Cannot resolve SID names in ACLs

B

bridget sullivan

Currently our ~300 user domain is in mixed mode, recently migrated from NT4.
We have two AD servers (one upgraded and one clean install), a Win2k member
file server and 3 NT4 BDCs (among other NT4 and Win2k member servers). When
we view the share and directory permissions on the Win2k file server
(member), only the SID account shows up on the ACL, not the actual group
name or user name. This is making it extremely difficult to view or
troubleshoot permissions problems. We are also preparing for Exchange 2000
and have installed the Active Directory Connector from Exch2k SP3 which is
running on user-mailboxes and custom-contacts, not DL-groups. Has anyone
seen this and found a resolution? I also noticed that when I open ADUC and
view Foreign Security Principals, there are two entries: one group for
everyone and a group that only has a SID and when I double click it
generates a pop up error "The object name cannot be show in its
user-friendly form. This can happen if the object is from an external domain
and that domain is not available to translate the object's name or the
object no longer exists on that domain. We only have a single forest, domain
etc.

I found this article, but it does not quite address the same problem as it
is happening to all of our groups and users.

http://support.microsoft.com/default.aspx?scid=kb;en-us;271959

Thanks for any help!

Bridget
 
M

Matjaz Ladava [MVP]

Can you verify, that your nameresolution works on your Windows 2000 server ?
What is your DNS configuration ? Do you have a reverse-lookup zone in your
DNS server ? Are you using only internal DNS server on your servers/clients.
Please run dcdiag and netdiag on your DC's to get a AD status report.

--
Regards

Matjaz Ladava, MCSE (NT4 & 2000), MVP
(e-mail address removed)
http://ladava.com
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top