Domain Migration Administrator 7.6
How to migrate computers, files, folders, and shares to another domain with Domain Migration Administrator if both the source and the target OUs containing the computers are controlled by the FDCC Vista Security Settings GPO: FDCC v1.0 Q3 2008 Vista Security Settings
To work around this issue, disable the FilterAdministorToken security setting. You can disable this setting by importing the FDCC Workaround Security Settings GPO template to a temporary GPO. You can import the template by using Group Policy Management Console (GPMC), Active Directory Users and Computers, or NetIQ Group Policy Administrator. For more information, see the Microsoft or NetIQ Group Policy Administrator documentation. Ensure you have downloaded the template, the link is at the bottom of this page
To Migrate Computers with FDCC Vista GPO:
- Create and link an empty GPO in the root of the domain.
- Import the FDCC Workaround Security Settings GPO template to the empty GPO.
- Ensure no other GPOs can override the FDCC Workaround Security Settings GPO:
- If using GPMC, right-click the GPO and select Enforced.
- If using Active Directory Users and Computers, select No Override: Prevents other Group Policy Objects from overriding policy set in this one on the Group Policy tab in the GPO Properties.
- After Group Policy replication, migrate computers, files, folders, and shares by using Domain Migration Administrator. For more information, see the User Guide for Domain Migration Administrator.
- After migration, disable the link of the GPO you created in Step 1.
When you migrate computers, files, folders, or shares from a source domain to a target domain, with both source and target domain under an Organisational Unit with FDCC Vista security settings, the migration fails.