Solved

Domain migration - computer account issue after using ADMT

Posted on 2004-10-01
3
420 Views
Last Modified: 2010-04-19
I am an OU administrator for my organization.  We recently used ADMT (active directory migration tool) to move all of our computers from an old (and busted) windows 2000 AD to a new windows 2003 AD.  I have full control of my OU and group policy privileges.  All my stuff is in my own OU or subcontainers.

When we ran the ADMT tool against the list of computers in the old domain, many of those computers no longer existed.  This caued lots of problems running ADMT as it would time out on computers it could not contact.  It also created computer accounts in the new domain for these computers even though it was never able to successfully contact them.

So now I have all my computers in the new domain, but I've also got these extra computer names.  I do not know whether our domain admin has any kind of policy in place to expire computer accounts that have never "phoned home", and I can't wait for that to kick in anyway.

Does anyone know how I can go through my OU and find computer accounts that have never contacted the DC so I can delete them and make my list accurate?  
0
Comment
Question by:mslunecka
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
3 Comments
 
LVL 2

Accepted Solution

by:
PKundtz earned 500 total points
ID: 12206506
Here are three options to generate a list of active computers.  You can use this list to remove inactive computer accounts:

You can compair AD computer accounts with DHCP if you use DHCP to assign IP addresses to you computers.

You can also look at your DNS for a list of computers that were once active.

Run ping & SNTP sweep across your network for a week or two.  Look@LAN is a good freeware program (http://www.lookatlan.com/download/LALSetup.exe).  This identifies computer names and IP addresses that are active and keeps a record of active hosts.  YOu can cross-check this list with the computers in AD and remove the inactive computers.

0
 
LVL 6

Author Comment

by:mslunecka
ID: 12208315
Good suggestions.  I had been looking for an AD specific solution, but I think comparing against the DHCP logs will probably be the best bet.  We have a fairly new DHCP/DNS management system that we built and it should be able to do that.  I won't be able to test it out until monday though.  I'll leave the question open for now and distribute points monday when I've had a chance to test it out.

I had considered running a LANguard scan of my network, but the problem is that I would get so many computer names back (I only administer one piece of our network) it would take too much effort to sift through them, and I need a more immediate answer than that would provide.  SOme of the computers in my list just don't get turned on very often.

If anyone else knows of a way to check the AD for computers that have contacted the DC recently I'd be interested in that as well.
0
 
LVL 6

Author Comment

by:mslunecka
ID: 12218788
Thanks for your help! I never actually had a chance to test your solution, though I've no doubt it would have worked (we keep good DHCP records and comparing a list of our computers against leases for the last 3 months wouldn't have been very difficult)

On our domains the computer account password changes monthly.  The accounts don't really expire, but we were able to check for accounts with expired passwords and eliminate them that way.  I'm not sure how our domain admin generated the list, but it showed up in my inbox this morning and I got what I needed.
0

Featured Post

Free NetCrunch network monitor licenses!

Only on Experts-Exchange: Sign-up for a free-trial and we'll send you your permanent license!

Here is what you get: 30 Nodes | Unlimited Sensors | No Time Restrictions | Absolutely FREE!

Act now. This offer ends July 14, 2017.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Setting up a Microsoft WSUS update system is free relatively speaking if you have hard disk space and processor capacity.   However, WSUS can be a blessing and a curse. For example, there is nothing worse than approving updates and they just have…
This article provides a convenient collection of links to Microsoft provided Security Patches for operating systems that have reached their End of Life support cycle. Included operating systems covered by this article are Windows XP,  Windows Server…
NetCrunch network monitor is a highly extensive platform for network monitoring and alert generation. In this video you'll see a live demo of NetCrunch with most notable features explained in a walk-through manner. You'll also get to know the philos…
Monitoring a network: why having a policy is the best policy? Michael Kulchisky, MCSE, MCSA, MCP, VTSP, VSP, CCSP outlines the enormous benefits of having a policy-based approach when monitoring medium and large networks. Software utilized in this v…

688 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question