Windows Admin Center ISSUE in Windows server 2019 RRS feed

  • Question

  • Evaluation Environment:

    Orchestrator Server & Windows Admin Center: SVR01 (windows server 2019)

    Source server: SVR02  IP:DHCP (windows server 2016)

    Destination Server: SVR03 IP:DHCP (windows server 2019)

    Install Progress:

    1. Install WAC ,Storage Migration Service in SVR01(orchestrator)
    2. Install Storage Migration Proxy in SVR03 (destination)
    3. Use domain user l2_cn11325 added into three of them local administrators group
    4. Open firewall rules and telnet successful

    Demanded Security requirements

    •A migration account that is an administrator on the source computers and the orchestrator computer.

    •A migration account that is an administrator on the destination computers and the orchestrator computer.

    •The orchestrator computer must have the File and Printer Sharing (SMB-In) firewall rule enabled inbound.

    •The source and destination computers must have the following firewall rules enabled inbound (though you might already have them enabled):

    • File and Printer Sharing (SMB-In)
    • oNetlogon Service (NP-In)
    • oWindows Management Instrumentation (DCOM-In)
    • oWindows Management Instrumentation (WMI-In)

    Tips: Installing the Storage Migration Service Proxy service on a Windows Server 2019 computer automatically opens the necessary firewall ports on that computer.

    •If the computers belong to an Active Directory Domain Services domain, they should all belong to the same forest. The destination server must also be in the same domain as the source server if you want to transfer the source's domain name to the destination when cutting over. Cutover technically works across domains, but the fully-qualified domain name of the destination will be different from the source...

    Evaluation Process:

    1. create a job and inventory your servers in svr01 (succeed)
    2. transfer data from svr03 (succeed)
    3. cut over to the new servers (failed)  

    ISSUE: popping up "we can can connect to the source computer using a local user accoutn. Fail: access is denied.

    we can can connect to the destination computer using a local user accoutn. Fail: access is denied"

    (fail to upload picture because until you are able to verify my account)

    Thursday, July 11, 2019 8:08 AM

All replies

  • You'll reach more WAC experts in dedicated forum over here.



    Regards, Dave Patrick ....
    Microsoft Certified Professional
    Microsoft MVP [Windows Server] Datacenter Management

    Disclaimer: This posting is provided "AS IS" with no warranties or guarantees, and confers no rights.

    Friday, July 12, 2019 12:54 AM
  • Hi SuperZhi,

    Sorry you are running into issues with Cutover.  It sounds like you are using a local user account for the cutover phase.  For cutover you need to be using accounts with Admin rights and permission to change computer objects in the Active Directory.  They must be domain accounts, not local accounts.  Please try using accounts with those permissions and see if that works for you and let me know.



    Wednesday, July 17, 2019 9:42 PM
  • Thanks for your answers. Finally, i found the root reason. One GPO policy to forbid access. Please see the picture. Delete the local administrators group, the error is missed.

    url: Local policies/User Rights Assignment

    deny access this computer from the network.

    (i want to upload picture but it always till me no permission. So pity 5_5!)

    Thursday, July 18, 2019 5:54 AM