Active Directory Migration

Hi

Im trying to do an Active Directory migration from one domain to another, these are differnet forests i.e. abc.com and 123.com. Here's whats been done, DNS it working with secondary zones setup for each server so they can handle dns requests. I have also created the trusts between the domains and validated each fine.

However ive installed the Active Directory Migration tool but when i got to move a user I get the following error in the log
2007-03-21 20:28:05 ERR2:7301 Failed to migrate source object 'CN=admin admin' to domain 'abc.com'. The target object could not be created. hr=0x80070005  Access is denied.

Can yoy help?
Thanks
kev8326Asked:
Who is Participating?
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

Jay_Jay70Commented:
are you using crenetials from your domain or from the source domain?
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
kev8326Author Commented:
Hi

I believe that is where i was going wrong, i was putting in details of the target domain rather than the source. It appears i've moved forward and gained another stumbling block...

I get a message SID History for test1 cannot be updated because auditing is not enabled on abc.com.   rc=8536.\n  This operation requires that auditing be enabled for Success and Failure auditing of account management operations

I have enabled this in group policy and made sure that it has success and failures. this is done at the root of AD and there isnt anything to stop it propogating to other OU's.

Is there something ive missed?
thanks
0
kev8326Author Commented:
Hi

Somehow got it working, i also added the admin on domain A to the account operators group in Domain B and it started working. Does that sound like it was the isue?
0
Jay_Jay70Commented:
deffinitely, you need to have the priviliges on the local domain :) Nice work mate!
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Networking

From novice to tech pro — start learning today.