Uers and computers migration cross forest with ADMT

Posted on 2006-03-20
Last Modified: 2008-02-26
I'm try to use ADMT to migrate users and computer from domain_A (W2k3 funct. level) in forest_1 to domain_B (W2k3 funct. level)  in forest_2.
I've problems to migrate the SID. When I try to migrate the SID, the ADMT pop-up the error "Could not verify auditing and TcpipClientSupport on domains. Will not be able to migrate Sid's. Access is denied".
Some suggestion?

Another problem, less important, is migrate the password. When I try to do that, using the Password Export Server Service, ADMT pop-up error that require to put the domain_B\administrator in the domain_A\DomainAdmins group. Is this possible?

Thanks in advance for your attention.

Question by:DavideD
    LVL 70

    Accepted Solution


    TCPIP Client Support must be enabled in the registry on the Source Domain Controller, the key is:


    Then TcpipClientSupport should be created as a DWORD and set to 1 (then the server rebooted).

    For me personally I normally run ADMT as a Domain Admin in the Source Domain that has been added to the Administrators Group in the Destination Domain which gets past the security issues you're getting.

    Anyway, there's an MS Article all about this one:;en-us;322970


    Author Comment


    Hi Chris,
    following your suggestion I finish the cross forest migration with the ADMT v.2.0, maybe the big error was to use the version v.3.0 of the tool.


    Featured Post

    Why You Should Analyze Threat Actor TTPs

    After years of analyzing threat actor behavior, it’s become clear that at any given time there are specific tactics, techniques, and procedures (TTPs) that are particularly prevalent. By analyzing and understanding these TTPs, you can dramatically enhance your security program.

    Join & Write a Comment

    The HP utility "HP Lights-Out Online Configuration Utility for Windows Server 2003/2008" could be of great use when it comes to remotely configure a HP servers ILO WITHOUT rebooting the server. We would only need to create and run scripts using thi…
    Numerous times I have been asked this questions that what is it that makes my machine log on so slow, there have been cases where computers took 23 minute exactly after taking password and getting to the desktop. Interesting thing was the fact th…
    To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…
    This demo shows you how to set up the containerized NetScaler CPX with NetScaler Management and Analytics System in a non-routable Mesos/Marathon environment for use with Micro-Services applications.

    745 members asked questions and received personalized solutions in the past 7 days.

    Join the community of 500,000 technology professionals and ask your questions.

    Join & Ask a Question

    Need Help in Real-Time?

    Connect with top rated Experts

    19 Experts available now in Live!

    Get 1:1 Help Now