Hi khudwrx03,
I have had no problems moving even large complex (4 domain into one)
migrations with ADMT v2. likewise, no issues with v3 either. Really it
comes down to limiting your exposure by going slowly, running the security
translation to ensure that you migrate all objects, and testing thoroughly.
Remember that things will still work with the SID History until the PDCe and
the foreign DNS go out of scope (it'll continue to work afterwards, but it
gets dicey and you'll lose SID to name resolution). If you are seeing that
you are relying on the SIDHistory for the permissions, you can try the
security translation again. remember that it all comes down to SID. If you
are seeing the SID from the target domain on the ACE in the ACL when you view
it from xcacls, then you have done the translation correctly.
--
Ryan Hanisco
MCSE, MCTS: SQL 2005, Project+
http://www.techsterity.com
Chicago, IL
Remember: Marking helpful answers helps everyone find the info they need
quickly.
Post by khudwrx03Post by Ryan HaniscoDomain migrations and consolidations are my specialty, let me know if you
have any other questions.
--
Ryan Hanisco
MCSE, MCDBA
FlagShip Integration Services
Ryan,
I am currently supporting a domain migration. Child domain school into
the forest school system domain.
Is there a danger to not using ADMT v3.0 to move member servers into
the forest domain? We are experiencing an issue where the users and
groups are being moved using ADMTv2.0 successfully with the domain
controllers still in place. The ACL list comes up in the GUI windows
box with the child domain tag still in place. XCACLS from a command
prompt shows the correct forest domain tag. Users still have access to
the resources.
Once the child domain controllers have been collasped, the ACL domain
tag issue goes away. Users still have access to the member server
resources without using ADMT to migrate them -- basically just rename
the domain and reboot.
Any thoughts would be greatly appreciated.
Keith
MCSE -- Windows Admin Lead
Fairfax County Public Schools
Fairfax, VA
--
khudwrx03
------------------------------------------------------------------------
khudwrx03's Profile: http://forums.techarena.in/member.php?userid=32707
View this thread: http://forums.techarena.in/showthread.php?t=65052
http://forums.techarena.in