Logo
Windows XP
Windows Vista
Windows 7
Windows Azure
Windows Server
Windows Phone
EPL Standings
 
 
Windows Server

Microsoft Exchange Server 2007 : Consolidating a Windows 2000 Domain to a Windows Server 2003 Domain Using ADMT (part 2) - Installing a Password Migration DLL on the Source Domain

- 2015 Chevrolet Camaro Z28 - The Legend Returns
- Wagon Audi Allroad Vs. Subaru Outback
- 996 Carrera 4S is Driving Perfection
3/16/2014 1:58:27 AM
Exporting Password Key Information

A 128-bit encrypted password key must be installed from the target domain on a server in the source domain. This key allows for the migration of password and SID history information from one domain to the next.

To create this key, follow these steps from the command prompt of a domain controller in the target domain where ADMT is installed:

1.
Insert a floppy disk into the drive to store the key. (The key can be directed to the network but, for security reasons, directing to a floppy is better.)

2.
Change to the ADMT directory by typing cd C:\program files\active directory migration tool, where C: is the OS drive. Then press Enter.

3.
Type admt key <SourceDomainName> a: <password>, where <SourceDomainName> is the NetBIOS name of the source domain, a: is the destination drive for the key, and <password> is a password that is used to secure the key. Refer to Figure 2 for an example. Then press Enter.

Figure 2. Exporting the password key.

4.
Upon successful creation of the key, remove the floppy and keep it in a safe place.

Installing a Password Migration DLL on the Source Domain

A special password migration dynamic link library (DLL) must be installed on a domain controller in the source domain. This machine will become the Password Export Server for the source domain. The following procedure outlines this installation:

1.
Insert the floppy disk with the exported key from the target domain into the server’s disk drive.

2.
Insert the Windows Server 2003 CD into the CD-ROM drive of the domain controller in the source domain where the Registry change will be enacted.

3.
Start the Password Migration Utility by choosing Start, Run, and typing d:\i386\ADMT\Pwdmig\Pwdmig.exe, where d: is the drive letter for the CD-ROM drive. Then click OK.

4.
At the welcome screen, click Next.

5.
Enter the location of the key that was created on the target domain; normally, this is the A: floppy drive, as indicated in Figure 3. Click Next to continue.

Figure 3. Setting up the password migration DLL.


6.
Enter the password twice that was set on the target domain, and click Next.

7.
At the Verification page, click Next to continue.

8.
Click Finish after the installation is complete.

9.
The system must be restarted, so click Yes when prompted to automatically restart. Upon restarting, the proper settings will be in place to make this server a Password Export Server.

Setting Proper Registry Permissions on the Source Domain

The installation of the proper components creates special Registry keys but leaves them disabled by default, for security reasons. You need to enable a specific Registry key to allow passwords to be exported from the Password Export Server. The following procedure outlines the use of the Registry Editor to perform this function:

1.
On a domain controller in the source domain, open the Registry Editor (Start, Run, Regedit).

2.
Navigate to HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa.

3.
Double-click the AllowPasswordExport DWORD value.

4.
Change the properties from 0 to 1–Hexadecimal.

5.
Click OK and close the Registry Editor.

6.
Reboot the machine for the Registry changes to be enacted.

At this point in the ADMT process, all prerequisites have been satisfied, and both source and target domains are prepared for the migration.

Top Search -----------------
- Windows Server 2008 R2 : Work with RAID Volumes - Understand RAID Levels & Implement RAID
- Windows Server 2008 R2 Administration : Managing Printers with the Print Management Console
- Configuring Email Settings in Windows Small Business Server 2011
- Windows Server 2008 R2 : Configuring Folder Security, Access, and Replication - Implement Permissions
- Monitoring Exchange Server 2010 : Monitoring Mail Flow
- Windows Server 2008 R2 :Task Scheduler
- Windows Server 2008 R2 : File Server Resource Manager
- Windows Server 2008 R2 : Installing DFS
- Exchange Server 2010 : Managing Anti-Spam and Antivirus Countermeasures
- Windows Server 2008 R2 : Configuring Folder Security, Access, and Replication - Share Folders
Other -----------------
- Microsoft Exchange Server 2007 : Upgrading Separate AD Forests to a Single Forest Using Mixed-Mode Domain Redirect (part 2)
- Microsoft Exchange Server 2007 : Upgrading Separate AD Forests to a Single Forest Using Mixed-Mode Domain Redirect (part 1)
- Windows Server 2012 : Provisioning and managing shared storage (part 7) - Managing shared storage - Managing volumes, Managing shares
- Windows Server 2012 : Provisioning and managing shared storage (part 6) - Managing shared storage
- Windows Server 2012 : Provisioning and managing shared storage (part 5) - Provisioning SMB shares - Creating general-purpose SMB shares
- Windows Server 2012 : Provisioning and managing shared storage (part 4) - Provisioning SMB shares - Configuration options for SMB shares, Types of SMB shares
- Windows Server 2012 : Provisioning and managing shared storage (part 3) - Provisioning shared storage - Creating volumes
- Windows Server 2012 : Provisioning and managing shared storage (part 2) - Provisioning shared storage - Creating virtual disks
- Windows Server 2012 : Provisioning and managing shared storage (part 1) - Provisioning shared storage - Creating a storage pool
- Microsoft Exchange Server 2010 : Completing Transport Server Setup (part 8) - Configuring Transport Rules
 
 
Most view of day
- Visual Basic 2010 : Implementing WCF Data Services
- Upgrading to SharePoint 2010 : Performing a Database Attach Upgrade
- BizTalk 2010 Recipes : EDI Solutions - Configuring an EDI Envelope
- System Center Configuration Manager 2007 : Network Design - Network Discovery
- Exchange Server 2010 : Using EMS to Do Administrative Mailbox Tasks (part 2)
- Microsoft PowerPoint 2010 : Adding a Digital Signature to a Macro Project & Assigning a Macro to a Toolbar or Ribbon
- Service-Orientation with .NET : Entity Abstraction with a .NET REST Service
Top 10
- Microsoft Exchange Server 2007 : Consolidating a Windows 2000 Domain to a Windows Server 2003 Domain Using ADMT (part 5) - Migrating Computer Accounts
- Microsoft Exchange Server 2007 : Consolidating a Windows 2000 Domain to a Windows Server 2003 Domain Using ADMT (part 4) - Migrating User Accounts
- Microsoft Exchange Server 2007 : Consolidating a Windows 2000 Domain to a Windows Server 2003 Domain Using ADMT (part 3) - Migrating Groups
- Microsoft Exchange Server 2007 : Consolidating a Windows 2000 Domain to a Windows Server 2003 Domain Using ADMT (part 2) - Installing a Password Migration DLL on the Source Domain
- Microsoft Exchange Server 2007 : Consolidating a Windows 2000 Domain to a Windows Server 2003 Domain Using ADMT (part 1) - Modifying Default Domain Policy on the Target Domain
- Microsoft Exchange Server 2007 : Upgrading Separate AD Forests to a Single Forest Using Mixed-Mode Domain Redirect (part 2)
- Microsoft Exchange Server 2007 : Upgrading Separate AD Forests to a Single Forest Using Mixed-Mode Domain Redirect (part 1)
- Windows Server 2012 : Provisioning and managing shared storage (part 7) - Managing shared storage - Managing volumes, Managing shares
- Windows Server 2012 : Provisioning and managing shared storage (part 6) - Managing shared storage
- Windows Server 2012 : Provisioning and managing shared storage (part 5) - Provisioning SMB shares - Creating general-purpose SMB shares
Windows XP
Windows Vista
Windows 7
Windows Azure
Windows Server
Windows Phone
2015 Camaro