Jordan,

1) Did you verify that both DNS _and_ WINS resolution are functioning properly ? You will need both of these to function properly for the migration to work.
2) Did you add both the Anonymous Logon group as the Everyone group to the Pre-Windows 2000 Compatible Access group ?


Regards,

Paul.

----- Original Message ----- From: "Jordan Arendt" <[EMAIL PROTECTED]>
To: <[EMAIL PROTECTED]>
Sent: Wednesday, September 15, 2004 10:52 PM
Subject: [ActiveDir] ADMT v2 PES question



Hi all,

So, I've got a 2k3 forest that I am migrating an NT 4 domain into.
I've setup a Password Export Server on a DC in my test NT 4 domain.
Set registry entries, established trusts, etc.  When I go to migrate a
user, I get:

WRN1:7557 Failed to copy the password for {user.} A strong password
has been generated instead. Unable to copy password. Access is denied.

I'm looking at
http://support.microsoft.com/default.aspx?scid=kb;%5BLN%5D;322981

and have verified everything except:

Pre-Windows 2000 Compatible Access has Read and Enumerate Entire SAM
Domain permissions on the object, as follows:
CN=Server,CN=System,DC={TargetDomain},DC={tld}

Can anyone translate this for me? I'm not sure what I am supposed to do here.

Thanks,

Jordan
List info : http://www.activedir.org/mail_list.htm
List FAQ : http://www.activedir.org/list_faq.htm
List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

List info : http://www.activedir.org/mail_list.htm List FAQ : http://www.activedir.org/list_faq.htm List archive: http://www.mail-archive.com/activedir%40mail.activedir.org/

Reply via email to