Skip to content

Glossary

SID history

SIDHistory is an AD attribute that keeps an account's old security identifiers after migration so it retains access to legacy resources.

When a user or group is migrated between domains, it receives a new security identifier (SID). To avoid breaking access to resources still secured with the old SID, migration tools copy the previous SID into the object's sIDHistory attribute. At logon, the domain controller adds every SID in sIDHistory to the user's access token, so the account is treated as if it still held those identities. The attribute is meant to be temporary scaffolding until resource ACLs are re-permissioned.

It matters because any SID placed in sIDHistory grants its full privileges. An attacker who can write the attribute, or who forges a ticket carrying extra SIDs, can silently add the SID of a privileged group such as Domain Admins or Enterprise Admins in another domain. Leftover SID history from old migrations also makes permissions hard to reason about. Inventory accounts with non-empty sIDHistory, flag any entries that resolve to privileged or same-domain SIDs, re-permission resources, then clear the attribute and keep SID filtering enabled on trusts.

See Cleaning up SIDHistory and SID filtering and selective authentication.