| Previous | Next |
| ERROR_DS_NO_CHECKPOINT_WITH_PDC | ERROR_DS_CANT_CREATE_IN_NONDOMAIN_NC |
ERROR_DS_SOURCE_AUDITING_NOT_ENABLED
Source-side account-management auditing is mandatory
The SID-history API verifies auditing in the source as well as the destination. Source auditing provides evidence that the original account SID was read and used in a migration. For older source domains, the operation generates recognizable membership changes through a specially named local group so administrators can identify each use.
Check effective success and failure auditing for account management on the source PDC or PDC emulator selected for the operation. Verify the required source audit group and transport prerequisites when the documented legacy workflow applies. Confirm events can be written before retrying. Treat the failure as a security control: directly copying a SID value would bypass the audit trail and the authenticated RPC/LDAP protections of the supported API.
What to inspect
- Verify source account-management audit policy is effective.
- Check the source PDC Security log and required audit group.
- Confirm the migration uses the documented protected API path.
References
- Microsoft: source auditing and audit-group requirements
- Microsoft: privileged account change controls
- MS-ADTS: SID and principal terminology
Looking for a different code? Search another status or error code.