Hello,
I think this problem is concerning Sid Filtering on your trust.
- Can you please verify that the Sid Filtering is correctly disabled ?
http://technet.microsoft.com/en-us/l.../cc772816.aspx
- Can tou dump the user Token and confirm that is member of the correct
groups (source / target)
Whoami /all
Regards,
Karim Said-Lalouani
"M-O" <M-> a écrit dans le message de news:
M-...
>
> we have two w2k3-forests which we have to consolidate. (migrate user,
> groups, server to the new forest). the two domains are full trusted and
> SID-filter is disabled.
> we have installed admt3 on the target-domain, pes on the source-domain
> without any errors. so long it works fine.
> Then we migrated some user and groups to the target-domain for
> test-purpose from Dom_source to Dom_target. Now the problem:
>
> - user logs on the target domain
> - user tries to get access to a shared folder an a fileserver in the
> source-domain
> - that doesn't work, access denied error
> - when creating a new shared folder on fileserver in source-dom,
> access works well
> - when running admt security-wizard against fileserver, user has
> access to the "old" fileshare-folder
>
>
> Of cause we have migrated groups and users with SID-history.
>
> can someone explain this to me?
> I believed that the SID-history of the migrated user in the target-dom
> is the "key" to get access on ressources in the source-dom.
> Why have I run security-wizard against the fileserver ?
> Why is the access-denied-error only for old shares and folders ?
>
> of cause, when I give ntfs-rights from target-dom to this shared
> folders, it works again fine.
>
>
> --
> M-O
> ------------------------------------------------------------------------
> M-O's Profile: http://forums.techarena.in/members/m-o.htm
> View this thread: http://forums.techarena.in/server-migration/1055942.htm
>
> http://forums.techarena.in
>