![]() ![]() Also, this Group object in the Active Directory has an attribute called PrimaryGroupToken, which stores the RID for this group within the domain.īoth Windows NT and Lightweight Directory Access Protocol (LDAP) providers allow programmers to change a user's primary group by setting the PrimaryGroupID attribute value to the RID of a group that the user is a member of. A user's primary group can only be a group that exists in the same domain as the user, and this group has to be a group that the user is a member of. The primary group of a user is stored (as the group's RID in the user's domain) on the PrimaryGroupID attribute of a user object. ![]() ![]() Two of these components on the SID are the domain relative identifier (RID) and the RID specific to the object within the domain. The SID has several components, as described in the "SID Components" reference included in the "Reference" section of this article. ![]() More Information How the primary group is stored on a user object in the Active DirectoryĮvery security context object (such as users and security groups) in the Active Directory has a security identifier (SID) attribute associated with it. This article explains how to use native Active Directory Services Interface (ADSI) components to determine the primary group membership of a user. How to use native ADSI components to find the primary group Summary ![]()
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |