Security Translation

To migrate the security settings for extra domain objects, run the Security Translation Wizard on the Action menu in ADMT. The Security Translation Wizard changes the SIDs in ACLs and SACLs on objects that do not belong to the domain or that are not migrated as part of the Computer Migration Wizard. This wizard uses many of the same dialog boxes as the Group Account Migration Wizard; therefore, only the dialog boxes that are unique to the Security Translation Wizard are displayed in this section. Refer to the section entitled "Migrating Group Accounts" earlier in this chapter to see the remaining dialog boxes.

Follow these steps to migrate the security settings for extra domain objects:

  1. Choose to test only or migrate Start by selecting whether to test the effects of the security translation or actually to perform the migration. Select Test The Migration Settings And Migrate Later to run the migration in Test mode, or choose Migrate Now to perform the group merge operation.

    Tip

    It is a good idea to do a test run prior to performing the security translation because it will allow you to discover and resolve errors.

  2. Select translation options In the Security Translation Options dialog box (as shown in the following screen), you can select previously migrated objects or use a SID mapping file. A SID mapping file is constructed by using comma-separated pairs of source–destination references (name or SID) specified on each line of a text file. You can use this file to migrate security for accounts that are skipped by the Group Account Migration Wizard (such as Administrators).

    image with no caption
  3. Select the domains Next you must provide the source and destination domain names. Enter the DNS or NetBIOS names of the domains (if the destination domain is the forest root, you must provide the DNS name).

  4. Select the computers In the Computer Selection dialog box, select the computers on which to perform the security translation. Click Add, click Advanced, click Find Now, and then select the relevant computers.

  5. Select objects to translate Locate and select the objects on the source computer for which you want to translate the security settings. The SIDs assigned to ACLs and SACLs for the selected objects are translated to corresponding security descriptors on the objects in the destination domain. Objects available for security translation include files and folders, local groups, printers, shares, registry, user profiles, and user rights, yet none are selected by default.

  6. Specify security translation options You can decide how SIDs are translated by selecting one of the following options:

    • Replace—Replaces SIDs referencing objects in the source domain accounts and adds the SIDs to the account in the destination domain

    • Add—Maintains original set of SIDs references while adding SIDs to the account in the destination domain

    • Remove—Deletes the SIDs applied to the ACLs and SACLs and removes the permissions to access source domain objects

The summary of the security translation is shown next. Check the information before you click Finish to perform the translation. If you are running in Test mode, verify that the line Changes Will Not Be Written is present, which indicates that this migration is running in Test mode and will not actually perform the requested changes. Once completed, you can click View Log to review each action taken during the merge process.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset