RE: 2003 to 2003 Cross Forest migration
- From: v-xuwen@xxxxxxxxxxxxxxxxxxxx (Vincent Xu [MSFT])
- Date: Thu, 15 Jun 2006 07:07:30 GMT
Hi,
You definitely have to run ADMT on target DC to migrate objects from source
domain. You also have to add the operation usrer account into the domain
admins group of both target domain & source domain.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================
--------------------
<FjsmZJ3jGHA.4688@xxxxxxxxxxxxxxxxxxxxx>Thread-Topic: 2003 to 2003 Cross Forest migration
thread-index: AcaPwhg9gRUi/kJ0Rg6grH9WHN+nfQ==
X-WBNR-Posting-Host: 66.162.54.194
From: =?Utf-8?B?UGxheno=?= <Plazz@xxxxxxxxxxxxxxxxxxxxxxxxx>
References: <24FF770F-FFEE-48AA-B8DC-6117FC940726@xxxxxxxxxxxxx>
microsoft.public.windows.server.migration:24061Subject: RE: 2003 to 2003 Cross Forest migration
Date: Wed, 14 Jun 2006 07:52:01 -0700
Lines: 107
Message-ID: <C0289328-DAB8-47A1-B091-F8CC3C88B86B@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.windows.server.migration
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
credentialsNNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.windows.server.migration
Hi,
Thanks for the assistance! Ok I have enabled the SID history on the
source DC and still get the error SID History couldn't be Updated
Coupleentered must have Admin privledges which it does on the source DC??
This isof more questions? Can you run ADMT from the source DC to the Target?
thewhat I'm currently attempting. Tried to run ADMT tool from a Member DC in
target domain but can't get permisions to setup any Domain admins from
/enablesidhistory:yessource? Any and all help is extremely appreciated. TIA
Plazz
"Vincent Xu [MSFT]" wrote:
Hi,
Yes, you have to disable SID filtering and enable SID history by using:
Enable SID history by running :
netdom trust trusted_domain /domain:trusting_domain
created
SID filtering is enabled automatically on any trust relationships
Serverby domain controllers running Windows 2000 Service Pack 4 or Windows
line2003. Or, you can manually enable it by using the Netdom trust command
SIDutility with the /EnableSIDHistory:no command line switch. To disable
imposefiltering (and thus enable SIDHistory), use the /EnableSIDHistory:yes
switch.
More information:
If even this level of SIDHistory accessibility is too much, you can
Quarantineeven stricter limits on your trust relationships by enabling the
processingfeature. (In this context, the Quarantine feature controls SID
Accessover trust relationships and shouldn't be confused with the Network
usedProtection or Network Access Quarantine Control technologies that are
forto control local and remote access connections.) By enabling Quarantine
enablinga trust relationship, you are specifying that only SIDs from the exact
domain on the other side of the trust are to be honored.In effect,
areQuarantine on a trust relationship will break the transitivity of that
trust, so that only the specific domains on either side of the trust
onconsidered participants in the trust. Quarantine is disabled by default
switch.all trust relationships; you can manually enable it by using the Netdom
trust command line utility with the /quarantine:yes command line
relationshipUse the /quarantine:no switch to disable Quarantine on a trust
sowhere it has already been enabled.
Hope this helps.
Best regards,
Vincent Xu
Microsoft Online Partner Support
======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader
rights.that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no
or======================================================
--------------------
microsoft.public.windows.server.migration:24049Thread-Topic: 2003 to 2003 Cross Forest migration
thread-index: AcaPIke4qqMuhidfRZ+7vpQsB8yB0g==
X-WBNR-Posting-Host: 66.162.54.194
From: =?Utf-8?B?UGxheno=?= <Plazz@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: 2003 to 2003 Cross Forest migration
Date: Tue, 13 Jun 2006 12:48:02 -0700
Lines: 8
Message-ID: <24FF770F-FFEE-48AA-B8DC-6117FC940726@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.windows.server.migration
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
NNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.windows.server.migration
Using ADMT Version 3 tool. Have 2 way trust setup. Can move the user
Source DCgroup
account but can not update SID History. Tool is being run from
believerecieving
SIDHistory cannot be updated. The credentials entered must have Admin
privlidges on the source domain which it does. My question is I
do
historyyou have to enable/disable SID filtering on the Domain trust for SID
to migrate?
.
- Follow-Ups:
- Re: 2003 to 2003 Cross Forest migration
- From: Jorge de Almeida Pinto [MVP]
- RE: 2003 to 2003 Cross Forest migration
- From: Plazz
- Re: 2003 to 2003 Cross Forest migration
- References:
- RE: 2003 to 2003 Cross Forest migration
- From: Vincent Xu [MSFT]
- RE: 2003 to 2003 Cross Forest migration
- From: Plazz
- RE: 2003 to 2003 Cross Forest migration
- Prev by Date: Re: DNS is not doing recursive queries
- Next by Date: RE: Unable to add domain admins from trusted domain to local admin
- Previous by thread: RE: 2003 to 2003 Cross Forest migration
- Next by thread: RE: 2003 to 2003 Cross Forest migration
- Index(es):
Relevant Pages
|
Loading