ADMT Security Translation Issue

N

NV

All,

I have a rather simple question which I know there is a logical
explanation for but I do not know what it is.

I am using ADMT 2.0 to begin migrating NT 4.0 domain servers to AD. I
have already migrated users and the global groups over from the NT
domain to AD. I also want the security to be translated into their
equivalent groups on the AD side. Here is the scenario:

NT 4 Domain = MyDomain
AD Domain = MyAdDomain
Share Folder = NT4-Folder
NTFS Perm = MyDomain\Developers - Full Control

I have Server-1 which have Share and NTFS permissions applied on the
folders. When I use ADMT 2.0 to migrate the server, I have the
following selected:

- Translate Objects dialog box
- "I selected all the check box"

- Security Translation Objects dialog box
- "Add - Add equivalent security references for target objects and
leave source references intact."

....

- Naming Conflicts dialog box
- "Replace conflicting accounts (With No Check Boxes selected below
this)"

When the migration happens, I log into the server to verify the Share
and NTFS security on each folders. And I see the following on the
NT4-Folder for the NTFS permissions:

Share Folder = NT4-Folder

NTFS Perm = MyAdDomain\Developers - Full Control
MyAdDomain\Developers - Full Control

I see the entry twice. I assume one of them is to reference the NT4
global group and the other one is the AD equivalent of the NT4 global
group.

Why are both entries the same and how do I verify which one is
referencing the NT4 global group?

Any input would be appreciated.

Thanks!

NV
 
G

Guest

You see 2 entries because you selected Add in the Security translations object dialogue box and this will leave the original group and add the SID for the new global group

I don't beleive it is possible to view which group is which through the normal GUIs. You would need a tool to see the permissions assigned to each SID and verify which SID belongs to which group.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top