RE: ADMT Hybrid Inter/Intra Forest Profile Issue

Tech-Archive recommends: Fix windows errors by optimizing your registry



Hi,

Frist, the profile new created issue is nothing related to the sidhistory.
Just considering that, is migration is succeed, the profile should be moved
to the new domain already, why they need sidhistory in such case? The
profile is new created because the security translation is failed. My
question is: When you finished migration to temp domain, have you tried to
logon to see if the profile will be recreated?


Best regards,

Vincent Xu
Microsoft Online Partner Support

======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================



--------------------
Thread-Topic: ADMT Hybrid Inter/Intra Forest Profile Issue
thread-index: Acaq7UHN/Ygoj+j3RTGC+HLr/VDffA==
X-WBNR-Posting-Host: 24.242.226.119
From: =?Utf-8?B?U2NvdHQgSi4gUGV0ZXJzb24sIE1DU0QsIE1DUFNCLCBNQ1Q=?=
<ScottJPetersonMCSDMCPSBMCT@xxxxxxxxxxxxxxxxxxxxxxxxx>
Subject: ADMT Hybrid Inter/Intra Forest Profile Issue
Date: Tue, 18 Jul 2006 21:39:01 -0700
Lines: 47
Message-ID: <AAA1A891-FC5F-4950-B059-8CBB326CCAD0@xxxxxxxxxxxxx>
MIME-Version: 1.0
Content-Type: text/plain;
charset="Utf-8"
Content-Transfer-Encoding: 7bit
X-Newsreader: Microsoft CDO for Windows 2000
Content-Class: urn:content-classes:message
Importance: normal
Priority: normal
X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
Newsgroups: microsoft.public.windows.server.migration
Path: TK2MSFTNGXA01.phx.gbl
Xref: TK2MSFTNGXA01.phx.gbl
microsoft.public.windows.server.migration:24481
NNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
X-Tomcat-NG: microsoft.public.windows.server.migration

Synopsis: We have two (2) domains in the same forest, Domain A and Domain
B.
Hundreds of users exist in both domains, via identical samAccountNames.
Users
bounce back and forth between using both accounts, etc. We are migrating
duplicate users from A (Source) to B (Target), and since they are in the
same
forest, we can't use ADMT directly, but in order to maintain the
sidHistory
(since sids can't exist in same forest), we are doing the following, in
general:

1. Migrating all users from Domain A to a Temp Domain (out of forest) (in
order to keep a sidHistory, but remove users to create in same forest)
2. Storing all user attributes from users in Domain A in a database (to
have
values to write later, such as title, phoneNumber)
3. Deleting all users from Domain A (so we can add sidHistory in same
forest)
4. Writing attributes from database to corresponding users in Domain B
(so
users data will be updated)
5. Migrating all users from Temp Domain to Domain B (to add sidHistory)
6. (Optionally, removing the sidHistory entry that was from Temp Domain,
maintaining only the entry from Domain A)

So, everything works, mail, security, shares, etc., everything related
directly to a sidHistory/security descriptor/acls. The sidHistory is
perfect
and all attributes seem correct. What DOESN'T work is the user's profile.
A
NEW profile always gets created when they log in. If we do a test, say,
NOT
going through the TEMP domain (via ADMT A to B where a duplicate doesn't
exist already of course) the Profile migrates perfectly. ONLY when we go
A-->TEMP--> does it have the issue.

Now I know people are thinking "something is getting stripped or
corrupted"
going through the TEMP domain, but ADMT works perfectly and a comparison
of
attributes on a user object appear identical, ESPECIALLY the sidHistory,
which we believe is the only thing a profile depends on. So, the question
is:
Why is it always creating a NEW profile even when the AD attributes are
correct, especially the sidHistory?

Another way to state this:
We have successfully migrated the sidhistory via the temp domain. That
works
perfectly. But, when the migrated user logs on, he receives a new
profile.
This is not the case when we migrate directly from source domain to
target
domain. It is only a problem when we migrate via the temp forest.

Is there something besides sidhistory that allows the user to maintain
the
profile on the computer?

BTW, no need to respond about using MoveTree or other processes, we have
been down every road...what I'm really hoping for is what we are missing
RE:
the profiles, or what we can do alternatively, realizing this is hundreds
of
users...


.



Relevant Pages

  • RE: ADMT Hybrid Inter/Intra Forest Profile Issue
    ... We are migrating the user and letting sidhistory (or some other ADMT ... Migrating all users from Temp Domain to Domain B ... What DOESN'T work is the user's profile. ...
    (microsoft.public.windows.server.migration)
  • RE: ADMT Hybrid Inter/Intra Forest Profile Issue
    ... "The profile is new created because the security translation is failed."? ... We'll test the profile in TEMP ASAP and give a status. ... the profile new created issue is nothing related to the sidhistory. ... Migrating all users from Temp Domain to Domain B ...
    (microsoft.public.windows.server.migration)
  • Kein Zugriff trotz SIDHistory
    ... 2000 AD in ein Windows Server 2008 AD. ... Memberserver W2k4: Daten und Profile ... Memberserver W2k8 Daten und Profile ... dass ich keinen Zugriff mit der SIDHistory auf ...
    (microsoft.public.de.german.windows.server.active_directory)
  • RE: AD SID History
    ... take hours for just one single server. ... This makes the migration easier and lets you spread out the ... Removing the SIDHistory should always be tested as if any of the security ... I want to install an W2K3 AD, ...
    (microsoft.public.windows.server.active_directory)
  • RE: ADMT Errors
    ... I understand that you fail to migrate sidhistory ... when migrating users with ADMT. ... How to Troubleshoot Inter-Forest sIDHistory Migration with ADMTv2 ... Microsoft Online Partner Support ...
    (microsoft.public.windows.server.migration)