ADMT 3.2 weird issue in 2008 R2 - Audit directory service access problem
hello,
i scratching head on following problem , after couple of days decided ask help.
my source domain 2003 , has 3 dcs, target 2008 r2 with 1 dc. set auditing in default domain controllers policy as required in admt 3.2 guide:
computer configuration | policies | windows settings | security settings | local policies | audit policy
audit account management - success , failure
audit directory service access - success
applied with gpupdate /force , computer reset.
but when run account migration wizard throws error:
auditing not enabled on target domain. enable auditing? if not, sid migration disabled.
yes / no / cancel
i go yes , wizard works fine times. not every time - noticed if in moment i keep window open (eg while doing else) for more ~5 minutes migration fails , logfile shows error auditing not enabled. when continue without pause works fine.
when @
computer configuration | policies | windows settings | security settings | local policies | audit policy
after allow wizard enable auditing can see that audit directory service access set no auditing. that does not make much sense to me...
i looked @ computer configuration | policies | windows settings | security settings | advanced audit policy config | audit policies and options , suboptions here stay unmodified on not defined.
now this problem becomes weirder - if keep policy way , run admt again throws same error , offers me enable me again. if click yes and look @ domain controllers policy again don't see change there, audit directory service access still set no auditing. wizard end succesfully again.
problem is unrealiable , can not use scripts problem didn't find out way how turn auditing on in script. when run vbscript user account migration sid history same error:
# c:\windows\syswow64\cscript.exe admt-users-sid-pass.wsf
c:\utils\admt-users-sid-pass.wsf(42, 5) admt.migration.1: unable migrate users. following configuration required sid history has not been performed. auditing has not been enabled in target domain. unspecified error (0x80004005)
but if i run gui wizard first , let enable auditing abiout approximately 5 minutes after wizard changes script works fine - no error and logfile in admt folder shows success. looks like the change which wizard makes either times out or overwritten else. cannot figure out changes.
does have idea going on wrong here?
thanks
hello martin p7,
please try to enabled "audit: force audit policy subcategory settings (windows vista or later) override audit policy category settings", still attempt set audit settings in 'computer configuration/windows settings/security settings/local policies/audit policies' location instead of computer configuration/windows settings/security settings/advanced audit configuration/audit policies.
security auditing settings not applied windows vista-based , window server 2008-based computers when deploy domain-based policy
http://support.microsoft.com/kb/921468
brent
please remember click “mark answer” on post helps you, , click “unmark answer” if marked post not answer question. can beneficial other community members reading thread. ”
Windows Server > Migration
Comments
Post a Comment