PC Review


Reply
Thread Tools Rate Thread

Migrate Built-in/Well Known NT groups to AD

 
 
Keith
Guest
Posts: n/a
 
      15th Jun 2004

Can NT built-in groups like Domain Admins or Domain Users
be migrated to W2K AD?

If not, please advise how can you migrate these groups?


Keith
 
Reply With Quote
 
 
 
 
Marin Marinov
Guest
Posts: n/a
 
      15th Jun 2004
In article <1c5e801c452cc$3d148ee0$(E-Mail Removed)>,
(E-Mail Removed) says...
>
> Can NT built-in groups like Domain Admins or Domain Users
> be migrated to W2K AD?
>
> If not, please advise how can you migrate these groups?
>
>
> Keith
>

Hi Keith,
No, you can't migrate built-in and well-known security principals. Well-
known (built-in) groups like Administrators always have the same SID.
"Predefined" groups like Domain Admins have the same RID but a
different domain part of the SID,i.e. different SID as a whole. The
Active Directory Migration Tool (ADMT) won't migrate built-in or
predefined groups and won't fix membership for these groups so if you
migrate a user that is a member of Domain Admins in the source domain he
won't be such in the target. As always, all migrated users become
automatically members of Domain Users.

The resolution would be to manually add the respective users to these
groups (if you need to) so make sure you document these memberships. For
such users to maintain access to resources you'll need to translate
security with the Security Translation Wizard and a SID mapping file.

I would suggest that you read through (URLs wrap):

Windows 2000 Domain Migration Cookbook
http://www.microsoft.com/technet/pro...rv/deploy/cook
book/cookintr.asp

Domain Migration Cookbook (Chapter 9: Migration of a Windows NT 4.0
Account Domain to Active Directory)
http://www.microsoft.com/technet/pro...rv/deploy/cook
book/cookchp9.mspx

HTH
--
Cheers,
Marin Marinov
MCT, MCSE 2003/2000/NT4.0,
MCSE:Security 2003/2000, MCP+I
-
This posting is provided "AS IS" with no warranties, and confers no
rights.

"True knowledge exists in knowing that you know nothing."
Socrates
 
Reply With Quote
 
 
 
 
Guest
Posts: n/a
 
      16th Jun 2004
Marin,

Thank you very much for your invaluable help.

Keith.
>-----Original Message-----
>In article <1c5e801c452cc$3d148ee0$(E-Mail Removed)>,
>(E-Mail Removed) says...
>>
>> Can NT built-in groups like Domain Admins or Domain

Users
>> be migrated to W2K AD?
>>
>> If not, please advise how can you migrate these groups?
>>
>>
>> Keith
>>

>Hi Keith,
>No, you can't migrate built-in and well-known security

principals. Well-
>known (built-in) groups like Administrators always have

the same SID.
>"Predefined" groups like Domain Admins have the same RID

but a
>different domain part of the SID,i.e. different SID as a

whole. The
>Active Directory Migration Tool (ADMT) won't migrate

built-in or
>predefined groups and won't fix membership for these

groups so if you
>migrate a user that is a member of Domain Admins in the

source domain he
>won't be such in the target. As always, all migrated

users become
>automatically members of Domain Users.
>
>The resolution would be to manually add the respective

users to these
>groups (if you need to) so make sure you document these

memberships. For
>such users to maintain access to resources you'll need

to translate
>security with the Security Translation Wizard and a SID

mapping file.
>
>I would suggest that you read through (URLs wrap):
>
>Windows 2000 Domain Migration Cookbook
>http://www.microsoft.com/technet/pro...l/windows2000s

erv/deploy/cook
>book/cookintr.asp
>
>Domain Migration Cookbook (Chapter 9: Migration of a

Windows NT 4.0
>Account Domain to Active Directory)
>http://www.microsoft.com/technet/pro...l/windows2000s

erv/deploy/cook
>book/cookchp9.mspx
>
>HTH
>--
>Cheers,
> Marin Marinov
> MCT, MCSE 2003/2000/NT4.0,
> MCSE:Security 2003/2000, MCP+I
>-
>This posting is provided "AS IS" with no warranties, and

confers no
>rights.
>
>"True knowledge exists in knowing that you know nothing."
>Socrates
>.
>

 
Reply With Quote
 
 
 
Reply

Thread Tools
Rate This Thread
Rate This Thread:

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
utlook 2007 quits querying known working free/busy server with known working free/busy account.. Simuser Microsoft Outlook Discussion 0 29th Oct 2009 09:23 PM
Outlook 2007 quits querying known working free/busy server with known working free/busy account.. Simuser Microsoft Outlook Discussion 1 26th Oct 2009 09:19 PM
Outlook 2007 quits querying known working free/busy server with known working free/busy account. Simuser Microsoft Outlook Calendar 0 26th Oct 2009 05:01 PM
Passing known summaries to known control names from VB =?Utf-8?B?TWlrZUM=?= Microsoft Access Form Coding 2 21st Sep 2005 03:29 PM
Restricted Groups: "Member of" and add Domain Groups to local Groups Hansi Microsoft Windows 2000 Group Policy 1 5th Mar 2005 04:24 AM


Features
 

Advertising
 

Newsgroups
 


All times are GMT +1. The time now is 01:07 AM.