Re: ADMT v3 - can't migrate SID history



it is not possible to make a user of domain A a member of a global group of
domain B

add target domain admins to source administrators

use an account in the target that is a member of domain admins in the
target.

in the target these are full permissions, but depending on the task
possibilties exist to delegate and minimize permissions as needed

--

Cheers,
(HOPEFULLY THIS INFORMATION HELPS YOU!)
# Jorge de Almeida Pinto #
BLOG --> http://blogs.dirteam.com/blogs/jorge/default.aspx
-----------------------------------------------------------------------------
* This posting is provided "AS IS" with no warranties and confers no rights!
* Always test before implementing!
-----------------------------------------------------------------------------


-----------------------------------------------------------------------------
"Herb Martin" <news@xxxxxxxxxxxxxx> wrote in message
news:uPkMgumEGHA.336@xxxxxxxxxxxxxxxxxxxxxxx
> "TimS" <TimS@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:1FF4B74D-D75A-48DE-87E7-320F1C480D4A@xxxxxxxxxxxxxxxx
>>I am doing an inter-forest migration - Both the source and destination
>> domains are Windows 2003 running in 2000 native mode. I have a two-way
>> trust
>> established. I am attempting to test-migrate a few groups, and I'm
>> selecting
>> to migrate the SID History. It prompts me for a user with administrative
>> permissions in the source domain, and I enter an account that is a member
>> of
>> the source domain's Domain Admins group. I have tried this with a couple
>> different domain admin accounts, and I keep getting the following error:
>> ERR2:7447 SID History cannot be updated for test-jax2. The credentials
>> entered (VOJAX\\jaxadmin) must have Administrator privileges on the
>> source
>> domain.
>
> Are there really two backslashes there?
>
> NetBIOS domain\user names use one backslash: DomainName\UserName
>
>> What could be wrong here? What permissions are needed to bring over the
>> SID
>> history?
>
> You have a trust, why not just make the admin for target a member of
> Domain Admins on the source?
>
>
> --
> Herb Martin, MCSE, MVP
> Accelerated MCSE
> http://www.LearnQuick.Com
> [phone number on web site]
>
> "TimS" <TimS@xxxxxxxxxxxxxxxxxxxxxxxxx> wrote in message
> news:1FF4B74D-D75A-48DE-87E7-320F1C480D4A@xxxxxxxxxxxxxxxx
>>I am doing an inter-forest migration - Both the source and destination
>> domains are Windows 2003 running in 2000 native mode. I have a two-way
>> trust
>> established. I am attempting to test-migrate a few groups, and I'm
>> selecting
>> to migrate the SID History. It prompts me for a user with administrative
>> permissions in the source domain, and I enter an account that is a member
>> of
>> the source domain's Domain Admins group. I have tried this with a couple
>> different domain admin accounts, and I keep getting the following error:
>> ERR2:7447 SID History cannot be updated for test-jax2. The credentials
>> entered (VOJAX\\jaxadmin) must have Administrator privileges on the
>> source
>> domain.
>>
>> What could be wrong here? What permissions are needed to bring over the
>> SID
>> history?
>>
>> Thanks,
>> Tim
>
>


.



Relevant Pages

  • Re: How to change domain administrator to limited/restricted user?
    ... Depending on the number of users, computers, member servers and the rest of the infrastructure, I might be tempted to start over. ... If it's "a" domain administrator, then remove the user from the ... Are the individual users direct members of the Domain Admins group or members of a group added to the Domain Admins group. ... Check a workstation or two and see if the user is a member of the local workstation administrators group. ...
    (microsoft.public.windows.server.sbs)
  • Re: ADMT v3 - cant migrate SID history
    ... the administrator account in the target domain, and that I have added the ... > add target domain admins to source administrators ...
    (microsoft.public.windows.server.active_directory)
  • Re: Domain Admins Security Group Message In Backup
    ... Are you logging in as *the* built-in Administrator account? ... How does your Member Of: ... > says that I do not have access and must be in the Domain Admins Security ... I am logged in as the Server Administrator and it has only just ...
    (microsoft.public.windows.server.sbs)
  • Re: Cant login locally to the server
    ... Administrator seems to be member of both Domain Admins and Administrators ... Check your SBS with the SBS Best Practices Analyzer ...
    (microsoft.public.windows.server.sbs)
  • local and domain administrator account
    ... someone logs on to a computer as the administrator and the computer is ... a member of a domain, the user will have complete access to all ... Administrator account from the Domain Admins (and Enterprise Admins) ...
    (microsoft.public.win2000.security)