Windows SID /TRANSLATION

Roberto Alomar 1 Reputation point
2020-11-19T19:42:32.607+00:00

Hello,

We still have Windows 2000 member server in a multi-domain network and since we upgraded all domains DC from Windows2016 to Windows2019 the W2K server can't translate SID to group/user friendly name. Any clues on this ?

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,431 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Vicky Wang 2,731 Reputation points
    2020-11-20T08:34:09.69+00:00

    This policy setting enables or disables the ability of an anonymous user to request security identifier (SID) attributes for another user.

    If this policy setting is enabled, a user might use the well-known Administrators SID to get the real name of the built-in Administrator account, even if the account has been renamed. That person might then use the account name to initiate a brute-force password-guessing attack.

    Misuse of this policy setting is a common error that can cause data loss or problems with data access or security.

    Best practices
    Set this policy to Disabled. This is the default value on member computers; therefore, it will have no impact on them. The default value for domain controllers is Enabled.
    Location
    Computer Configuration\Windows Settings\Security Settings\Local Policies\Security Options

    Hope this information can help you
    Best wishes
    Vicky

    0 comments No comments

  2. Vicky Wang 2,731 Reputation points
    2020-11-25T07:03:53.53+00:00

    Hi,

    Just checking in to see if the information provided was helpful.

    Please let us know if you would like further assistance.

    Best Regards,
    Vicky

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.