RE: Local Group memberships

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Frances [MSFT] (v-franhe_at_microsoft.com)
Date: 03/03/05


Date: Thu, 03 Mar 2005 13:29:13 GMT

Hello,

Good to hear from you.

According to your message, I understand you want to migrate builtin group
membership from NT to win2k3 domain.

Built-in accounts (such as Administrators, Users, and Power Users) cannot
be ADMT migration objects. Because built-in account SIDs are identical in
every domain, migrating these accounts to a target domain results in
duplicate SIDs in a single domain. Every SID in a forest must be unique.

If you want to add a user who is member of account operators in Windows NT
to the account operator group in windows 2003. You have two methods.

I assume the user is already migrated to win2k3 domain using ADMT user
migration wizard.

1. Manually add the user to the "account operator" group.

2. Using script.
1) Export the membership from NT domain to a .txt file.
Use Showmbrs to export the membership of group "server operators".
You will have the following formats:
Domain1\User1
Domain1\User2

2) Modify the .txt file to the format "dsmod group" desire.

Refer to the following article for the syntax of the command.

Dsmod group
http://www.microsoft.com/windowsxp/home/using/productdoc/en/default.asp?url=
/windowsxp/home/using/productdoc/en/dsmod_group.asp

You may have to write a script to get the desired format.

3) Use "dsmod group" to add the membership to "account operator" group.

Since script is not supported in the newsgroup, I just give you the idea to
achieve your goal. Hope this helps.

If you have any questions or concerns regarding this issue, please do not
hesitate to let me know.

Best regards,

Frances He

Microsoft Online Partner Support
Get Secure! - www.microsoft.com/security

=====================================================

When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.

=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.



Relevant Pages

  • Re: Really bad table design...
    ... there could be two membership fees at the start of every year ... The balance forward system simply lists all these, ... > dues are paid once a year based a pre-set date for all board members. ... >> and account activity, ...
    (microsoft.public.access.tablesdbdesign)
  • Re: Computer Missing from AD
    ... Well, now that you've checked group membership, I assume we should wait and ... then look in the event log when/if any new computer account will be deleted. ... >>> 'Missing Computers Object in AD'. ...
    (microsoft.public.windows.server.active_directory)
  • Re: Pulling hair out - and there aint much left
    ... I can actually create a new user account on the remote system, ... to modify group membership for an existing or a new user I just created, ... > administrator's group on those machines? ... please advise what SID is.and how I would check this. ...
    (microsoft.public.win2000.networking)
  • Re: Changing group
    ... >captive account which would execute a utility to change their GROUP ... separating production from testing just through changing group membership. ... If your utility was an image that you installed in memory with cmkrnl privilege ...
    (comp.os.vms)
  • RE: local administrator on a domain controler...
    ... Account Operators (which can log on locally, Shut down the system and has ... including its own membership and that of the Server Operators. ... a service administrator because it can modify Server Operators, ...
    (microsoft.public.windows.server.active_directory)