Jordan,
1) Did you verify that both DNS _and_ WINS resolution are functioning properly ? You will need both of these to function properly for the migration to work.
2) Did you add both the Anonymous Logon group as the Everyone group to the Pre-Windows 2000 Compatible Access group ?
Regards,
Paul.
----- Original Message ----- From: "Jordan Arendt" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, September 15, 2004 10:52 PM
Subject: [ActiveDir] ADMT v2 PES question
Hi all,
So, I've got a 2k3 forest that I am migrating an NT 4 domain into. I've setup a Password Export Server on a DC in my test NT 4 domain. Set registry entries, established trusts, etc. When I go to migrate a user, I get:
WRN1:7557 Failed to copy the password for {user.} A strong password has been generated instead. Unable to copy password. Access is denied.
I'm looking at http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;322981
and have verified everything except:
Pre-Windows 2000 Compatible Access has Read and Enumerate Entire SAM Domain permissions on the object, as follows: CN=Server,CN=System,DC={TargetDomain},DC={tld}
Can anyone translate this for me? I'm not sure what I am supposed to do here.
Thanks,
Jordan
List info : http://www.activedir.org/mail_list.htm
List FAQ : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/
