Solved

Using ADMT to Migrate User Accounts from Windows 2000 AD Domain to a Windows 2008 Domain

Posted on 2008-10-28
3
1,277 Views
Last Modified: 2010-04-21
Hi Experts,

I created a lab environment to start working on a server migration project.  My goal is to move the user accounts from a Windows 2000 AD Server to a Windows 2008 AD Server.  I have information overload from Google, but I did not find any web page that has steps 1 through 100 that show you exactly how to do this.

I believe that what I need to do is run MS's ADMT and then figure out the rest of the process.  

What I've done so far is:
Convert our existing AD server to a VM
Created a new VM with Windows 2008 - I also installed AD services and ran DC Promo.  This also confgured DNS
On each server, I then created Secondary zones on each server

So far I think I'm on the right track...

Now when I run MS ADMT, it states that my Admin account on 2008 does not have access to the 2000 Admin account (not using the verbatim error message).  

Can anyone explain to me verbatim what to do to enable trusts between both servers?  Or am I going about this totally wrong?

Thanks!
0
Comment
Question by:byd2k
  • 2
3 Comments
 
LVL 30

Accepted Solution

by:
LauraEHunterMVP earned 350 total points
ID: 22825978
AD migrations require that a trust relationship be in place. You need to configure an external trust from the 2000 domain to the 2008 domain, and vice versa.

The procedures to do so are described here: http://technet.microsoft.com/en-us/library/cc738617.aspx
0
 

Author Comment

by:byd2k
ID: 22831156
Thanks for your reply.

On the Windows 2000 server, I ended up getting to step 4 where you have to enter in the other domain name.

Windows comes back with the error:  

AD cannot verify the trust.

The error returned was:  The security database on the server does not have a computer account for this workstation trust relationship.

I tried to do as the instructions state, but I can't add this server as a computer on the other server because the trust isn't setup correctly.  ;)

I upped the points.

Thanks again,
byd2k
0
 

Author Closing Comment

by:byd2k
ID: 31510827
Thanks for your help.  The instructions were pretty generic.  What I actually had to do was this process, however from the Windows 2008 side.  When I configured the server from the 2008 side for trust, it populated the trusts in Windows 2000.  For some reason I could not follow the instructions verbatim.

Thanks again,
Byd2k
0

Join & Write a Comment

I wrote this article to explain some important DNS concepts that should be known to avoid some typical configuration errors I often see in forums. I assume that what is described here is the typical behavior of Microsoft DNS client. I don't know …
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

747 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now