24 December, 2010

Transitioning Service Accounts {ADMT 3.0}

The Wizard

(Make sure you run this wizard on the destination domain controller logged in as the administrator of the source domain)

We will select a "User Account Migration Wizard" while migrating a Service Account because a Service Account is nothing but a User Account + SPN Registered for that User Account



Select the Source and the Destination Domain and the Domain Controller




Select the Service Account (Actually a User Account) to be Migrated



Select an OU in the Destination Domain where you want to store this Service Account after Migration



Password Options: Generate complex passwords


Account Transition Options: Enable target accounts / Migrate user SIDs to target domains


As stated in the previous post (http://www.adshotgyan.com/2010/12/ad-migration-process-admt-30.html), Auditing has to be Enabled on the Source and the Destination Domain. You don't have to enable the Auditing manually, this get enabled automatically by the ADMT Wizard


Auditing before getting enabled on Source Domain


Auditing after getting enabled on Source Domain


Auditing before getting enabled on Destination Domain


Auditing after getting enabled on Destination Domain


As stated in the previous post (http://www.adshotgyan.com/2010/12/ad-migration-process-admt-30.html), one of the requirement of ADMT is to create a local group in the source domain in the format of <NetBIOS Name of the source domain+$$$> (Source$$$). Again, you don't have to create the group, ADMT Wizard give you an option to create the group automatically







User Options: Update user rights



Conflict Management: Do not migrate source object if a conflict is detected in the target domain


Service Account Information: Migrate all service accounts and update SCM for items marked include