
Administrative Access:
Create a 2 way trust betwen each source and target domain.
Add both the source and targets Domain Admins group, the Enterprise Admins group to each domains Administrators group.
Create or select an account on the target domain and add it to Domain Admins, Enterprise Admins and Schema Admins Group.
Use the above account as the migration account to perform the migration as well as for the service account.
Enable this account to logon locally and run as a service on both the source and target PDC Emulator.
Domain Policy:
verify that IPFiltering is turned off on both domains
Verify that Windows Firewall is turned off as a group policy
http://domainreconfigure.blogspot.com/search/label/Step%203%20Virtual%20Migration
DNS Configuration:
Once the target domain’s DNS server is configured and running, configure the DNS network card clients of the source domain computers to point to the new DNS Server and add the new domain to the domain suffix list.
Create a Domain Local Group:
Create a Domain Local group on both the source and target domain called DomainNetBiosName$$$ example: WINZERO$$$. Add 3 $ signs to the local group name. DO NOT add members to this group.
Enable Auditing:
Enable Account Management sucess and failure Auditing for both the domain and domain controller for both the source and target domain.
You will need to reboot the server for the auditing to take effect.
Register DLLs:
On the target domain PDC emulator register clonepr.dll.
Copy Clonepr.dll to the Windows directory from the WADMigrator working directory.
Open the command prompt
Type regsrv32 drive:\Windows\clonepr.dll to successfully register the dll.
Password Policies:
Check and verify that the source minimum domain password policy and restrictions less or equally restrictive to any target domain password policy. Passwords will not migrate if the password policy of the target domain is more restrictive then the password policy of the source domain.
After installation of WADMigrator Verify the following registry setting on both the target and sourec PDC emulators.
Registry Settings:
Check, add and verify the registry settings of the PDC or PDC emulator or FSMO server. (Usually the first installed domain controller in the source domain)
HKEY_LOCAL_MACHINE
SYSTEM\CurrentControlSet\Control\Lsa
Key: AllowpasswordExport
Type: DWORD
Set to: 1
HKEY_LOCAL_MACHINE
SYSTEM\CurrentControlSet\Control\Lsa
Key: RestrictAnonymous
Type: DWORD
Set to: 0
HKEY_LOCAL_MACHINE
SYSTEM\CurrentControlSet\Control\Lsa
Key: TcpipClientSupport
Type: DWORD
Set to: 1
HKEY_LOCAL_MACHINE
SYSTEM\CurrentControlSet\Services\Tcpip\Parameters
Key: MaxUserPort
Type: DWORD
Set to: 0x0000fffe (hex) or 65534 (decimal)
Thursday, February 12, 2009
WADMigrator Premigration Checklist
Posted by
AMS
at
3:21 PM
2
comments
Labels: AD Migration Checklist, WADMigrator, WADMigrator checklist, Windows Firewall, Winzero Active directory Migrator
Friday, February 06, 2009
Winzero Releases WADMigrator

Winzero Releases the next solution in Active Directory Migration Challenges - Winzero Active Directory Migrator ensuring coexistence between migrated and un-migrated users, simplifing the migration processes with automated resource updating and continued support during and after the migration process.
Whether migrating to meet specific economic challenges or undergoing acquisition, mergers or divestitures, Winzero Active Directory Migrator provides the features necessary to meet your evolving needs and budget.
Posted by
AMS
at
9:49 AM
0
comments
Labels: Active Director Migration, Virtual Domain Migration, WADMigrator, Winzero Active directory Migrator
Tuesday, November 11, 2008
PasswordCopy Issue
Bulletin: 111108
Software Effected:
ServerMigrator, PasswordCopy and WADMigrator
Issue:
Just recently Microsoft has released an update that is preventing passwordcopy from accessing the system32 directory that a number of our clients started experiencing in the last week.
Solution:
We have identified this issue and have resolved it. There will be a new ServerMigrator and PasswordCopy available starting November 12th that over rides the password copy problem some of our clients were experiencing.
New Update Releases:
ServerMigrator2007 version 5.10
PasswordCopy32 version 3.00
WADMigrator version 5.00
* PasswordCopy Server Edition and Domain Edition will be repalced with PasswordCopy32 followed by PasswordCopy64.
Posted by
AMS
at
10:00 AM
0
comments
Labels: Password Copy Issue, PasswordCopy
Sunday, October 26, 2008
Virtual Migration Part 6 Custom Remaping
Once the common update process of associating source and target accounts for servers and workstations are complete, the Virtual Consultant will use Winzero addons and scripts to associate source and target SIDs for additional resource that are not part of a standard migration.
The Virtual Consultant will follow a set of guidelines to verify that all unique directories and applications that rely on Netbios Name or SID access are updated.
Using Winzero Update Process Addons
The virtual consultant will verify and update resources as needed using the Winzero Migration Addon Tools for the following resources to maintain coexistance during the migration process.
Roaming or mandatory profiles
Exchange 5.5 account associations
Exchange 200x account associations
SQL Server upto version 7
SQL Server 2000/2005
NAS and SAN Server permissions
Using Winzero Custom Scripting
Using the Winzero scripting utility, the Virtual Consultant will identify any unique applications that require updating and automate the update process for:
Any inhouse applications
Once the update process is complete, the Virtual Consultant will conduct a controlled migration of a typical user to verify that all access to resources has been maintained.
Posted by
AMS
at
10:07 AM
0
comments
Labels: Custom Scripting, Recource Update, Step 6 Virtual Migration, Winzero Addons
Saturday, August 02, 2008
Virtual Migration Part 5 - Resource Remapping
The most crucial aspect of the migration is the Update process. This is how the new target SIDS are associated with the Source SIDS. This processes runs locally on each computer and may take any where from 2 minutes to 5 minutes for workstations and 4 minutes to 6 hours on servers. Because this process is multitasked the total time required is the time required to update the largest server and to locate all workstations. In order for the updater to successfully execute on the remote machine the computer must be online, reachable through DNS or WINS and the account used for the update must have administrative rights locally on the remote computer.
The Virtual Consultant will begin the update process and continue to update all workstations and servers until all computers have been updated using the report information gathered from the Directory Object Extractor Reports.
The Update process runs on the remote computer in the background without disruption to the logged on user. The process appends the target SID of the migrated object every where the source SID has rights or permissions. The Update process appends Local group membership, Share, Folder and File permissions, local profiles, mapped drives, connected printers and user rights.
Using the update method, two essential migration requirements are met. One the virtual consultant running the migration project knows exactly which user and computers are ready to be cut over to the target domain and most importantly the end user now has the exact same rights and permissions in the target domain as they had in the source domain including the same desktop and profile settings.
Posted by
AMS
at
4:24 PM
0
comments
Labels: Profile update, SID remap, Step 5 Virtual Migration, Update process
