Link to home
Create AccountLog in
Windows Server 2003

Windows Server 2003

--

Questions

--

Followers

Top Experts

Avatar of catsup3
catsup3

ADMT Sid Migration issues
SID migration was working successfully yesterday. I installed the PES service on the SOURCE domain controller and rebooted overnight. Today when I run a user/group migration and select the option to migrate SIDs I receive the message:

Could not verify auditing and TcpipClientSupport on domains. Will not be able to migrate Sid's. The specified domain either does not exist or could not be contacted.

See below for config details and things I have tried:

Both domains are 2003 functional level
Two-way external trusts are established between source.com.au and target.com.au
SID filtering and SID history have been configured as per the following commands:

netdom trust source.com.au /domain:target.com.au /enablesidhistory:yes /quarantine:no
These commands completed successfully

Trusts have been validated via gui, however, when the command "netdom trust source.com.au /domain:target.com.au /twoway /verify" is run on the source domain I receive the error: "The command failed to complete successfully."
If this command is run on the target domain it verifies successfully.
Could this be causing the problem? What is the resolution for this? Removing & recreating the trusts?

SOURCE DC - Windows 2003
Running PES (service logon using TARGET\user)
TARGET\user is a member of BUILTIN\Administrators on the source domain

MIGRATION SERVER - Windows 2008 (not a DC)
TARGET\user is a member of local administrators on the migration server and TARGET\domain admins
ADMT migration tool is being run using the TARGET\user account

I can migrate accounts without sids
I can ping sourcedc.source.com.au from the target domain and vica versa.
RPCping on port 135 works both ways also.
I have verified that SOURCE$$$ exists on the source domain
I have verified the HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\TcpipClientSupport 1 exists on the source DC (it has been rebooted since this key was added)
Audit Account Management is enabled (success and failure) in both domain controller policies

Can anyone assist?

Zero AI Policy

We believe in human intelligence. Our moderation policy strictly prohibits the use of LLM content in our Q&A threads.


Avatar of RickSheikhRickSheikh🇺🇸

What scope is the {SOURCEDOMAIN}$$$ group ?  ifs its of Global, try changing that to Domain Local.

Avatar of catsup3catsup3

ASKER

Its domain local & I have tried recreating it.

ASKER CERTIFIED SOLUTION
Avatar of catsup3catsup3

ASKER

Link to home
membership
Log in or create a free account to see answer.
Signing up is free and takes 30 seconds. No credit card required.
Create Account

Reward 1Reward 2Reward 3Reward 4Reward 5Reward 6

EARN REWARDS FOR ASKING, ANSWERING, AND MORE.

Earn free swag for participating on the platform.

Windows Server 2003

Windows Server 2003

--

Questions

--

Followers

Top Experts

Windows Server 2003 was based on Windows XP and was released in four editions: Web, Standard, Enterprise and Datacenter. It also had derivative versions for clusters, storage and Microsoft’s Small Business Server. Important upgrades included integrating Internet Information Services (IIS), improvements to Active Directory (AD) and Group Policy (GP), and the migration to Automated System Recovery (ASR).