Quantcast
Channel: Migration for Active Directory - Recent Threads
Viewing all 44 articles
Browse latest View live

QMM 8.10

$
0
0

We're using  the QMM for AD 8.10 and while we're trying to stop the synchronization job it's giving an error " cannot stop  service  Aedsaresolver". Tried restarting the quest services but all the services are getting restarted except this. Can someone please help me out or any suggestions.

Thanks,

Ravi.


Retain the target source account already there

$
0
0

I want to use the existing samaccount in the target domain and not have the source over write it.  I have googled for an hour and can't find the solution.  The only thing I see if for office 365 and not for the the AD solution.  Please advise.

Thanks,

Ken

Symantec PGP Encryption and Migration

$
0
0

I am trying to get some general guidance or past experience details on PGP encryption laptop migration using RUM. 

How do you achieve this?

Thanks,

Aru

Intraforest Migration using QMM

$
0
0

I have performed may Inter-forest migrations using QMM.  But this is the first time I am planning to perform an Intra-forest migration.  I couldn't find any good document or KB on this topic on the site.

I barely read something about SID History issues during the migration. But I don't think that article is explaining the complete technical details.  Why and how SID history copy will become an issue?  How can I identified these issues forehand?

Also, what is the best practice recommendation for Intra-forest migration?  I don't think user guide has this topic.

Thanks in advance!

Aru

Keep same domain name with the old and new domain

$
0
0

I have a scenario where the netbios name is the same on the source and target domains.  I need to keep the same domain name on both sides.  Is this possible?  I tried to google and found nothing.  If someone could steer me to the proper article, I would really appreciate it!

SIDHistory processing – Previous migration done with ADMT

$
0
0

I am trying to figure out how to deal with this scenerio.  After an hour on google, I have become very frustrated.  If anyone can point me to an article describing how to work with this delemma, I would be forever grateful.

Merging multiple accounts from multiple sources

$
0
0

I have never run into this before :(.   I have a user that has an account in several source domains, and he wants to retain all rights from all of them in to his ONE target account.  I have searched this site and connot find anything about this scenario.  Any help would be great.

Remote user cannot log in after migration

$
0
0

I have a user that cannot log in to their machine after migration.  Is there an article that I can use to troubleshoot these home users not being able to connect?


trouble shooting messed up profiles for users

$
0
0

Hey guys.  I am trying to find an article that shows what the resolution would be when someone logs in to a machine prematurely and the users profile is blank.  We have instances where the techs are to hastily logging in to a machine either before the machine was migrated or the machine failed on migration.  I am looking for different methods of "FIXING" the profile that the tech has now broke.

Chrome & Dropbox issues after QMM migration

$
0
0

Hi All,

After doing QMM migration on workstations, Chrome & Dropbox no longer functions properly.  Migration of the workstations itself work fine however.

User accounts are synchronized properly & have SID history, so it's "reusing" the local workstation profile, as it should.  but because Chrome & Dropbox typically install themselves onto the user's appdata folder, we believe that may be part of the problem as the programs have issues reading the folders after it has changed domains.  security permissions on the folders seem ok in that the new/synchronized account on the domain should have full access to those folders.

only solution so far is to uninstall & reinstall, which is not practical for a large organization.

just wondering if anyone has run into this issue or anything similar.  any tips, tricks, or suggested pre-emptive measures?

Thanks!

Upgrading schema in the middle of migration

$
0
0

Hello,

I have a situation where there are multiple Source Domain(s) Windows 2003 R2 and Windows 2008 R2. The Target is presently 2008 R2. They would like to upgrade the Target Domain 2012 R2. This would not be an issue, if I wasn't in the middle of the migration already. As it may be I am in the middle of the migration already.

I am aware of the following from SOL109535:

Migration Manager uses a strict criteria for migrating a distinct set of attributes. The lowest version of Active Directory in the migration found of source and target Active Directory is used as the basis for migrating schema attribute values.

Is this possible or recommended? If possible would just upgrading the Target to 2012 R2 feasible.

What would be the best way to attack this situation?

Your feedback is greatly appreciated.

Intraforest Migration - High Level Steps / Documentation

$
0
0

Good morning,

I don't see any information in QMM guide on Intra-forest migration. We have a lot of information on Inter-forest migration. 

I always migrate groups first in my Inter-forest migrations.  Since we can't keep SID History and Source Object at the same time in Intra-forest migration, what would be the best approach here?

If I delete source groups, users will lose all application permission and access. Am I missing something here?

Could you provide some pointers?

Thanks,

Migration with McAfee Endpoint Encryption

$
0
0

Hi

I'm looking to migrate 2,000 machines to a new domain using QMM. Most of the machines are encrypted with McAfee Endpoint Encryption 5.2.12

Does anyone have experience migrating encrypted machines, or can point me towards some documentation? Thanks.

Regards

Alec

 

 

Migration Approach

$
0
0

Hello,

I would like to get feedback on a plan to carry out an AD/Exchange migration.

Source (Exchange 2003) = DomainA

Target (Exchange 2010) = DomainB

Initially we would like to migrate mailboxes from DomainA to DomainB but leave the current AD accounts in the source enabled.  We would like to create linked mailboxes and leave users logging into the source domain but using target mailboxes (resource Forrest).


To achieve this I have configured AD domain pair in QMMAD and configured the syncronisation node.  This has sucessfully created the disabled AD accounts in target together with linked mailboxes with the correct attributes.


I then created legacy mailbox and calendar sync collections and sucessfully synced mailbox content and calendar content to these mailboxes in the target.

The question I have is what are the next steps?  Do I just need to "switch" the mailbox and then reconfigure user profiles in the source to point to the target Exchange server?


Also, what happens with calendar, full mailbox access permissions?  Would I need to run the exchange processing wizzard?

At the moment we just want to migrate mailboxes, the AD accounts, fileservers etc will be migrated later.

Thanks

Mark

Exchange Resource Forest to Resource Forest Migration

$
0
0

We need to consolidate two Exchange 2007 orgs. Both have their own resource forest.

a. User accounts from accounts forest 1 will move to accounts forest 2

b. Mailbox's will move from resource forest 1 to resource forest 2.

Can we use QMM and how would it work i.e.

a. in what order would accounts and mailboxes be moved

b. how would the linked account that has migrated to resource forest 2 know to connect to the user account that has migrated to accounts forest 2?

Thanks


Warning: Configuration path \\console-server\\QuestResourceUpdatingConfigs$\ is not accessible. Error 0x00000035. The network path was not found.

$
0
0

This is killing me.  I am not getting access denied.  The log shows everything works perfectly on the discovery except for the end of the log that states : 

Warning: Configuration path \\VNLDSCAPP01\QuestResourceUpdatingConfigs$\ is not accessible. Error 0x00000035. The network path was not found.


I have tried to discover from two seperate consoles in two different data centers and get the same error.  Ignoring the hidden shares for now, I created a share on the console and granted everyone full rights to it.  If I try \\consoleserver\  I get a failure that it cannot find it.  The firewall is off on the server being discovered.  I have tried the reg hack of placing the ip, short name, and dns name in there and none of them work.  I have placed the console in the host file on the server and that did not help. 


Has anyone experienced this without the access denied?  What more can I do to trouble shoot the problem?

Thanks in advance!

Kerberos Authentication

$
0
0

Hello,

might be, anyone can help here. Whyever, ADM will use NTLM to migrate accounts between the domain (Intra Forest). Because we've seen, that the accounts for example for DSA to migrate SIDHistory will not only use NTLM, this account will also be used from the console to authenticate the console user (for example by browsing OUs).

I there any chance to switch to Kerberos? NTLM contains some security issues and if I use the account for whatever reason on the console mmachine, then the password hash will be stored there and a "unfriendly user" can use These high-previlaged account for whatever reasons (to read the hash, it is a simple exercise).

As long we asked Dell, there we got the information that this should work and there might be a work around to use Kerberos. But we dont find any additional information. I cannot imagine, that this will not work - it is a required security feature for such a critical tool, where I ned to use administrative accounts (Dell recommends Enterprise Admin!!!). But a clear message is missing.

Migration Steps for Vsphere Horizon View Clients

$
0
0

I have a couple of questions concerning the migration of a VDI environment. Any assistance is appreciated.

1. Looking for best practice steps for migration of  VSphere Horizon View Clients ( VDI environment).

2. Can the migration of the VDI users be segmented? Thinking a custom vmover.ini for users we want to move would work, but would like confirmation.

Can passwords be synchronized for new accounts not migrated?

$
0
0

This will be a migration that will have a coexistence of 1-2 years.  Not all users in source will be migrated, only users in one division.  Users need to maintain an account in source domain and target domain during the coexistence to use their source accounts to access source company apps and target accounts to access a few applications on target.   Client will continue creating source account and matching target account using their respective provisioning systems and all future account creations will match samaccountname.  Can Migration Manager merge the new accounts automatically using Directory Sync so passwords will stay in sync for the new accounts?  If so, how would this be done?  I've done some testing in the lab and passwords only sync for accounts that have been migrated or created by Dir Sync. If I manually create a new account with same samaccountname in source and target the passwords do not sync and the accounts do not merge.

vMover not Processing NetApp Filer

$
0
0

I am having issues processing data on a NetApp Filer using the Command Line vMover.

I am able to scan the data in the target share using the syntax below:

 vmover.exe /c /volume=\\server\share\ /ini=file.ini /log=file.log /statefile=file.txt.

The log output shows that the files are being scanned but there are no files modified and the permissions on the files have not been changed.

When I enable logging in the ini file I receive a bunch of entries  that state "TraceMsg   -5".

The ini also contains all of the user and group info at the bottom. I used the ini from a previous job created in the GUI to ensure the proper format.

Can anyone shed any light on what exactly is happening here?

Thanks,

Tony

Viewing all 44 articles
Browse latest View live


<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>