Can relative identifers (RID) in 2 different domains be same?


hello all,

i know user accounts on local machine or on domain can identified using security identifier (sid) since unique. 1 of important part of sid rid, relative each identifier authority value. question whether situation explained below can arise:

sub-domain identifier dev - 500

sub-domain identifier testing - 501

1. consider x machine part of 1 sub-domain dev , user test on machine x assigned sid s-1-5-500-1001

2. make settings machine x part sub-domain testing & logon using same user i.e. test.

here sub-domain identifier going different (501 in case), can rid same of rid in dev domain?


nikhil chudekar

on tue, 14 jun 2011 07:22:38 +0000, nikhil31 wrote:

i talking domain users.

if create 1 domain user sid s-1-5-500-1001 & if move machine 1 domain domain , create another

domain user there chances rid in sid of newly created domain user 1001?

domain accounts don't exist on member computers, exist in ad
database situation you're describing still can't happen.


paul adare
mvp - identity lifecycle manager
http://www.identit.ca
rom: ram after delicate operation.



Windows Server  >  Security



Comments

Popular posts from this blog

2008 Windows Deployment Server Properties Error

Can no longer user MS Update - Files required to use Microsoft Update are no longer registered

How do a find data in one file, search for it in another file and if not found, write a custom message to another file