<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.microsoft.co.il/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Yuval Sinay : Forest Migration</title><link>http://blogs.microsoft.co.il/blogs/yuval14/archive/tags/Forest+Migration/default.aspx</link><description>Tags: Forest Migration</description><dc:language>en</dc:language><generator>CommunityServer 2007.1 (Build: 20917.1142)</generator><item><title>How to install ADMT 3.2 on Windows 2008 R2 SP1 Domain Controller</title><link>http://blogs.microsoft.co.il/blogs/yuval14/archive/2011/09/26/how-to-install-admt-3-2-on-windows-2008-r2-sp1-domain-controller.aspx</link><pubDate>Mon, 26 Sep 2011 05:39:17 GMT</pubDate><guid isPermaLink="false">b5c4f5bc-c09b-4439-a595-91a98c1847df:906013</guid><dc:creator>yuval14</dc:creator><slash:comments>5</slash:comments><wfw:commentRss xmlns:wfw="http://wellformedweb.org/CommentAPI/">http://blogs.microsoft.co.il/blogs/yuval14/rsscomments.aspx?PostID=906013</wfw:commentRss><comments>http://blogs.microsoft.co.il/blogs/yuval14/archive/2011/09/26/how-to-install-admt-3-2-on-windows-2008-r2-sp1-domain-controller.aspx#comments</comments><description>&lt;p&gt;The following post will cover the installation process of Microsoft ADMT 3.2 on Windows 2008 R2 SP1 Domain Controller.&lt;/p&gt; &lt;p&gt;Please note: Microsoft recommended to install the ADMT 3.2&amp;nbsp; tool a non domain controller computer. Using ADMT 3.2&amp;nbsp; on Domain Controller may reduce the security level of all the Domain Controller in the organization.&lt;/p&gt; &lt;p&gt;The installation process in divided to four sections:&lt;/p&gt; &lt;p&gt;1. SQL 2008 Express installation.&lt;/p&gt; &lt;p&gt;2. ADMT 3.2 installation.&lt;/p&gt; &lt;p&gt;3. ADMT 3.2 Configuration.&lt;/p&gt; &lt;p&gt;4. Enable Password Migration.&lt;/p&gt; &lt;p&gt;Note: In the past ADMT tool used Access database to save the migration configurations and data. ADMT 3.2 require to use SQL database.&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;b&gt;&lt;font size="4"&gt;1. SQL Express Installation&lt;/font&gt;&lt;/b&gt;&lt;/p&gt; &lt;p&gt;1.1 Download SQL 2008 Express x64.&lt;/p&gt; &lt;p&gt;&lt;a href="http://www.microsoft.com/download/en/details.aspx?id=25052"&gt;Microsoft® SQL Server® 2008 Express Edition Service Pack 1&lt;/a&gt;&lt;/p&gt; &lt;p&gt;Note: ADMT 3.2 doesn’t support SQL 2008 R2.&lt;/p&gt; &lt;p&gt;1.2&amp;nbsp; Logon into the target domain controller.&lt;/p&gt; &lt;p&gt;1.3 Launch &amp;quot;&lt;i&gt;SQLEXPR_x64_ENU.exe&lt;/i&gt;&amp;quot; file.&lt;/p&gt; &lt;p&gt;1.4&amp;nbsp; Press on the link &amp;quot;Installation&amp;quot;: &lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image001_069B3323.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image001" border="0" alt="clip_image001" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image001_thumb_58CD6A5D.jpg" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.5 Press on the link&amp;nbsp; &amp;quot;&lt;i&gt;New SQL Server stand-alone installation or add feathers to exiting&amp;nbsp; installation&lt;/i&gt;&amp;quot;:&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image002_5B26EC5B.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image002" border="0" alt="clip_image002" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image002_thumb_6D8F3D10.jpg" width="244" height="183" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.6 Press on &amp;quot;&lt;i&gt;Ok&lt;/i&gt;&amp;quot; button and then press on &amp;quot;&lt;i&gt;Next&lt;/i&gt;&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image003_12AC877D.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image003" border="0" alt="clip_image003" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image003_thumb_02510FC4.jpg" width="244" height="183" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.7&amp;nbsp; Mark the checkbox &amp;quot;&lt;i&gt;I accept the license term&lt;/i&gt;&amp;quot; and press on &amp;quot;&lt;i&gt;Next&lt;/i&gt;&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image004_3297E47A.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image004" border="0" alt="clip_image004" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image004_thumb_4BB33EB2.jpg" width="244" height="182" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.8 Press on &amp;quot;&lt;i&gt;Install&lt;/i&gt;&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image005_42E33666.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image005" border="0" alt="clip_image005" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image005_thumb_60751165.jpg" width="244" height="183" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.9 Press on &amp;quot;&lt;i&gt;Next&lt;/i&gt;&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image006_10BBE61C.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image006" border="0" alt="clip_image006" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image006_thumb_5BCEE0DE.jpg" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.10 Mark the checkbox &amp;quot;Database Engine Services&amp;quot; and then Press on &amp;quot;Next&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image007_32E3CBD5.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image007" border="0" alt="clip_image007" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image007_thumb_49566A5C.jpg" width="244" height="182" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.11 Press on &amp;quot;&lt;i&gt;Next&lt;/i&gt;&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image008_355CD7C6.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image008" border="0" alt="clip_image008" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image008_thumb_60C0F8C0.jpg" width="244" height="183" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.12 Press on &amp;quot;&lt;i&gt;Next&lt;/i&gt;&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image009_1EDA1372.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image009" border="0" alt="clip_image009" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image009_thumb_7516987E.jpg" width="244" height="183" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.13 Set the database engine to use &amp;quot;Administrator&amp;quot; account (or any equivalent domain account that is member of domain admins group) and press on &amp;quot;&lt;i&gt;Next&lt;/i&gt;&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/Capture_255D6D35.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="Capture" border="0" alt="Capture" src="http://blogs.microsoft.co.il/blogs/yuval14/Capture_thumb_57E0CAA7.png" width="244" height="182" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.14 Add the domain admins group and Administrator account as &amp;quot;SQL Server Administrator&amp;quot; and press on &amp;quot;Next&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/Capture_40661676.png"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="Capture" border="0" alt="Capture" src="http://blogs.microsoft.co.il/blogs/yuval14/Capture_thumb_0BE5442E.png" width="244" height="187" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.15 Press on &amp;quot;&lt;i&gt;Next&lt;/i&gt;&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image012_4272EF72.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image012" border="0" alt="clip_image012" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image012_thumb_469CC737.jpg" width="244" height="183" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.16 Press on &amp;quot;&lt;i&gt;Next&lt;/i&gt;&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image013_76E39BED.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image013" border="0" alt="clip_image013" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image013_thumb_7B79A6A7.jpg" width="244" height="184" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.17 Press on &amp;quot;&lt;i&gt;Install&lt;/i&gt;&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image014_40B1FDD1.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image014" border="0" alt="clip_image014" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image014_thumb_24C0C8D9.jpg" width="244" height="183" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;1.18 Press on &amp;quot;&lt;i&gt;Close&lt;/i&gt;&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image015_4DE86117.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image015" border="0" alt="clip_image015" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image015_thumb_59317554.jpg" width="244" height="183" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;font size="4"&gt;&lt;b&gt;2 &lt;/b&gt;&lt;b&gt;ADMT 3.2 Installation&lt;/b&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;2.1 &lt;a href="http://www.microsoft.com/download/en/details.aspx?id=8377"&gt;Download Microsoft ADMT 3.2&lt;/a&gt;.&lt;/p&gt; &lt;p&gt;2.2 Logon into the target domain controller.&lt;/p&gt; &lt;p&gt;2.3 Run the following commands:&lt;/p&gt; &lt;p&gt;NET LOCALGROUP SQLServerMSSQLUser$&lt;b&gt;DomainControllerName&lt;/b&gt;$SQLEXPRESS /ADD&lt;/p&gt; &lt;p&gt;* The SQLServerMSSQLUser$&lt;b&gt;DomainControllerName&lt;/b&gt;$SQLEXPRESS group should be created as local domain group.&lt;/p&gt; &lt;p&gt;* To user that using the ADMT 3.2 should be added to SQLServerMSSQLUser$&lt;b&gt;DomainControllerName&lt;/b&gt;$SQLEXPRESS group.&lt;/p&gt; &lt;p&gt;SC SHOWSID MSSQL$SQLEXPRESS&lt;/p&gt; &lt;p&gt;MD %SystemRoot%\ADMT\Data&lt;/p&gt; &lt;p&gt;ICACLS %systemroot%\ADMT\Data /grant *&lt;b&gt;S-1-5-80-3881436512-7290199661-1648723128-3569869737-3631323143&lt;/b&gt;:F&lt;/p&gt; &lt;p&gt;&lt;b&gt;S-1-5-80-3881436512-7290199661-1648723128-3569869737-3631323143&lt;/b&gt; = The SID that was obtained by using SC SHOWSID MSSQL$SQLEXPRESS command.&lt;/p&gt; &lt;p&gt;Source:&amp;nbsp; &lt;a href="http://support.microsoft.com/kb/2266373"&gt;ADMT 3.2 installation incomplete, MMC console error &amp;quot;cannot open database &amp;#39;ADMT&amp;#39; requested by the login&amp;quot;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;2.4 Launch ADMT 3.2 setup.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image017_174A9006.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image017" border="0" alt="clip_image017" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image017_thumb_6D871512.jpg" width="244" height="218" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;2.5 Approve the EULA and press on Next button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image019_2BA02FC4.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image019" border="0" alt="clip_image019" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image019_thumb_6874B196.jpg" width="244" height="215" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;2.6 Press on Next button (Don’t choose to participate in the CEIP program).&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image021_0672BF8B.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image021" border="0" alt="clip_image021" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image021_thumb_2AB7A40D.jpg" width="244" height="218" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;2.7 Point the ADMT 3.2 Installation to &amp;quot; .\SQLEXPRESS&amp;quot; instance.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image023_68D0BEBE.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image023" border="0" alt="clip_image023" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image023_thumb_2D30AFFE.jpg" width="244" height="219" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;2.7 Press on &amp;quot;Next&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image025_4B2EBDF2.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image025" border="0" alt="clip_image025" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image025_thumb_086F72BA.jpg" width="244" height="218" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;2.8 Press on &amp;quot;Finish&amp;quot; button.&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image027_4D3B96EE.jpg"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image027" border="0" alt="clip_image027" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image027_thumb_4EBCB302.jpg" width="244" height="218" /&gt;&lt;/a&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;b&gt;&lt;font size="4"&gt;3. ADMT 3.2 Configurations&lt;/font&gt;&lt;/b&gt;&lt;/p&gt; &lt;p&gt;During the first running of ADMT 3.2 the following changes would be done automatically on the domain controllers that handle the migration process (usually source and target domain controller hosting PDC Emulator FSMO).&lt;/p&gt; &lt;p&gt;I recommended to allow the ADMT 3.2 wizard to set the required settings automatically and not make this changes manually.&lt;/p&gt; &lt;p&gt;3.1 On the target domain PDC Emulator FSMO, set the following registry key:&lt;/p&gt; &lt;p&gt;HKLM\System\CurrentControlSet\Services\Netlogon\Parameters&lt;/p&gt; &lt;p&gt;Registry value: AllowNT4Crypto&lt;/p&gt; &lt;p&gt;Type: REG_DWORD&lt;/p&gt; &lt;p&gt;Data: 1&lt;/p&gt; &lt;p&gt;3.2&amp;nbsp; On the PDC emulator of the &lt;u&gt;old&lt;/u&gt; domain set the following registry key:&lt;/p&gt; &lt;p&gt;HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA&lt;/p&gt; &lt;p&gt;Modify the registry entry TcpipClientSupport, of data type REG_DWORD, by setting the value to 1.&lt;/p&gt; &lt;p&gt;3.3 On the target domain PDC Emulator FSMO set the following Group Policy:&lt;/p&gt; &lt;blockquote&gt; &lt;p&gt;3.3.1&amp;nbsp; Click Start, point to All Programs, point to Administrative Tools, and&amp;nbsp;&amp;nbsp; then click Group Policy Management.&lt;/p&gt; &lt;p&gt;3.3.2&amp;nbsp; Navigate to the following node: Forest | Domains | Domain | Domain Controllers | Default Domain Controllers Policy&lt;/p&gt; &lt;p&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Right-click Default Domain Controllers Policy and click Edit. &lt;/p&gt; &lt;p&gt;3.3.3&amp;nbsp; In Group Policy Management Editor, in the console tree, navigate to the following node: Computer Configuration | Policies | Windows Settings | Security Settings | Local Policies | Audit Policy&lt;/p&gt; &lt;p&gt;3.3.4&amp;nbsp; In the details pane, right-click Audit account management, and then click Properties. &lt;/p&gt; &lt;p&gt;3.3.5&amp;nbsp; Click Define these policy settings, and then click Success and Failure. &lt;/p&gt; &lt;p&gt;3.3.6&amp;nbsp; Click Apply, and then click OK.&lt;/p&gt; &lt;p&gt;3.3.7&amp;nbsp; In the details pane, right-click Audit directory service access and then click Properties. &lt;/p&gt; &lt;p&gt;3.3.8&amp;nbsp; Click defines these policy settings and then click Success. &lt;/p&gt; &lt;p&gt;3.3.9&amp;nbsp; Click Apply, and then click OK.&lt;/p&gt; &lt;p&gt;3.12&amp;nbsp;&amp;nbsp; If the changes need to be immediately reflected on the domain controllesr, open an elevated command prompt and type gpupdate /force.&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;3.13&amp;nbsp; Reboot the PDC emulators servers in each domain.&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt; &lt;p&gt;&lt;font size="4"&gt;&lt;b&gt;4. &lt;/b&gt;&lt;b&gt;Enable Password Migration&lt;/b&gt;&lt;/font&gt;&lt;/p&gt; &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt; &lt;p&gt;The PES service installation in the source domain requires an encryption key. However, you must create the encryption key on the computer running ADMT in the target domain. &lt;/p&gt; &lt;p&gt;This way, you can store it in a secure location and reformat it after the migration is completed.&lt;/p&gt; &lt;p&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;4.1 On the target domain controller create a new encryption key:&lt;/p&gt; &lt;p&gt;admt key /option:create /sourcedomain: SourceDomainName.Local/keyfile:&amp;lt;KeyFilePath&amp;gt; /keypassword:{&amp;lt;password&amp;gt;|*}&lt;/p&gt; &lt;p&gt;Note: The source domain should set to: SourceDomainName.Local&lt;/p&gt; &lt;p&gt;4.2&amp;nbsp; On the old domain, logon into the PDC emulator.&lt;/p&gt; &lt;p&gt;4.3 Run the Pwdmig.msi that was created in the previous steps.&lt;/p&gt; &lt;p&gt;Note: You may need to provide the encryption &lt;/p&gt; &lt;p&gt;4.4 Follow the instructions bellow:&lt;/p&gt; &lt;blockquote&gt; &lt;h6&gt;&lt;font size="2"&gt;To configure the PES service in the source domain&lt;/font&gt;&lt;/h6&gt; &lt;p&gt;1. On the domain controller that runs the PES service in the source domain, insert the encryption key disk.&lt;/p&gt; &lt;p&gt;2. Run Pwdmig.msi. If you set a password during the key generation process on the domain controller in the target domain, provide the password that was given when the key was created, and then click &lt;strong&gt;Next&lt;/strong&gt;.  &lt;table style="color:#202020;" cellpadding="0"&gt;  &lt;tr&gt; &lt;td valign="bottom"&gt; &lt;p&gt;&lt;b&gt;Wizard page &lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="bottom"&gt; &lt;p&gt;&lt;b&gt;Action &lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top"&gt; &lt;p&gt;&lt;strong&gt;Welcome to the ADMT Password Migration DLL Installation Wizard&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top"&gt; &lt;p&gt;Click &lt;strong&gt;Next&lt;/strong&gt;.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top"&gt; &lt;p&gt;&lt;strong&gt;Encryption File&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top"&gt; &lt;p&gt;To install the ADMT Password Migration dynamic-link library (DLL), you must specify a file that contains a valid password encryption key for this source domain. The key file must be located on a local drive.&lt;/p&gt; &lt;p&gt;You use the &lt;strong&gt;admt key&lt;/strong&gt; command to generate the key files. For more information, see the previous procedure &amp;quot;To create an encryption key.&amp;quot;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top"&gt; &lt;p&gt;&lt;strong&gt;Run the service as&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top"&gt; &lt;p&gt;Specify the account that you want the PES service to run under. You can specify either of the following accounts:&lt;/p&gt; &lt;p&gt;· The local System account&lt;/p&gt; &lt;p&gt;· A specified user account  &lt;table style="color:#202020;" cellpadding="0"&gt;  &lt;tr&gt; &lt;td valign="bottom"&gt; &lt;p&gt;&lt;b&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image028_0CD5CDB4.gif"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image028" border="0" alt="clip_image028" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image028_thumb_2B400E9D.gif" width="10" height="10" /&gt;&lt;/a&gt;Note &lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top"&gt; &lt;p&gt;If you plan to run the PES service as an authenticated user account, specify the account in the format &lt;em&gt;domain&lt;/em&gt;\&lt;em&gt;user_name&lt;/em&gt;.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top"&gt; &lt;p&gt;&lt;strong&gt;Summary&lt;/strong&gt;&lt;/p&gt;&lt;/td&gt; &lt;td valign="top"&gt; &lt;p&gt;Click &lt;strong&gt;Finish&lt;/strong&gt; to complete the PES service installation.  &lt;table style="color:#202020;" cellpadding="0"&gt;  &lt;tr&gt; &lt;td valign="bottom"&gt; &lt;p&gt;&lt;b&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image0281_49AA4F86.gif"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;margin:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image028[1]" border="0" alt="clip_image028[1]" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image0281_thumb_361CEFE5.gif" width="10" height="10" /&gt;&lt;/a&gt;Note &lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top"&gt; &lt;p&gt;To use the password migration of ADMT, you must restart the server where you installed the PES service.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/p&gt; &lt;p&gt;3. After installation completes, restart the domain controller.&lt;/p&gt; &lt;p&gt;4. After the domain controller restarts, to start the PES service, point to &lt;strong&gt;Start&lt;/strong&gt;, point to &lt;strong&gt;All Programs&lt;/strong&gt;, point to &lt;strong&gt;Administrative Tools&lt;/strong&gt;, and then click &lt;strong&gt;Services&lt;/strong&gt;. &lt;/p&gt; &lt;p&gt;5. In the details pane, right-click &lt;strong&gt;Password Export Server Service&lt;/strong&gt;, and then click &lt;strong&gt;Start&lt;/strong&gt;.  &lt;table style="color:#202020;" cellpadding="0"&gt;  &lt;tr&gt; &lt;td valign="bottom"&gt; &lt;p&gt;&lt;b&gt;&lt;a href="http://blogs.microsoft.co.il/blogs/yuval14/clip_image0282_228F9044.gif"&gt;&lt;img style="background-image:none;border-bottom:0px;border-left:0px;padding-left:0px;padding-right:0px;display:inline;border-top:0px;border-right:0px;padding-top:0px;" title="clip_image028[2]" border="0" alt="clip_image028[2]" src="http://blogs.microsoft.co.il/blogs/yuval14/clip_image0282_thumb_7A10AE2F.gif" width="10" height="10" /&gt;&lt;/a&gt;Note &lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt; &lt;tr&gt; &lt;td valign="top"&gt; &lt;p&gt;Run the PES service only when you migrate passwords. Stop the PES service after you complete the password migration.&lt;/p&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/p&gt;&lt;/blockquote&gt; &lt;p&gt;Source:&amp;nbsp; &lt;a href="http://technet.microsoft.com/en-us/library/cc974435(WS.10).aspx"&gt;Enabling Migration of Passwords&lt;/a&gt;&lt;/p&gt; &lt;p&gt;4.5&amp;nbsp; Navigate to the following registry subkey on the source domain: HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\LSA&lt;/p&gt; &lt;p&gt;4.6 Verify that &amp;quot;AllowPasswordExport&amp;quot; (REG_DWORD) was set to 1.&lt;/p&gt; &lt;p&gt;4.7 Add target Domain Admin group as members of &amp;quot;Administrators&amp;quot; group in the source domain.&lt;/p&gt; &lt;p&gt;&amp;nbsp;&lt;/p&gt; &lt;p&gt;For further information, please review:&lt;/p&gt; &lt;p&gt;&lt;a href="http://blogs.technet.com/b/askds/archive/2010/07/09/admt-3-2-common-installation-issues.aspx"&gt;ADMT 3.2: Common Installation Issues&lt;/a&gt;&lt;/p&gt;&lt;img src="http://blogs.microsoft.co.il/aggbug.aspx?PostID=906013" width="1" height="1"&gt;</description><category domain="http://blogs.microsoft.co.il/blogs/yuval14/archive/tags/Migration/default.aspx">Migration</category><category domain="http://blogs.microsoft.co.il/blogs/yuval14/archive/tags/Active+Directory/default.aspx">Active Directory</category><category domain="http://blogs.microsoft.co.il/blogs/yuval14/archive/tags/ITPRO/default.aspx">ITPRO</category><category domain="http://blogs.microsoft.co.il/blogs/yuval14/archive/tags/Active+Directory+Migration+Tool/default.aspx">Active Directory Migration Tool</category><category domain="http://blogs.microsoft.co.il/blogs/yuval14/archive/tags/ADMT/default.aspx">ADMT</category><category domain="http://blogs.microsoft.co.il/blogs/yuval14/archive/tags/Domain+Migration/default.aspx">Domain Migration</category><category domain="http://blogs.microsoft.co.il/blogs/yuval14/archive/tags/Forest+Migration/default.aspx">Forest Migration</category></item></channel></rss>