<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Marcelo Hunecke - Blog de infraestrutura Microsoft : ADMT</title><link>http://blogs.technet.com/mhunecke/archive/tags/ADMT/default.aspx</link><description>Tags: ADMT</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>Como manter o SID History dos grupos Built-in?</title><link>http://blogs.technet.com/mhunecke/archive/2009/05/05/como-manter-o-sid-history-dos-grupos-built-in.aspx</link><pubDate>Tue, 05 May 2009 17:06:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3235723</guid><dc:creator>mhunecke</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mhunecke/comments/3235723.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhunecke/commentrss.aspx?PostID=3235723</wfw:commentRss><description>&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;As ferramentas de migração de domínios&amp;nbsp;(ADMT,&amp;nbsp;NetIQ DMA, Quest Migrator, etc) não permitem a migração grupos Built-In (Domain Users, Domain admins, etc) do Active Directory, isso significa que permissões atribuídas&amp;nbsp;a estes grupos serão&amp;nbsp;perdidas durante o processo de migração.&amp;nbsp;Para minimizar este impacto, recomenda-se o uso do script abaixo para adicionar o SID do grupo Built-In do&amp;nbsp;domínio origem&amp;nbsp;como SID History&amp;nbsp;no grupo Built-In do&amp;nbsp;domínio de destino.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;OBS.: O script sidhist.vbs encontra-se disponível no Support Tools do WIndows Server 2003.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;C:\Program Files\Support Tools&amp;gt;sidhist.vbs /srcdc:dc.dominio_origem&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt; /srcdom:dominio_origem /srcsam:"Domain Users" /dstdc:dc.dominio_destino /ds&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;tdom:dominio_destino /dstsam:"Domain Users"&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Microsoft (R) Windows Script Host Version 5.6&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;?xml:namespace prefix = o ns = "urn:schemas-microsoft-com:office:office" /&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Connected&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Success&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;C:\Program Files\Support Tools&amp;gt;sidhist.vbs /srcdc:dc.dominio_origem&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt; /srcdom:dominio_origem /srcsam:"Domain Admins" /dstdc:dc.dominio_destino /ds&lt;/FONT&gt;&lt;FONT size=3 face=Calibri&gt;tdom:dominio_destino /dstsam:"Domain Admins"&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;FONT size=3 face=Calibri&gt;Microsoft (R) Windows Script Host Version 5.6&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Copyright (C) Microsoft Corporation 1996-2001. All rights reserved.&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;o:p&gt;&lt;FONT size=3 face=Calibri&gt;&amp;nbsp;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Connected&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;Success&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;/FONT&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;onde:&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;STRONG&gt;dc_dominio_origem&lt;/STRONG&gt; é o FQDN do controlador de domínio do domínio origem, por exemplo: dc01.contoso.com&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;STRONG&gt;dominio_origem&lt;/STRONG&gt; é o nome DNS do domínio origem, por exemplo: contoso.com&lt;/FONT&gt;&lt;/P&gt;&lt;FONT size=3 face=Calibri&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;STRONG&gt;dc_dominio_origem&lt;/STRONG&gt; é o FQDN do controlador de domínio do domínio destino, por exemplo: dc01.msft.net&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;&lt;FONT size=3 face=Calibri&gt;&lt;STRONG&gt;dominio_destino&lt;/STRONG&gt; é o nome DNS do domínio destino, por exemplo: msft.net&lt;/FONT&gt;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style="MARGIN: 0in 0in 0pt" class=MsoNormal&gt;OBS.: Após o ajuste de permissões em todos os servidores/serviços,&amp;nbsp;recomenda-se a remoção do SID History. Caso a remoção não seja&amp;nbsp;feita poderão&amp;nbsp;haver problemas com o tamanho do Token de usuários que pertencem a muito grupos. (ver artigo sobre MaxTokenSize).&lt;/P&gt;&lt;/FONT&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3235723" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhunecke/archive/tags/ADMT/default.aspx">ADMT</category></item><item><title>Pré-requisitos para migração de computadores via ADMT</title><link>http://blogs.technet.com/mhunecke/archive/2009/05/05/pr-requisitos-para-migra-o-de-computadores-via-admt.aspx</link><pubDate>Tue, 05 May 2009 16:47:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3235702</guid><dc:creator>mhunecke</dc:creator><slash:comments>0</slash:comments><comments>http://blogs.technet.com/mhunecke/comments/3235702.aspx</comments><wfw:commentRss>http://blogs.technet.com/mhunecke/commentrss.aspx?PostID=3235702</wfw:commentRss><description>&lt;P&gt;Para a migração de contas de computador via ADMT - Active Directory Domain Migration, é necessário que os seguintes requisitos sejam atendidos nas estações/servidores que serão migradas ou mesmo onde rodará o Translate Security.&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;Firewall desativado;&lt;/LI&gt;
&lt;LI&gt;Compartilhamentos administrativos liberados; (&lt;SPAN style="mso-ansi-language: PT-BR" lang=PT-BR&gt;&lt;FONT size=3&gt;&lt;FONT face=Calibri&gt;caso não estejam liberados, é necessário alterar o valor da chave de registro&amp;nbsp;AutoShareServer e AutoShareWks para&amp;nbsp;1&amp;nbsp; em HKEY_LOCAL_MACHINE\SYSTEM\CURRENT CONTROL SET\SERVICE\LANMANSERVER\PARAMETERS e reiniciar o serviço de SERVER).&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;Serviço REMOTE REGISTRY, WORKSTATION, SERVER e NETLOGON rodando;&lt;/LI&gt;
&lt;LI&gt;Grupo do domínio Domain Admins do domínio origem como Administrador local de&amp;nbsp;todas as estações/servidores;&lt;BR&gt;&amp;nbsp;&lt;/LI&gt;&lt;/UL&gt;
&lt;P mce_keep="true"&gt;&amp;nbsp;&lt;/P&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3235702" width="1" height="1"&gt;</description><category domain="http://blogs.technet.com/mhunecke/archive/tags/ADMT/default.aspx">ADMT</category></item></channel></rss>