Duplicate entries for the target account appear on the ACL after security is translated. (NETIQKB13885)

  • 7713885
  • 02-Feb-2007
  • 17-Oct-2007

Resolution

fact
Domain Migration Administrator 7.1

symptom
Duplicate entries for the target account appear on the ACL after security is translated.

cause
This is a known issue with accounts that have been migrated with SID History. The source and target accounts actually have two different SIDs, but the Windows 2000 operating system resolves them as both belonging to the targer domain, ie. target_domain\user_acct.

fix

 All access for these users, both source and target, will remain intact. If the account was migrated without SID history, it will appear in the ACL as source_domain\userx and once security was translated, you should see target_domain\userx.

Please refer to Microsfot KB Article: 307521 - An Access Control Entry May Seem to Be Displayed Incorrectly with the sIDHistory Attribute for more information.

The only way to show the account as source instead of target is to remove the SIDHistory or view the ACL from an NT machine.



note

Please contact Technical Support to create a 'Support Request' for any issues you encounter that are not addressed by the User Guide, any Knowledge Base articles found on the website, or current Hotfixes available for download.



Additional Information

Formerly known as NETIQKB13885