ADMT 3.2 "Could not verify auditing and TcpipClientSupport on domains. Will not be able to migrate Sid's. The specified domain either does not exist or could not be contacted."

Siddhesh Sawant 46 Reputation points
2020-09-28T11:21:12.993+00:00

Hi,

We are migrating few of our users (Along with there SIDs) from ABC Forest to XYZ forest with the help of MS ADMT 3.2 (Active Directory migration tool). Following are the DC's and ADMT Machine's Configuration:

  1. Source DC (ABC.com) - Windows Server 2008 R2 Standard
  2. Target DC (XYZ.com) - Windows Server 2019 Datacenter
  3. ADMT Machine - Windows Server 2012 R2 (Connected to Target DC)

While migrating user's accounts, On "Account Transition Options" window, if we select any option in "Target Account State" only and proceed every thing works as expected. But along with when we ticked "Migrate user SIDs to target domain" checkbox, tool throws below error.

---------------------------

Error

---------------------------

Could not verify auditing and TcpipClientSupport on domains. Will not be able to migrate Sid's. The specified domain either does not exist or could not be contacted.

---------------------------

---------------------------

28728-image.png

I can able to ping/Nslookup both the domains from ADMT machine as well as from DC to DC. Is there any thing else i have to verify to trouble shoot this issue?

Windows for business | Windows Client for IT Pros | Directory services | Active Directory
0 comments No comments
{count} votes

4 answers

Sort by: Most helpful
  1. Vicky Wang 2,741 Reputation points
    2020-09-29T06:53:07.63+00:00

    Hi,@SiddheshSawant-1300
    Judging from the error report, the network problem has caused the failure to contact the DC to be migrated.
    Whether the port required for the normal work of ADMT is open can not be confirmed through PING/NSLOOKUP. Please refer to the following connection to confirm that the necessary ports have been opened, and the influence of blocked ports on ADMT has been excluded.

    1. How to configure a firewall for Active Directory domains and trusts:

    https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/config-firewall-for-ad-domains-and-trusts

    1. ADMT Migration and Network Ports: http://techgenix.com/admt-migration-and-network-ports/
    2. ADMT Series – 1. Preparing Active Directory : https://blog.thesysadmins.co.uk/admt-series-1-preparing-active-directory.html

    Hope this information can help you
    Best wishes
    Vicky

    0 comments No comments

  2. Siddhesh Sawant 46 Reputation points
    2020-09-29T18:53:05.143+00:00

    Thanks @Vicky Wang

    Have checked all the security ports (Mentioned in the links in your last post) From Target to Source, Source to Target and Source/Target to ADMT Machine. I can able to Telnet each and every port, Port on which at least one service has hosted. Following are my observation:

    1. On Both the DCs, we have configured Stub Zone on DNS Server. (Do i have to Configure Conditional Forward only?)
    2. One-way trust is in place, where Source trusts Target forest. (Do i need two-way trust?) Ref URL: https://learn.microsoft.com/en-us/troubleshoot/windows-server/identity/inter-forest-sidhistory-migration-with-admt.
    0 comments No comments

  3. Vicky Wang 2,741 Reputation points
    2020-10-01T08:25:53.18+00:00

    Hi,
    Thank you for the update.
    Because your question is more complex and difficult, it exceeds the scope of our forum’s knowledge
    After discussing with our colleagues, we suggest that you find more professional engineers for help, they can give you more professional and quick answers.
    Thank you for your understanding and support
    reference:https://support.microsoft.com/en-in/hub/4343728/support-for-business
    Best wishes
    Vicky

    0 comments No comments

  4. Michał Witwicki 6 Reputation points
    2023-07-13T14:50:55.79+00:00

    I have the same error message, does anyone have any idea what else can be done?

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.