Migrating Service Accounts

Although many services operate using the local system authority, the local system authority has no rights or permissions to access network servers or services. Thus, special service accounts are used to provide credentials to network services that access other computers operating on your network. Service accounts are essentially user accounts that are designated for special purposes. They are used to run a specific network service using a unique set of user credentials assigned to the network service.

To migrate service accounts, run the Service Account Migration Wizard on the Action menu in ADMT. The Service Account Migration Wizard uses many of the same dialog boxes as the Group Account Migration Wizard; thus, only dialog boxes specific to migrating service accounts are shown in this section. Refer to the section entitled "Migrating Group Accounts" earlier in this chapter to see the remaining dialog boxes.

Follow these steps to migrate service accounts:

  1. Select the domains You must select or supply the source and destination domain names. Enter the DNS or NetBIOS names of the domains (if the destination domain is the forest root, you must provide the DNS name).

  2. Update information In the Update Information dialog box (as shown in the following screen), you choose either to use the service account information already collected or to reacquire the information.

    image with no caption
  3. Select the source of the service account data In the Service Account Selection dialog box, you must specify the computer that contains the service accounts to migrate. To do so, click Add, click Advanced, click Find Now, and then select the computer with the service accounts.

  4. Deploy the agent When the ADMT Agent Monitor begins, it attempts to install itself onto the specified computer (by using a remote procedure call [RPC] connection to the ADMIN$ share). The Agent Monitor displays information about the service accounts discovered in the Summary, Monitoring Settings, and Server List (default) tabs. In addition to the list of service accounts, in the Service List tab you can obtain more information about the progress of the agent (by using the Agent Detail), and you can use the View Dispatch Log option to assess each step of the process. You can also initiate or end monitoring by clicking the Start Monitoring and Stop Monitoring buttons.

  5. Discover service accounts The Service Account Information dialog box displays the service account (by Computer, Account, Status, Service) and provides the option to select accounts to migrate (Skip/Include). If the status of an account is Update Failed, ADMT was unable to update the service. When the service is back online, select the service account, then refresh the account information by selecting the Update SCM Now option.

On the summary screen, you are congratulated on successfully defining the service account entries and are prompted to click Finish to complete the service account migration. Verify that the information is correct before doing this. Once completed, you can click View Log to review each action taken during the merge process.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset