Microsoft Active Directory Migration

Environment
  • Microsoft Active Directory 2000 / 2003 / 2008

Servers Migration
  • Security translation
  • Service account translation
  • Manual join domain, and then reboot

Longer Distance
  • More the number of retries more, and shorter the retry interval (mins), when starting agent actions

Unable to Access Server Service on the Machine 'Hostname'. Make Sure Netlogon and Workstation Services Are Running And You Can Authenticate Yourself to the Machine
  • Check the shared folder - admin$ & c$, permission

ERR2:7006 Failed to Install Agent on \\hostname, rc=5 Access Is Deined
  • This would course "ERR2:7667 Unable to Access admin$", and "ERR2:7666 Unable to Access Server Service" also
  • Ensure client is disabled firewall and enabled file sharing. This can be via group policy if Active Directory, or setting registry if NT Domain
  • If the server can't ping to there, edit the %windir%\system32\drivers\etc\hosts, or if there is wrong DNS server setting

ERR2:7666 Unable to Access Server Service on the Machine
  • Set the user account, which runs migration tools, to be local administrator

Computer Migration Fail Not Find Solution
  • Wanna save time, or not find other solutions
  • Manual join the new domain
  • Restore the user profile
    • Desktop
    • Favorite
    • My Documents

Error - Windows cannot connect to the domain, either because the domain controller is down or otherwise unavailable , or because your computer account was not found. Please try again later. If this message continues to appear, contact your system administrator for assistance
User can't login, get this error after the reboot of migration
  • dis-join the domain, not reboot
  • Re-join the domain, reboot
  • If still can't, delete the computer account also after dis-join

ERR2:7674 Unable to determine the local path for ADMIN share on the machine
  • Check if there is shared ADMIN$

Others
  • If can't migrate the computer via add traction
    • If the destination already have the host, delete it and run again migrate to add the computer
  • If computer migrate fail, and if wanna manual join the domain
    • Should not delete the created account, and then go to manual join
    • The computer may still success to join the domain, however, the account may not be here
    • If that, follow the Error - Windows cannot connect to the domain
  • If agent operation success, and post-check fail
    • User account still can't login via the new domain account
    • This may be caused by the trust relationship between server and client
    • If that, follow the Error - Windows cannot connect to the domain 
  • If nslookup and ping can find the domain controller, client still can't join
    • Try to rename the client's hostname, and then join again