ADMT - SID history not working

Hello guys,

I have stopped with ADMT migration tests. Using ADMT 3.2 installed within my resource forest (FFL = WS 2003). I have resource forest with 4 child domains divided per continent.

Resource forest and domain functional level WS 2003. Target forest WS 2003, target child domain functional level is WS 2008 R2

Two way external trust is between with Disabled SID filtering feature. I have created HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA (TcpipClientSupport - DWORD with value 1 on resource PDC.

My ADMT service account is member of Built-in Administrator in resource forest and Domain admins in target domain . Im able migrate users from resource to target forest including passwords (PES already configured), but when I want to use option to migrate SID to target domain, Im getting error:

Does anyone know what is the root cause? Thank you for help!

Petr Weiner

August 24th, 2015 5:29am

Hi,

Thanks for your post.

May I ask that what the exact error message do you get?

Are you follow the steps to migrate the SID History?

https://technet.microsoft.com/en-us/library/Cc728166(v=WS.10).aspx

In addition, the similar thread discussed before, you may also follow the steps to have a  check.

https://social.technet.microsoft.com/Forums/windowsserver/en-US/8a96f63e-5024-495a-958f-f43873efb680/admt-32-sid-history-not-running?forum=winserverMigration

Best Regards,

Mary Dong

Free Windows Admin Tool Kit Click here and download it now
August 25th, 2015 1:51am

August 25th, 2015 3:20am

Hi,

Thanks for your reply.

This problem may occur if the {SOURCEDOMAIN}$$$ group on   the source domain was created as a global group instead of as a local group. You could also do a check.

https://support.microsoft.com/en-us/kb/317846

And you could also follow the steps to do the troubleshooting

https://support.microsoft.com/en-us/kb/322970

Best Regards,

Mary Dong

Free Windows Admin Tool Kit Click here and download it now
August 25th, 2015 10:58pm

I did very advanced debug where is written what you wrote as well, so even group exists, its not working.
August 26th, 2015 6:55pm

Hi,

Have you tried disabling SID filtering using Netdom command in the target domain as given below,
Netdom trust SourceDomain /domain:TargetDomain /quarantine:No /usero:domainadministratorAcct /passwordo:domainadminpwd

By default, SID filtering is turned on.To disable SID filtering, you must be a domain admi
Free Windows Admin Tool Kit Click here and download it now
August 26th, 2015 9:10pm

Thanks for answer, but done 2 weeks ago.
August 27th, 2015 10:48am

any clue?
Free Windows Admin Tool Kit Click here and download it now
September 1st, 2015 3:01am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics