Re: ADMT V2.0 NT4.0 -> Windows 2003

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Hi,

Thanks for your answers. They have helped me greatly. I just need to
understand a process.

So after the user and workstation accounts have been migrated with ADMT, the
user logs in with the same username and password with the new domain and his
old profile is present?
Do I need to manually change the domain membership of the workstation?

Thanks

Elvis

"Ulf B. Simon-Weidner [MVP]" wrote:

> Hello Elvis,
>
> > 1) When I use ADMT can the NT 4.0 domain be a different name to new AD domain?
>
> If you use ADMT the NT4 domain needs to be named differently than the new AD
> domain, you can not use the same name.
>
> > 2) When I transfer all user and computer account settings, what happens to
> > the desktop (windows XP). Do I still have to change its domain membership and
> > migrate its profile or is this automated with the ADMT?
>
> IIRC you can let ADMT translate the profiles when migrating the workstation and
> user.
>
> > 3) What happens to the User account (OLD SID) once the NT4.0 domain does not
> > exist?
>
> The old sid is kept in the sidhistory and will remain there until you clean it
> up. If you finished your migration and translated all permissions on files,
> shares, services, exchange, printers, ... to the new domain names you should
> clean up sidhistory.
> The existence of the old domain is not necessary for sidhistory to work. When a
> user logs on he's getting a token with SIDs for himself, his old SIDs in
> sidhistory, and SIDs of all groups he belongs to. When he's trying to access a
> ressource the computer verifies the access control entries on the ressource
> with the SIDs in the token provided. As soon he finds any matching he'll grant
> or deny the specified access. If you have a server which has not been reacled
> (replacing SIDs on the access entries of the old domain with the SIDs of the
> new domain) the user will get access because the resource has the old SID in
> the ACE and the user has the old SID in the sidhistory.
>
> > 4)How effective and stable is the ADMT provided the correct configurations
> > (trusts etc) have been established before using it?
>
> ADMT works very well, however you should gain some experience with it prior to
> running the migration in your production environment. Also make sure that you
> perform the migration as you intend to do it to figure out the right path for
> users, groups and computers to be migrated.
>
> Look at the new release of ADMT (ADMT v3) which is downloadable from MS since
> it provides new features and reliability especially if you don't have all
> computers connected and online in the network when you perform the migration.
> Also password migration has been made easier.
>
> Some infos and link to the download:
> http://msmvps.com/ulfbsimonweidner/archive/2005/10/04/69009.aspx
>
>
>
> --
> Gruesse - Sincerely,
>
> Ulf B. Simon-Weidner
>
> MVP-Book "Windows XP - Die Expertentipps": http://tinyurl.com/44zcz
> Weblog: http://msmvps.org/UlfBSimonWeidner
> Website: http://www.windowsserverfaq.org
>
.



Relevant Pages

  • RE: ADMT Errors
    ... I understand that you fail to migrate sidhistory ... when migrating users with ADMT. ... How to Troubleshoot Inter-Forest sIDHistory Migration with ADMTv2 ... Microsoft Online Partner Support ...
    (microsoft.public.windows.server.migration)
  • RE: SID History Clean Up
    ... By default, SIDHistory, password, and objectGUID are all preserved during ... For inter-forest migration, SIDHistory will be ... preserved if choosing 'Enable SIDHistory' in ADMT migration Wizard. ... For more information about how to use Visual Basic Script to clear ...
    (microsoft.public.windows.server.migration)
  • Re: ADMT V2.0 NT4.0 -> Windows 2003
    ... If you use ADMT the NT4 domain needs to be named differently than the new AD ... The old sid is kept in the sidhistory and will remain there until you clean it ... If you finished your migration and translated all permissions on files, ... user logs on he's getting a token with SIDs for himself, ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADMT V2.0 NT4.0 -> Windows 2003
    ... > So after the user and workstation accounts have been migrated with ADMT, ... >> The old sid is kept in the sidhistory and will remain there until you ... If you finished your migration and translated all permissions on ... >> user logs on he's getting a token with SIDs for himself, ...
    (microsoft.public.windows.server.active_directory)
  • Re: Error migrating users
    ... Windows2003 automaticlly block Access to the SidHistory Property for ... function for the migration process, ... "John" wrote in message ... There is a mention of domain names in CAPS but I am not sure if it is> relevant or how to get admt to work around it. ...
    (microsoft.public.windows.server.active_directory)