Glossary
SID filtering
SID filtering is a trust protection that strips foreign or privileged SIDs from authentication data crossing an Active Directory trust.
SID filtering (also called SID filter quarantining) is applied by the trusting domain's domain controllers when authentication arrives over a trust. It removes security identifiers from the incoming authorization data that do not belong to the trusted domain or forest, including SIDs carried in sIDHistory. Forest trusts filter by default, and external trusts created on modern Windows versions have quarantine enabled by default. Within a single forest, however, domains are not a security boundary and SID filtering is not applied between them.
It matters because without it, an administrator — or attacker — in a trusted domain can inject a privileged SID from the trusting domain, such as Enterprise Admins, and be granted that access across the trust. Keep SID filtering enabled on every external and forest trust, verify its state with netdom or PowerShell rather than assuming, and treat any request to disable it for a migration as a temporary, time-boxed exception. Pair it with selective authentication so trusted users can only reach explicitly permitted systems.
See SID filtering and selective authentication and Hardening AD trusts.