Solved

ADMT 3.2 & PES 3.1:  Unable to establish a session with the password export server.  Access is denied.

Posted on 2010-09-20
3
7,239 Views
Last Modified: 2012-05-10
I am trying to migrate my domain and am encountering a problem with the ADMT PES account migration.  When I try to migrate a user password it fails with the above listed message.  I have the PES server on a different DC than the one I'm targetting for migration, and i have my ADMT server on a different server than the 1 DC in our target domain.  Everything is virtualized with ESX 4.0.

When I skip the PES password migration to see if I can migrate without bringing over the password it gives me a different error on the "Account Transition Options" page saying "Could not verify auditing and TcpipClientSupport on domains.  Will not be able to migrate SIDs.  Access is denied."

I can ping FQDNs and host names via each server involved in this process.  This is a Inter-Forest migration (between 2 seperate forests) and the trust is setup already and is working.  I have a user called PES that is a Domain Admin in the source domain and a member of the built-in Administrators group in the target domain.  I have an ADMT user that is in the Domain Admins of the target domain and is a member of the built-in Administrators group of the source domain.  The trust is working.  Auditing has been enabled and is showing up on the servers it should be when I run rsop.msc.  The following registry keys have been updated to show the following:  On PES:      HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\AllowPasswordExport = 1
On Target DC:      HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA\RestrictAnonymous = 0

Any ideas as to why this might not still be working?
0
Comment
Question by:ChocolateRain
  • 2
3 Comments
 
LVL 4

Expert Comment

by:geieea
ID: 33727802
ADMT is free and therefore, a major PITA to set up. I've found that if you miss any one of the steps in the ADMT set up, it will fail. Run through the ADMT/PES checklist again and execute them in the exact order as it instructs. Also, use the same server for the PES as the target migration DC.
0
 
LVL 1

Author Comment

by:ChocolateRain
ID: 33782631
Thanks for the advice.  The book I've finished reading "Mastering Windows Server 2008 R2" from Sybex said the same thing: "ADMT is a nightmare".

I've been through the steps so many times I'm blue in the face.  I emailed Microsoft and am now working on it with them.  If I get an answer specifically as to why it wasn't working I'll post it here.
0
 
LVL 1

Accepted Solution

by:
ChocolateRain earned 0 total points
ID: 33827215
Below is the log with MS that fixed our problem.

Namrata Saha has joined the support session. (1:02 PM)
Chocolaterain has joined the support session. (1:03 PM)
Chocolaterain is now sharing. (1:04 PM)
Namrata Saha: TcpipClientSupport
Namrata Saha: DWORD value of 1
Namrata Saha: Add the Domain Admins global group from the source domain to the Administrators local group in the target domain.  
Add the Domain Admins global group from the target domain to the Administrators local group in the source domain.  
Create a new local group in the source domain called Source Domain $$$.
Namrata Saha: Enable auditing for the success and failure of user and group management on the source domain.  
Enable auditing for the success and failure of Audit account management on the target domain in the Default Domain Controllers policy.
On the PDC in the source domain, add the
    TcpipClientSupport:REG_DWORD:0x1
(HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA )
Namrata Saha: Run the following command on the destination server where we have installed the ADMT :

ADMT KEY /OPT:CREATE /SD:<SOURCE DOMAIN> /KF:<LOCAL PATH>\KEY.PES
Namrata Saha: Copy the KEY.PES file to the source domain or make it available over a network share.
Copy the C:\WINDOWS\ADMT\PES folder from the target domain to the source domain.
On the source domain , run PWDMIG.MSI and follow the wizard..
Namrata Saha: When you run the ADMT Password Migration DLL Installation Wizard, you are prompted for the path of the .pes file that you moved to the Source domain. You must specify a local path for this file. You are also prompted for the password that you used when you created this file.
When you are ready to migrate passwords from the Source domain, change the AllowPasswordExport registry value to 1.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa
AllowPasswordExport = 1
Microsoft has requested to share control. (1:47 PM)
Chocolaterain has granted control to Namrata Saha. (1:47 PM)
Microsoft: http://technet.microsoft.com/en-us/library/cc772816(WS.10).aspx
Microsoft: Netdom trust TrustingDomainName /domain: TrustedDomainName /quarantine:No
Microsoft: v-2nams@mssupport.microsoft.com
Microsoft has exited the support session. (2:13 PM)
0

Featured Post

Back Up Your Microsoft Windows Server®

Back up all your Microsoft Windows Server – on-premises, in remote locations, in private and hybrid clouds. Your entire Windows Server will be backed up in one easy step with patented, block-level disk imaging. We achieve RTOs (recovery time objectives) as low as 15 seconds.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Background Information Recently I have fixed file server permission issues for one of my client. The client has 1800 users and one Windows Server 2008 R2 domain joined file server with 12 TB of data, 250+ shared folders and the folder structure i…
A project that enables an administrator to perform actions within a user session context not just at the time of login but any time later on day(s) or week(s) later.
This tutorial will walk an individual through the steps necessary to configure their installation of BackupExec 2012 to use network shared disk space. Verify that the path to the shared storage is valid and that data can be written to that location:…
This tutorial will walk an individual through the steps necessary to enable the VMware\Hyper-V licensed feature of Backup Exec 2012. In addition, how to add a VMware server and configure a backup job. The first step is to acquire the necessary licen…

713 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question