Hi,
How are you?
I am writing to see if you have any update about this post. If my
suggestion is helpful or you
have solved this ssue, please feel free to let me know.
Sincerely
Morgan Che
Microsoft Online Support
Microsoft Global Technical Support Center
Get Secure! -
www.microsoft.com/security
=====================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others may learn and benefit from your issue.
=====================================================
This posting is provided "AS IS" with no warranties, and confers no rights.
--------------------
--->X-Tomcat-ID: 74848826
--->References: <eMdjy1dmGHA.1552.RemoveThis@TK2MSFTNGP04.phx.gbl>
<thomasdietrich.39o13f.RemoveThis@DoNotSpam.com>
--->MIME-Version: 1.0
--->Content-Type: text/plain
--->Content-Transfer-Encoding: 7bit
--->From: v-morche.RemoveThis@online.microsoft.com (Morgan che(MSFT))
--->Organization: Microsoft
--->Date: Tue, 20 May 2008 07:53:24 GMT
--->Subject: Re: ADMT V3 has no right to migrate computers account from NT4
to 2003
--->X-Tomcat-NG: microsoft.public.windows.server.migration
--->Message-ID: <kuOaY6kuIHA.1788.RemoveThis@TK2MSFTNGHUB02.phx.gbl>
--->Newsgroups: microsoft.public.windows.server.migration
--->Lines: 125
--->Path: TK2MSFTNGHUB02.phx.gbl
--->Xref: TK2MSFTNGHUB02.phx.gbl
microsoft.public.windows.server.migration:3632
--->NNTP-Posting-Host: TOMCATIMPORT3 10.201.220.210
--->
--->Hi,
--->
--->Thanks for posting here.
--->
--->< I cannot logon to my Target DC using credentials from the Source
domain.
--->It complains that "The local policy of this system does not permit you
to
--->logon interactively">
--->
--->[Morgan]:
--->
--->To avoid "The local policy of this system does not permit you to logon
--->interactively" message, please perform the below steps:
--->
--->1. Please log on the problematic computer. Click Start and choose Run.
--->
--->2. Type "gpedit.msc" and click OK.
--->
--->3. In the "Group Policy" window, double click on "Windows Settings"
under
--->"Computer Configuration".
--->
--->4. Double click on "Security Settings".
--->
--->5. Double click on "Local Policies" and choose "User Rights Assignment".
--->
--->6. In the right panel, double click on the "Allow log on locally"
policy.
--->Please add the migrated user account and reboot the computer
--->to test the result.
--->
--->If the "Allow log on locally" policy is grayed out, it probably
inherits
--->from Domain or OU policy. Please modify "Allow log on locally" policy
on
--->the domain or OU where you define this policy.
--->
--->< if I logon to the Target DC as a user from the Target domain, then
logon
--->completed, but I get errors when trying to migrate.>
--->
--->[Morgan]:
--->
--->To further assist on this issue, please send me the migration log file
via
--->v-morche@microsoft.com . If there is any error message in Event log,
please
--->send me together.
--->
---><I've found that the "net local group administrators Target\UserID
/add"
--->worked in testing, but how I can get this command on every workstation
in
--->the source domain?>
--->
--->[Morgan]:
--->
--->We don't need to run this command on every workstation. In a domain
--->environment, by default, the domain admin belongs to local
administrator
--->group on member workstation. We just need to add a target Domain Admin
user
--->account to the Administrators of local built-in group in the source
domain,
--->when we log into the target server using this Domain Admin account from
the
--->target domain, we will have the corresponding permissions to 'move'
between
--->the target and source domain.
--->
---><I've already added Target\Domain Admins, and Target\UserID to the
--->Source\BuiltIn\Administrators group, but that didn't work.>
--->
--->[Morgan]:
--->
--->I recommend you refer to the following article firstly. To successfully
--->migrate computer account, not only we should grant the corresponding
--->permissions, but should we also perform other tasks, such as opening
audit,
--->enabling TcpipClientSupport etc.
--->
--->ADMT v3 Migration Guide
--->http://www.microsoft.com/downloads/details.aspx?familyid=D99EF770-3BBB-4
B9E-
--->
--->A8BC-01E9F7EF7342&displaylang=en
--->
--->Hope this helps. If anything is unclear, please post back.
--->
--->
--->Sincerely
--->Morgan Che
--->Microsoft Online Support
--->Microsoft Global Technical Support Center
--->
--->Get Secure! -
www.microsoft.com/security
--->=====================================================
--->When responding to posts, please "Reply to Group" via your newsreader
so
--->that others may learn and benefit from your issue.
--->=====================================================
--->This posting is provided "AS IS" with no warranties, and confers no
rights.
--->
--->
--->--------------------
--->--->From: thomasdietrich <thomasdietrich.39o13f.RemoveThis@DoNotSpam.com>
--->--->Subject: Re: ADMT V3 has no right to migrate computers account from
NT4
--->to 2003
--->--->Date: Mon, 19 May 2008 21:44:03 +0530
--->--->Message-ID: <thomasdietrich.39o13f.RemoveThis@DoNotSpam.com>
--->--->Organization: Computer Help -
http://forums.techarena.in
--->--->User-Agent: vBulletin USENET gateway
--->--->X-Newsreader: vBulletin USENET gateway
--->--->X-Originating-IP: 66.195.135.194
--->--->References: <eMdjy1dmGHA.1552.RemoveThis@TK2MSFTNGP04.phx.gbl>
--->--->Newsgroups: microsoft.public.windows.server.migration
--->--->NNTP-Posting-Host: hostname.techarena.in 207.58.143.175
--->--->Lines: 1
--->--->Path:
TK2MSFTNGHUB02.phx.gbl!TK2MSFTNGP01.phx.gbl!TK2MSFTNGP02.phx.gbl
--->--->Xref: TK2MSFTNGHUB02.phx.gbl
--->microsoft.public.windows.server.migration:3625
--->--->X-Tomcat-NG: microsoft.public.windows.server.migration
--->--->
--->--->
--->I'm having similar trouble. I cannot logon to my Target DC using
--->credentials from the Source domain. It complains that "The local
--->policy of this system does not permit you to logon interactively".
--->However, if I logon to the Target DC as a user from the Target domain,
--->then logon completed, but I get errors when trying to migrate. I've
--->found that the "net localgroup administrators Target\UserID /add"
--->worked in testing, but how I can get this command on every workstation
--->in the source domain?
--->--->I've already added Target\Domain Admins, and Target\UserID to the
--->Source\BuiltIn\Administrators group, but that didn't work.
--->--->
--->--->Please advise,
--->--->Tom
--->
--->
--->--
--->thomasdietrich
--->------------------------------------------------------------------------
--->thomasdietrich's Profile:
http://forums.techarena.in/member.php?userid=49810
--->View this thread:
http://forums.techarena.in/showthread.php?t=540707
--->
--->http://forums.techarena.in
--->
--->--->
--->
--->
>> Stay informed about: ADMT V3 has no right to migrate computers account from NT4..