Re: Migration for NT 4.0 to Windows Server 2008 Domain Controller
- From: v-dashen@xxxxxxxxxxxxxxxxxxxx (David Shen [MSFT])
- Date: Tue, 16 Sep 2008 11:17:03 GMT
Hi Saji,
Sorry for my late reply.
According to my research, we can establish the trust relationship between
Windows NT4 to Windows 2008. Before we establish the trust, we need to
changes the security setting in one GPO that is shown below:
Make sure that the following settings are configured:
RestrictAnonymous and RestrictAnonymousSam:Network access: Allow anonymous
SID/Name
translation ENABLED
Network access: Do not allow anonymous enumeration of SAM accounts
DISABLED
Network access: Do not allow anonymous enumeration of SAM accounts and
shares
DISABLED
Network access: Let Everyone permissions apply to anonymous users
ENABLED
Network access: Named pipes can be accessed anonymously ENABLED
Network access: Restrict anonymous access to Named Pipes and shares
DISABLED
LM Compatibility:Network security: LAN Manager authentication level "LM &
NTLM
responses" or "Send LM & NTLM - use NTLMV2 session security if negotiated"
SMB Signing, SMB Encrypting, or both:Microsoft network client: Digitally
sign
communications (always) DISABLED
Microsoft network client: Digitally sign communications (if server agrees)
ENABLED
Microsoft network server: Digitally sign communications (always) DISABLED
Microsoft network server: Digitally sign communications (if client agrees)
ENABLED
Domain member: Digitally encrypt or sign secure channel data (always)
DISABLED
Domain member: Digitally encrypt secure channel data (when it is possible)
ENABLED
Domain member: Digitally sign secure channel data (when it is possible)
ENABLED
Domain member: Require strong (Windows 2000 or later) session key
DISABLED
For more reference, please refer to:
Trust between a Windows NT domain and an Active Directory domain cannot be
established or it does not work as expected
http://support.microsoft.com/?id=889030
Hope it helps.
David Shen
Microsoft Online Partner Support
.
- Follow-Ups:
- Re: Migration for NT 4.0 to Windows Server 2008 Domain Controller
- From: sajidaniel
- Re: Migration for NT 4.0 to Windows Server 2008 Domain Controller
- References:
- Re: Migration for NT 4.0 to Windows Server 2008 Domain Controller
- From: sajidaniel
- Re: Migration for NT 4.0 to Windows Server 2008 Domain Controller
- From: David Shen [MSFT]
- Re: Migration for NT 4.0 to Windows Server 2008 Domain Controller
- From: sajidaniel
- Re: Migration for NT 4.0 to Windows Server 2008 Domain Controller
- From: David Shen [MSFT]
- Re: Migration for NT 4.0 to Windows Server 2008 Domain Controller
- From: sajidaniel
- Re: Migration for NT 4.0 to Windows Server 2008 Domain Controller
- Prev by Date: Re: Using SQL for ADMT DB
- Next by Date: Using ADMT 3.0
- Previous by thread: Re: Migration for NT 4.0 to Windows Server 2008 Domain Controller
- Next by thread: Re: Migration for NT 4.0 to Windows Server 2008 Domain Controller
- Index(es):
Relevant Pages
|