adconnectdump icon indicating copy to clipboard operation
adconnectdump copied to clipboard

Could not determine SID for ADSync user - cannot continue searching for masterkeys

Open johnmalone12 opened this issue 5 months ago • 0 comments

Thanks for the amazing work. My environment has a credential file for the service C:\Users<service-name>\AppData\Local\Microsoft\Credentials<cred-file> where I can read the master key guid. However, the master key file is located in C:\Users<service-name>\AppData\Roaming\Microsoft\Protect\S-1-5-21-...<master key guid> and not in C:\Users<service-name>\AppData\Roaming\Microsoft\Protect\S-1-5-80-...<master key guid>.

The master key in that location cannot be decrypted using the current application logic because the derived key is invalid.

What could be the issue? Why can I not see the directory Protect\S-1-5-80-... ?

P.S: I run the script with psexec otherwise I cannot see any credentials

johnmalone12 avatar Sep 05 '24 14:09 johnmalone12