Solved

Using ADMT to Migrate User Accounts from Windows 2000 AD Domain to a Windows 2008 Domain

Posted on 2008-10-28
3
1,281 Views
Last Modified: 2010-04-21
Hi Experts,

I created a lab environment to start working on a server migration project.  My goal is to move the user accounts from a Windows 2000 AD Server to a Windows 2008 AD Server.  I have information overload from Google, but I did not find any web page that has steps 1 through 100 that show you exactly how to do this.

I believe that what I need to do is run MS's ADMT and then figure out the rest of the process.  

What I've done so far is:
Convert our existing AD server to a VM
Created a new VM with Windows 2008 - I also installed AD services and ran DC Promo.  This also confgured DNS
On each server, I then created Secondary zones on each server

So far I think I'm on the right track...

Now when I run MS ADMT, it states that my Admin account on 2008 does not have access to the 2000 Admin account (not using the verbatim error message).  

Can anyone explain to me verbatim what to do to enable trusts between both servers?  Or am I going about this totally wrong?

Thanks!
0
Comment
Question by:byd2k
  • 2
3 Comments
 
LVL 30

Accepted Solution

by:
LauraEHunterMVP earned 350 total points
ID: 22825978
AD migrations require that a trust relationship be in place. You need to configure an external trust from the 2000 domain to the 2008 domain, and vice versa.

The procedures to do so are described here: http://technet.microsoft.com/en-us/library/cc738617.aspx
0
 

Author Comment

by:byd2k
ID: 22831156
Thanks for your reply.

On the Windows 2000 server, I ended up getting to step 4 where you have to enter in the other domain name.

Windows comes back with the error:  

AD cannot verify the trust.

The error returned was:  The security database on the server does not have a computer account for this workstation trust relationship.

I tried to do as the instructions state, but I can't add this server as a computer on the other server because the trust isn't setup correctly.  ;)

I upped the points.

Thanks again,
byd2k
0
 

Author Closing Comment

by:byd2k
ID: 31510827
Thanks for your help.  The instructions were pretty generic.  What I actually had to do was this process, however from the Windows 2008 side.  When I configured the server from the 2008 side for trust, it populated the trusts in Windows 2000.  For some reason I could not follow the instructions verbatim.

Thanks again,
Byd2k
0

Featured Post

Free Tool: Port Scanner

Check which ports are open to the outside world. Helps make sure that your firewall rules are working as intended.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This article describes my battle tested process for setting up delegation. I use this process anywhere that I need to setup delegation. In the article I will show how it applies to Active Directory
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

790 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question