ADMT, sIDHistory : access denied with group based ACL


hello,

i'm trying migrate accounts using admt. disabled sid filtering , enabled sid history , user account able access shared folder added source account in acl of folder. however, if remove acl use group, no longer access folder.

my user member of group (of course). sidhistory attribute both on group , user populated sid of source objects. it's pretty weird :-/ missed don't know what.

the migration involve windows 2008 , windows 2012 r2 active directories.

thank !

hi,
have disabled sid filtering on both domain side? if not, please have try using netdom command below that:
netdom trust sourcedomainname /domain:targetdomainname /quarantine:no /usero:<user name> /passwordo:<password> (source side)
netdom trust targetdomainname /domain:sourcedomainname /quarantine:no /usero:<user name> /passwordo:<password> (target side)
, enabling sid history:
netdom targetdomainname /domain: sourcedomainname /enablesidhistory:yes

and scope group? if group universal/global, might not access resource.
in addition, please validate trust.
here similar thread, refer detail discussion in it:
unable access resources in source domain after admt migration
https://social.technet.microsoft.com/forums/windows/en-us/fe4b23d1-cebb-4bca-8b9c-0671af34e6ee/unable-to-access-resources-in-source-domain-after-admt-migration?forum=winservermigration
best regards,
wendy


please remember mark replies answers if , unmark them if provide no help.
if have feedback technet subscriber support, contact tnmff@microsoft.com.



Windows Server  >  Migration



Comments

Popular posts from this blog

WIMMount (HSM) causing cluster storage to go redirected (2012r2 DC)

Failed to delete the test record dcdiag-test-record in zone test.com

Azure MFA with Azure AD and RDS