Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Server > Active Directory > Foreign Security Principals

Reply
Thread Tools Display Modes

Foreign Security Principals

 
 
TPGBrennan
Guest
Posts: n/a

 
      03-16-2010

The documentation I can find shows that Authenticated Users should reside in
the cn=WellKnown Security Principals, cn=Configuration, dc=<forestRootDomain.
However, there is also an object named Authenticated Users in the
ForeignSecurityPrincipals containers. Because the documentation stated the
important Authenticated Users was in the WellKnown Security Principals
container we deleted everything int he ForeignSecurityPrincipal container; at
one time we had external trusts to two other domains and had more than 80,000
FSPs, those trusts are now long gone so we wanted to clean up AD. This broke
several apps and proved the Authenticated Users in the
ForeignSecurityPrincipals container was THE Authenticated Users object. Is
there any documentation explaining the relationship between these two
containers?
 
Reply With Quote
 
 
 
 
Paul Bergson [MVP-DS]
Guest
Posts: n/a

 
      03-17-2010
Did this break apps for all users, or only for users that were migrated to
this domain (Or a machine that was migrated)? This sounds like some type of
a sidHistory issue and the Authenticaetd Users within the FSP was for the
migrated users or a workstation/server that holds the data.

--
Paul Bergson
MVP - Directory Services
MCITP - Enterprise Administrator
MCTS, MCT, MCSE, MCSA, MCP, Security +, BS CSci
2008, Vista, 2003, 2000 (Early Achiever), NT4
Microsoft's Thrive IT Pro of the Month - June 2009

http://www.pbbergs.com

Please no e-mails, any questions should be posted in the NewGroups. This
posting is provided "AS IS" with no warranties and confers no rights.
"TPGBrennan" <> wrote in message
news:731F8C98-3CAB-468D-A91C-...
> The documentation I can find shows that Authenticated Users should reside
> in
> the cn=WellKnown Security Principals, cn=Configuration,
> dc=<forestRootDomain.
> However, there is also an object named Authenticated Users in the
> ForeignSecurityPrincipals containers. Because the documentation stated
> the
> important Authenticated Users was in the WellKnown Security Principals
> container we deleted everything int he ForeignSecurityPrincipal container;
> at
> one time we had external trusts to two other domains and had more than
> 80,000
> FSPs, those trusts are now long gone so we wanted to clean up AD. This
> broke
> several apps and proved the Authenticated Users in the
> ForeignSecurityPrincipals container was THE Authenticated Users object.
> Is
> there any documentation explaining the relationship between these two
> containers?



 
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
17 repeatedly offered updates not installing Cheshire Windows Update 2 02-28-2010 04:59 AM
Problems with installation of security update kb969615 andersbp Windows Update 14 02-14-2010 05:12 PM
Updates were unable to be successfully installed wjousts Windows Update 6 01-30-2010 04:01 PM
"Some updates could not be installed" Antnee20x Windows Update 7 12-18-2009 07:01 PM
Can download updates, but will not installs Peter Windows Update 4 11-16-2009 01:30 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59