| Previous | Next |
| ERROR_DS_MUST_BE_RUN_ON_DST_DC | ERROR_DS_CANT_TREE_DELETE_CRITICAL_OBJ |
ERROR_DS_SRC_DC_MUST_BE_SP4_OR_GREATER
The source PDC is too old for the protected SID-history workflow
For a Windows NT 4.0 source domain, Microsoft requires the source PDC used by DsAddSidHistory to run Service Pack 4 or later. The requirement is tied to auditing and protected source-domain operations, not to the Windows version of the migration workstation or destination domain controller.
Verify the actual source PDC selected by the migration, including its service-pack level and whether discovery is reaching an unexpected backup controller. Upgrade or replace the legacy controller before continuing. Do not suppress the check or route around the PDC, because the same workflow also depends on source auditing, the special audit group, and authenticated RPC access to retrieve the source SID.
What to inspect
- Identify the source PDC used by the call.
- Verify its operating-system and service-pack level.
- Recheck auditing and TcpipClientSupport after remediation.
References
- Microsoft: Windows NT source PDC and SP4 requirement
- MS-ADTS: PDC and downlevel trust terminology
- Microsoft: protected migration administration
Looking for a different code? Search another status or error code.
