Entra ID objects have a SID (securityIdentifier attribute) beginning with "S-1-12-1-"
However, I've found traces of other prefixes:
* S-1-12-2-
* S-1-12-3-
* S-1-12-8-
Has anyone already seen this? 🔍
Seem to be related to special Entra ID envs like the GovCloud (GCC, FedRamp...)
Curiously there isn't a single identifier in AD, but rather a handful of unique ones.
There are two unique immutable IDs:
ObjectID
SecurityIdentifier
There are many unique IDs:
sAMAccountName
userPrincipalName
dN
servicePrincipalNames
proxyAddresses (maybe?)
hmmm, we use SecurityIdentifier to convert the LDAP binary of a SID to a readable identifier, it's odd that functionality isn't on non-Windows in .NET 5, since a Linux machine may be consuming AD-based LDAP, etc.