Friday, November 06, 2009

The Machine SID Duplication Myth

I’ve been using NewSID for years, first with disk cloning and on the last years with VM images. And it comes as a great surprise for me that it’s okay to have duplicate machine SIDs!

According to Mark Russinovich:

This blog post debunks the myth with facts by first describing the machine SID, explaining how Windows uses SIDs, and then showing that - with one exception - Windows never exposes a machine SID outside its computer, proving that it’s okay to have systems with the same machine SID

The exception to the rule is quite obvious: domain controllers.

Oops. How can so many people (me included) be so wrong for so long?

