Hi,
I need to migrate 100 user accounts between two different Windows 2003
domains.
The domains belong to two different Windows 2003 Forest.
The source domain is managed by an outsourcer and we have only some
delegated task, such as create and manage domain user accounts and some group
accounts.
First of all, I created a lab environment.
Then I create two Windows 2003 forests that have each one two domains.
I do the following task:
1) create an external trust (two-way) between the two domains;
2) install the ADMT 3.0 on one domain controller of the destination domain;
3) create few user accounts in the source domain;
4) add the new user to the membership of certain global and domain local
groups in the source
domain. These groups are authorized to access to some file server that are
member server
in the source domain;
5) launch the ADMT 3.0 console in the domain controller of the destination
domain
6) choose the user accounts that I create on the 3rd step to migrate to the
destination domain.
Here begin the problems:
7) when I choose the "Migrate passwords" option it appear the following
message:
"Unable to establish a session with the password export server. Access is
denied."
So I select the "generate complex password for these users" option, and in
the next step
I select the following selections:
- Target same as source
- Migrate user SIDs to target domain
When I make the above selections, I receive the message:
"Could not verify auditing and TcpipClientSupport on domains. Will not be
able to migrate Sids. Access denied"
8) When I confirm the message I be able to continue but without the "Migrate
user SIDs to target domain" option selected.
Now, in the User Options screen of the ADMT User account Migration wizard, I
only select the "update user rights" and
deselect the "fix user's group memberships".
9) For the last step, I accepted the default option.
Results: I migrate the user accounts without the user memberships. The user
migrated are only
domain users of the domain destination.
Other Questions:
1) Do I need to launch the "ADMT User account Migration wizard" with a user
account
that have the correct user rights in the source domain?
2) How can I migrate the user password?
3) May I have to do other configuration in both domains?
4) Can I migrate only the user accounts from the source to the destination
domain with the right
user memberships, but leaving the account groups in the source domain?
Thank you very much for the help that can you give me and sorry for my bad
english.
Fr.


Reply With Quote

Bookmarks