Re: Problem using ADMT to migrate computer accounts

From: Michael (nospam_at_nospam.no)
Date: 09/14/04


Date: Tue, 14 Sep 2004 18:10:35 +0200


Draco,

Sounds like your situation is the one I describe below:

DOMAIN1 (Source)
----------
DOMAIN1\Administrators contains DOMAIN1\Domain Admins (by default) and
DOMAIN2\Administrators (you put it there).

Workstations in DOMAIN1
----------
By default, WORK1\Administrators (the local administrators group on
workstations) will only contain global group DOMAIN1\Domain Admins, and NOT
the local group DOMAIN1\Administrators since it is impossible in NT 4.0 for
a local group to contain another local group.

Therefore:
----------
Simply by adding DOMAIN2\Domain Admins to DOMAIN1\Administrators does not
give access to the workstations. (DOMAIN1\Domain Admins does not contain
DOMAIN1\Administrators, it is the other way around). You can't give an
account from another domain administrative access to workstations at the
domain level, you have to add them to the local Administrators group to each
workstation.

If you run the ADMT console under the credencials of someone in
DOMAIN1\Domain Admins, you have access to all the workstations (unless
someone removed the Domain Admins group from Administrators in a
workstation).

Good luck, post if you need a better explanation.

Michael S.

<anonymous@discussions.microsoft.com> escribió en el mensaje
news:215901c49a69$9ead2f10$a401280a@phx.gbl...
> Below is a copy of the agent log. I do not know why it
> says that it can not find the computer, the client can
> see and access files on both the source PDC and the
> Target DC.
>
> 2004-09-14 10:22:41 Created account input file for remote
> agents: DCTCache.003
> 2004-09-14 10:22:41 Installing agent on 1 servers
> 2004-09-14 10:22:41 The Active Directory Migration Tool
> Agent will be installed on \\VLAD
> 2004-09-14 10:22:41 WRN1:7290 Processor architecture for
> machine \\VLAD is unknown, Error accessing registry key
> SYSTEM\CurrentControlSet\Control\Session
> Manager\Environment rc=5 Access is denied.
> 2004-09-14 10:22:41 ERR2:7006 Failed to install agent on
> \\VLAD, rc=5 Access is denied.
> 2004-09-14 10:22:41 ERR2:7005 Failed to launch agent on
> \\VLAD, hr=80070005 Access is denied.
> 2004-09-14 10:22:42 All agents are installed. The
> dispatcher is finished.
> >-----Original Message-----
> >Hello all,
> >
> >I have a problem using ADMT to migrate computer
> accounts.
> >I'm able to move groups, users, and the computer
> accounts
> >themselves but the client agents will not install. All I
> >get in the logs is "Access is denied". I double check
> the
> >trust and the source domain's admin group includes the
> >target's domain admin group. Liked I said before I'm
> able
> >to move the computer account itself but without the
> agent
> >installing I still have to manually join the client
> >computer to the new domain, and create user profiles on
> >the client for the new domain, then move the users
> >previous profile to the new. All this manual labor kind
> >of defeats the purpose of using the ADMT in the first
> >place. I wonder if any of you have seen this problem
> >before and know of a solution. Any comments of
> >suggestions will be appreciated. Thanks.
> >.
> >



Relevant Pages

  • Re: Migrate computer from NT domain to Win2K AD
    ... Workstations in DOMAIN1 ... workstations) will only contain global group DOMAIN1\Domain Admins, ... a local group to contain another local group. ... you have to add them to the local Administrators group to ...
    (microsoft.public.windows.server.migration)
  • Re: 2003 Domain Admins in NT4 Domain
    ... it seems that you only add the 2003\Domain Admins ... admin rights on a workstation in the NT4 domain. ... After adding these two groups into NT4's workstation's local Administrators ... >workstations are actually using a different DNS server. ...
    (microsoft.public.windows.server.migration)
  • Domain Global Groups in Workstation Local Admin Groups
    ... I want to create Global security groups, and populate the workstations local ... My problem is that I only want our functional software admins to have admin ...
    (microsoft.public.windowsxp.security_admin)
  • Re: Problem using ADMT to migrate computer accounts
    ... >workstations) will only contain global group DOMAIN1 ... \Domain Admins, and NOT ... >a local group to contain another local group. ... Administrators group to each ...
    (microsoft.public.windows.server.migration)
  • Re: Win2K / Netware networking question
    ... > blocking the access to the other admins. ... > rights in NDS to do it, and if I was ever asked to do that (and I ... the Remote Control app to be exclusively user-initiated? ... are we talking Win2k servers or workstations? ...
    (comp.security.misc)