Active Directory – How to Change the SID of a User Account

active-directorysid

I accidentally deleted a user account, and need to recreate it with the same SID. I've created a new user account with the same name, but how do I edit the objectSid attribute? ADSIEDIT errors with "Access to the attribute is not permitted because the attribute is owned by the Security Accounts Manager (SAM)". Any other methods?

Best Answer

You can't. You have to do an authoritative restore of the user account in order to get a user back. Have a look at this Technet article.