RE: ADMT Permissions

Tech-Archive recommends: Fix windows errors by optimizing your registry




You need Domain Admin rights in the Source domain. If you run ADMT on a
server which is not a DC in the target domain then you can be more granular
with the permissions in the Target domain.

Granting the migration account Full Control of the OU to where you will
migrate the objects is sufficient. If you are migrating SIDs you need to
assign the permission Migrate SID History at the domain level of the Target
domain.

The account also needs to be a local Administrator of the server on which
you run ADMT. This is why if you run it on a DC it must be a Domain Admin.

To summarise these are the steps I take when setting up a migration.

- Create account in the Source domain and add to Domain Admins group in
Source.
- Grant this account Full Control of the target OU in the Target domain.
- Grant Migrate SID History permission to account in Target domain.
- Add account to local Administrators group of server running ADMT.
- Run ADMT in the context of this account.

Whether you need this type of granular control depends on your situation.
You could just add the account from the Source domain to the Administrators
group in the Target domain and do no more. But this is can be security
hazard as the domain admins from the Source domain can suddenly have domain
admin rights in the target domain. In a situation where you have say 20
domains migrating into one as I have seen this is a problem.

Best Regards
Joe Dunn MCSE



"markj" wrote:

Can you someone please define the exact permissions required to use the ADMT
for migrating users,groups and computers between forests?
Thanks.
.



Relevant Pages

  • RE: ADMT ver 3: ERR2:7816
    ... I was originally logging into the target server (with ADMT on it) using the ... source domain admin account, and this user account was a member of the local ... Although this source domain admin had ...
    (microsoft.public.windows.server.migration)
  • RE: ADMT Permissions
    ... You need Domain Admin rights in the Source domain. ... with the permissions in the Target domain. ... Granting the migration account Full Control of the OU to where you will ... This is why if you run it on a DC it must be a Domain Admin. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Server 2000 - 2003 Migration
    ... Password Export Server or the account that the Password Export Server Service ... group in the source domain and that the Password Export Service account can ... On the Target domain the account running the ADMT is the Domain admin for the ...
    (microsoft.public.windows.server.migration)
  • RE: MIgration Question
    ... The source domain must trust the target domain ... The user account that is running ADMTv2 had Administrator rights in the ... If the target domain is a Windows Server 2003 domain, ... Active Directory Migration Tool Overview ...
    (microsoft.public.windows.server.migration)
  • RE: MIgration Question
    ... migrate a global group with SID history, migrated one user account. ... starting user/group migration. ... The source domain must trust the target domain ... If the target domain is a Windows Server 2003 domain, ...
    (microsoft.public.windows.server.migration)