Welcome to ServerForumz.com!
FAQFAQ      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

ADMT migration/security translation

 
   Windows Server (Home) -> Windows Server Migration RSS
Next:  DNS migration in AD install  
Author Message
Tom

External


Since: Oct 01, 2004
Posts: 174



(Msg. 1) Posted: Fri Jul 21, 2006 12:19 pm
Post subject: ADMT migration/security translation
Archived from groups: microsoft>public>windows>server>migration (more info?)

Hello all,

Regarding Intra-Forest migration using ADMT, four small (i think) questions.
Any help appreciated.

1) We are trying to migrate a file server that is also a DC from one domain
to another with least work. I am thinking you must have at least one DC left
in the source domain to run a secuirty translation on a migrated
workstation/server. Also, the file server/domain controller would need to be
demoted to a member server first, migrated to new domain, and then run
security translation wizard. Sound correct? Any feedback appreicated.

2) If My Docs folder is redirected from local profile to a shared network
folder will migrated users need to adjust this redirection at all either
before or after file server is migrated?

3) Also,the SIDhistory will still work for access too when both file server
and user accounts are in target domain, correct?

4) Will security translation work on a server that has not been migrated via
ADMT if a SID mapping file is employed? Example, if NTbackup or other copy
program is used to copy file shares with original ACL from file server in
source domain to one in the target domain, can the ADMT "secuirty translation
wizard" (using a SID map file) be used to change the source acct ACLs to the
target acct ACLs?

Thank You.

 >> Stay informed about: ADMT migration/security translation 
Back to top
Login to vote
Vincent Xu [MSFT]

External


Since: Nov 24, 2005
Posts: 462



(Msg. 2) Posted: Mon Jul 24, 2006 2:01 am
Post subject: RE: ADMT migration/security translation [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hi Tom,

1) Yes.

2) Also Yes.

3) No, SIDhistory is used to access the resource in SOURCE domain.

4) Yes, it works. Actually, computer migration does two things 1) Join the
computer into new domain 2) Run security translation. Now, you have to
perform securtiy translation manually since you have manually joined the
computer into new domain.


Best regards,

Vincent Xu
Microsoft Online Partner Support

======================================================
Get Secure! - www.microsoft.com/security
======================================================
When responding to posts, please "Reply to Group" via your newsreader so
that others
may learn and benefit from this issue.
======================================================
This posting is provided "AS IS" with no warranties,and confers no rights.
======================================================



--------------------
>>Thread-Topic: ADMT migration/security translation
>>thread-index: Acas+oXsFm7ZSBoIRYqUaAPCrAqwAQ==
>>X-WBNR-Posting-Host: 68.234.176.5
>>From: =?Utf-8?B?VG9t?= <Tom.TakeThisOut@discussions.microsoft.com>
>>Subject: ADMT migration/security translation
>>Date: Fri, 21 Jul 2006 12:19:01 -0700
>>Lines: 27
>>Message-ID: <89337FEE-1AF2-4D0D-8C91-ADBB0E9015A8.TakeThisOut@microsoft.com>
>>MIME-Version: 1.0
>>Content-Type: text/plain;
>> charset="Utf-8"
>>Content-Transfer-Encoding: 7bit
>>X-Newsreader: Microsoft CDO for Windows 2000
>>Content-Class: urn:content-classes:message
>>Importance: normal
>>Priority: normal
>>X-MimeOLE: Produced By Microsoft MimeOLE V6.00.3790.1830
>>Newsgroups: microsoft.public.windows.server.migration
>>Path: TK2MSFTNGXA01.phx.gbl
>>Xref: TK2MSFTNGXA01.phx.gbl
microsoft.public.windows.server.migration:24535
>>NNTP-Posting-Host: TK2MSFTNGXA01.phx.gbl 10.40.2.250
>>X-Tomcat-NG: microsoft.public.windows.server.migration
>>
>>Hello all,
>>
>>Regarding Intra-Forest migration using ADMT, four small (i think)
questions.
>>Any help appreciated.
>>
>>1) We are trying to migrate a file server that is also a DC from one
domain
>>to another with least work. I am thinking you must have at least one DC
left
>>in the source domain to run a secuirty translation on a migrated
>>workstation/server. Also, the file server/domain controller would need to
be
>>demoted to a member server first, migrated to new domain, and then run
>>security translation wizard. Sound correct? Any feedback appreicated.
>>
>>2) If My Docs folder is redirected from local profile to a shared network
>>folder will migrated users need to adjust this redirection at all either
>>before or after file server is migrated?
>>
>>3) Also,the SIDhistory will still work for access too when both file
server
>>and user accounts are in target domain, correct?
>>
>>4) Will security translation work on a server that has not been migrated
via
>>ADMT if a SID mapping file is employed? Example, if NTbackup or other
copy
>>program is used to copy file shares with original ACL from file server in
>>source domain to one in the target domain, can the ADMT "secuirty
translation
>>wizard" (using a SID map file) be used to change the source acct ACLs to
the
>>target acct ACLs?
>>
>>Thank You.
>>

 >> Stay informed about: ADMT migration/security translation 
Back to top
Login to vote
Display posts from previous:   
Related Topics:
Domain Users and Domain Admins Migration - I am migrating from Windows 2000 AD to Windows 2003 AD using ADMT v2.0. When I migrate computer accounts, ADMT does not update permissions for "Domain Users" and "Domain Admins". This means that if the following permission was applie...

NT 4.0 Server problem after 2003 Active directory migration - Ok folks. We have 4 New 2003 Domain controllers and 3 BDC's running windows Nt still. A active directory team came out and converted our domain to active directory. Now all of our Windows NT servers display SIDS instead of a display name from..

DHCP Migration...Export Import - Any help appreciated. We use a static dynamic DHCP structure using Linux... i.e every address is mac address registered. I can export this information from Linux and want to import this information into Windows2003 DHCP Server... i.e MAC address and IP...

ADMT2.0 computer migration - am some way through the migration from NT4 to win2k using ADMT2.0 things going good but there is one issue that wanted to understand wrt to computer migration using the GUI, the computer selection is a little bit clumsy so using the technique of typing...

moving admt application to another host - was hoping to get a procedural note on the move of the ADMT application to another server while maintaining the migration database. have read that it is just a copy of a database file (??) to the server on which the ADMT has been installed/ GT
   Windows Server (Home) -> Windows Server Migration All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum



[ Contact us | Terms of Service/Privacy Policy ]