabled. In Windows Server 2003, the SID filtering can be enabled or disabled on specified trusts. However, the built-in SIDs from outside the domain are always filtered out. MORE INFORMATIONBuilt-in groups are also known as "well-known" groups. For more information about migrating accounts while you are using SID history, visit the following Microsoft Web site: http://technet2.microsoft.com/windowsserver/en/library/044de91e-0cdf-480e-83e6-3be53f3cfb781033.mspx
(http://technet2.microsoft.com/windowsserver/en/library/044de91e-0cdf-480e-83e6-3be53f3cfb781033.mspx)
For more information about migrating accounts without using SID history, visit the following Microsoft Web site:http://technet2.microsoft.com/windowsserver/en/library/cea85aee-f4bb-4b2d-b457-97cb118da7251033.mspx
(http://technet2.microsoft.com/windowsserver/en/library/cea85aee-f4bb-4b2d-b457-97cb118da7251033.mspx)
For more information about on the security implications of using the SID history for access control, visit the Microsoft Security Bulletin MS02-001 at the following Microsoft Web site:http://www.microsoft.com/technet/security/bulletin/MS02-001.mspx
(http://www.microsoft.com/technet/security/bulletin/MS02-001.mspx)
The third-party products that this article discusses are manufactured by companies that are independent of Microsoft. Microsoft makes no warranty, implied or otherwise, regarding the performance or reliability of these products.
| Article Translations
|
Back to the top
