Task: User Migration (342)
Computer: workstation.new.domain (workstation)
Domain: new.domain (NEW)
OS: Windows 10 Enterprise 10.0 (19043)
Name: old.domain (OLD)
DC: OLDDC01.old.domain (OLDDC01)
OS: Windows Server 2008 R2 Enterprise 6.1 (7601) Service Pack 1
Name: new.domain (NEW)
DC: NEWdc01.new.domain (NEWDC01)
OS: Windows Server 2016 Standard 10.0 (14393)
Update Rights: No
Translate Roaming Profiles: No
Fix group membership: Yes
Conflict Option: Ignore
Migrate groups: No
Migrate service accounts: Yes
[Object Migration Section]
2021-09-30 10:52:55 Starting Account Replicator.
2021-09-30 10:52:57 Removing CN=users name (LDAP://OLDDC01.old.domain/CN=users name,OU=Disabled Users,DC=old,DC=domain) from the global groups it is a member of :
2021-09-30 10:52:57 ERR2:7621 Failed to move source object 'CN=users name'. Verify that the caller's account is not marked sensitive and therefore cannot be delegated. hr=0x8009030e No credentials are available in the security package
2021-09-30 10:52:57 Operation completed.
NOTE!! "Account is sensitive and cannot be delegated" is NOT checked for this user account.
ADMT worked up until a few weeks ago, but then stopped. We did recently update our Exchange servers to CU21. That would be the only major change to Active Directory that we've made between the last time ADMT worked and the time it stopped working.
This is critical because we are only about two thirds of the way through our domain migration. With ADMT out, we're stuck. Doe anyone have any suggestions on how to troubleshoot this problem? Thanks.