Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

You cannot delete a group in a Windows Server 2003-based domain


View products that this article applies to.

Symptoms

You cannot delete a group in a Windows Server 2003-based domain.

↑ Back to the top


Cause

This problem occurs because there is a conflict between objects that have the same objectSID value. Specifically, a Foreign Security Principal (FSP) object has a name that conflicts with another FSP object. When this problem occurs, the FSP code lets you manipulate only the older FSP object.

↑ Back to the top


Resolution

To resolve the problem, follow these steps:
  1. Use the LDP utility to rename the older object so that it has a new security identifier (SID).
  2. Delete the other conflicting object.
  3. Delete the original object that you renamed in step 1.

↑ Back to the top


Status

Microsoft has confirmed that this is a problem in the Microsoft products that are listed in the "Applies to" section.

↑ Back to the top


Keywords: KB948602, kbprb, kbtshoot, kbexpertiseinter

↑ Back to the top

Article Info
Article ID : 948602
Revision : 1
Created on : 3/4/2008
Published on : 3/4/2008
Exists online : False
Views : 249