Title: Message

You can have collisions between a domain controller SID and a member server SID when two machines have duplicate SIDs and one is DCPROMO’d and the other is joined to the new domain. The error messages that are logged say something to the effect that the domain and the member server SIDs conflict. Darn confusing when you see it for the first time. I’ll see if I can dig out the exact text of the message.

 

Wook

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe
Sent: Wednesday, January 18, 2006 6:36 PM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] AD computer accounts being removed

 

Yep sorry, didn't intend to say it wasn't a good idea. At some point the list will catch up and my post that says that will show up. :)

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Desmond
Sent: Wednesday, January 18, 2006 8:39 PM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] AD computer accounts being removed

Dozen other reasons to run it. Not running sysprep is just a bad idea.

 

Thanks,
Brian Desmond

[EMAIL PROTECTED]

 

c - 312.731.3132

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of joe
Sent: Wednesday, January 18, 2006 8:11 PM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] AD computer accounts being removed

 

Well not really. The important SID in question is the Domain SID and that isn't duped. The domain doesn't care about the machine SID. It is still good practice to newsid the machines though.

 

If the accounts are disappearing it is one of two things

 

1. Someone is deleting it.

 

2. During the join process something fails and the computer deletes the object out. I don't recall the details of this but I do recall hearing it happen. It happens right after the failed join though, you don't have to wait for it. I have also heard other people who don't have enough rights report the account being disabled instead of deleted. I never verified personally either.

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Desmond
Sent: Wednesday, January 18, 2006 6:50 PM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] AD computer accounts being removed

NO NO NO NO NO BAD BAD BAD

 

You have to use sysprep. You’re getting duplicate SIDs here – bad.

 

Thanks,
Brian Desmond

[EMAIL PROTECTED]

 

c - 312.731.3132

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Aaron Visser
Sent: Wednesday, January 18, 2006 5:44 PM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] AD computer accounts being removed

 

Gary, Brian,

 

I do not use Sysprep on my images and have yet to come across any problems, but there may be one big difference with my images, before I ghost them or create the image I put the said machine into a workgroup and then create image.  After I have imaged a computer I log on and change the Computer Name reboot and then join the domain with the new computer name, should I be using Sysprep?

 

And Brenda I have experienced your problem but I have never noticed the accounts actually being out of AD, anyways most times for me a simple reboot works although I have had to actually ghost computers in order to rejoin the domain because I do not have any local accounts active on my computers in the school, makes it a little safer J but with that comes more work L

 

 

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brian Desmond
Sent: Wednesday, January 18, 2006 12:38 PM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] AD computer accounts being removed

 

Gary-

 

Are you implying you don’t sysprep your images?

 

Thanks,
Brian Desmond

[EMAIL PROTECTED]

 

c - 312.731.3132

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Garyphold
Sent: Wednesday, January 18, 2006 3:04 PM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] AD computer accounts being removed

 

Brenda,

 

FWIW:  It happens to me when I clone a workstation then try to join that workstation to the domain in order to change the computer name.  AD sees 2 machines with the same name, gives me a notification and lets the 2nd one in.  Then when the original machine with that name logs in next time, it isn't seen on the network.  Then I have to do the same thing you did - with the original machine.  Then all is well again.  Don't know if that will help, but it might narrow down the problem some.

 

Gary

 

Gary Polvinale

Denton ATD

 

 

-----Original Message-----
From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brenda Casey
Sent: Wednesday, January 18, 2006 2:24 PM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] AD computer accounts being removed

Yes, their computer account in AD is actually gone.

 

Thanks,

Brenda

 

Brenda Casey
Network Manager

Billings Public Schools

[EMAIL PROTECTED]

406-247-3792

 

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gil Kirkpatrick
Sent: Wednesday, January 18, 2006 11:14 AM
To: ActiveDir@mail.activedir.org
Subject: RE: [ActiveDir] AD computer accounts being removed

When you say "lose their account", do you mean the computer object in AD disappears? Or something else?

 

-g

 


From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Brenda Casey
Sent: Wednesday, January 18, 2006 10:42 AM
To: ActiveDir@mail.activedir.org
Subject: [ActiveDir] AD computer accounts being removed

Occasionally computers will lose their account in Active Directory for no apparent reason. Sometimes it is a computer that has just joined the domain, while other times the machine has been a member of the domain for 2 years.  The computer can only be logged on by a local account (not a domain account).  To remedy this, the computer has to be disjoined from the domain, join a workgroup, then join the domain again.  As I am sure you all are aware, this is not only time consuming, but very inappropriate to have to do.

 

 Has anyone else had this experience and how have you fixed it?

 

Thanks,

Brenda

Reply via email to