windows-nt/Source/XPSP1/NT/admin/admt/documents/help-ms/admtinterforestacctmig.htm

123 lines
9.2 KiB
HTML
Raw Normal View History

2020-09-26 03:20:57 -05:00
<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0//EN"
"http://www.w3.org/TR/REC-html40/strict.dtd">
<HTML DIR="LTR">
<HEAD>
<TITLE>Perform an interforest account domain migration</TITLE>
<LINK REL="stylesheet" MEDIA="screen" TYPE="text/css" HREF="coUA.css">
<LINK REL="stylesheet" MEDIA="print" TYPE="text/css" HREF="coUAprint.css">
<SCRIPT LANGUAGE="JScript" SRC="shared.js"></SCRIPT>
<META HTTP-EQUIV="Content-Type" CONTENT="text-html;charset=Windows-1252">
<META HTTP-EQUIV="PICS-Label" CONTENT='(PICS-1.1 "<http://www.rsac.org/ratingsv01.html>" l comment "RSACi North America Server" by "inet@microsoft.com <mailto:inet@microsoft.com>" r (n 0 s 0 v 0 l 0))'>
<META NAME="MS.LOCALE" CONTENT="EN-US">
<META NAME="MS-IT-LOC" Content="Active Directory Migration Tool">
<META NAME="MS-HAID" CONTENT="a_ADMTInterforestAcctMig">
</HEAD>
<BODY>
<P CLASS="procLabel">To perform an interforest account domain migration</P>
<OL>
<LI>Create the Windows&nbsp;2000 target domain.</LI>
<P><A ID="expand" HREF="#" CLASS="expandToggle">More information</A></P>
<DIV CLASS="expand">
<UL>
<LI>For instructions on how to set up a Windows&nbsp;2000 domain or forest, see Windows&nbsp;2000 Server Help.</LI>
<LI>The <A ID="wPopup" HREF="HELP=ADMTGlos.hlp TOPIC=TargetDomain"> target domain</A> must be operating in <A ID="wPopup" HREF="HELP=ADMTGlos.hlp TOPIC=NativeMode"> native mode</A>.</LI>
</UL>
</DIV>
<LI>Establish trusts between the domains using the Trust Migration Wizard.</LI>
<P><A ID="expand" HREF="#" CLASS="expandToggle">More information</A></P>
<DIV CLASS="expand">
<UL>
<LI>You may also need to use <B>Active Directory Domains and Trusts</B> to manually create trusts between the source and target domain. Migrate the trusts before you migrate user accounts, service accounts, or local groups.</LI>
<LI>For details about creating trusts between domains, see Windows&nbsp;2000 Server Help and the Windows&nbsp;NT product documentation.</LI>
</UL></DIV>
<LI>Migrate global groups using the Group Migration Wizard.</LI>
<P><A ID="expand" HREF="#" CLASS="expandToggle">More information</A></P>
<DIV CLASS="expand">
<UL>
<LI>If you have mapped a group to a different group in the target domain, and then you migrate that group from the source domain to the target domain, the mapping information is replaced. The group is then mapped to the migrated group in the target domain.</LI>
<LI>If you are migrating a distribution group (these only exist in Windows&nbsp;2000) from the source domain to the target domain and group exists in the target domain as a security group, the target group will remain a security group even if the <B>Replace</B> option is selected.</LI>
<LI>If there is a large number of users in the domain, enumerating the users may take a significant amount of time and may impact your network bandwidth. To migrate many thousands of users you might want to migrate global groups and select to migrate their members with them.</LI>
</UL></DIV>
<LI>Identify and migrate user accounts using the User Migration Wizard.</LI>
<P><A ID="expand" HREF="#" CLASS="expandToggle">More information</A></P>
<DIV CLASS="expand">
<UL>
<LI>You can migrate user accounts incrementally. Begin with a small number of users as a pilot project to verify whether the new domain environment and all resource access works correctly. Then, migrate the remaining users in one or more groups.</LI>
<LI>When the tool migrates user accounts, users are prompted to change their passwords the first time they log on to the network. The tool will override the <B>Password never expires</B> option unless the account has been marked as a service account using the Service Account Migration Wizard.</LI>
<LI>If the <B>User cannot change password</B> check box is selected for a user account, that migrated user account will be locked until the Administrator resets the password because the user will not be able to reset the password.</LI>
<LI>Active Directory Migration Tool cannot determine if a particular user account is used by one or more services. If any user accounts in the source domain are used to allow services to log on, you must run the Service Account Migration Wizard and select any servers that are running service accounts. Then, Active Directory Migration Tool can build a list of the service accounts to be migrated before you run the User Migration Wizard. If the Password never expires property is set for a user account, the User Migration Wizard clears the <B>Password never expires</B> unless you have used the Service Account Migration Wizard first.</LI>
<LI>If there is a large number of user accounts in the domain, when the User Migration Wizard builds the list of user accounts in a domain, retrieving this information can take a significant amount of time and can cause a significant impact on your network traffic.</LI>
<LI>Active Directory Migration Tool only migrates user rights in additive mode. This means that the user rights of any existing users and groups in the target domain will not be removed during a migration operation.</LI>
<LI>The user principal name suffix attribute of migrated user accounts is left empty by default but an implicit user principal name suffix of the current domain exists by default for each domain. For example, if the target domain is microsoft.com, the implicit user principal name for users migrated to that domain is <I>UserName</I>@microsoft.com.</LI>
</UL></DIV>
<LI>Do one of the following:
<UL><LI>If you plan to migrate resource domains as part of the same migration process, see <A HREF="admtinterforestresmig.htm">To perform a interforest resource domain migration</A>.</LI>
<LI>Decommission the source account domain</LI>.
</UL>
</LI>
<P><A ID="expand" HREF="#" CLASS="expandToggle">More information</A></P>
<DIV CLASS="expand">
<UL>
<LI>If you plan to migrate resource domains as part of the same migration process, you should delay decommissioning the source account domain until the resource domain migration is complete. This will ensure that the source account domain controller will be available for service account migration, migration of <A ID="wPopup" HREF="HELP=ADMTGlos.hlp TOPIC=SharedLocalGroup">shared local groups</A>, and local workstation profile migration that may depend on a domain controller from the source account domain.</LI>
<LI>After all of the user accounts in an account domain have been migrated, you can migrate its domain controllers into the target domain just as you would in a resource domain migration.</LI>
</UL></DIV>
</OL>
<P class="important">Important</P>
<UL>
<LI>When performing an <A ID="wPopup" HREF="HELP=ADMTGlos.hlp TOPIC=InterforestMigration"> interforest migration</A>, first migrate <A ID="wPopup" HREF="HELP=ADMTGlos.hlp TOPIC=AccountDomain">account domains</A>, and then migrate <A ID="wPopup" HREF="HELP=ADMTGlos.hlp TOPIC=ResourceDomain">resource domains</A>.</LI>
<LI>Run the wizards in the order listed for best results.</LI>
</UL>
<P CLASS="note">Notes</P>
<UL>
<LI>When running the User Migration Wizard, Group Migration Wizard, or Security Migration Wizard, you must be logged on to the <I>target domain</I> as an administrator or member of the Administrators group.</LI>
<LI>The target domain must trust all domains that are trusted by the <A ID="wPopup" HREF="HELP=ADMTGlos.hlp TOPIC=SourceDomain">source domain</A> and must be trusted by all domains that trust the source domain. The Trust Migration Wizard allows you to compare and create the source and target domain trusts.</LI>
<LI>When migrating a user, group, or computer account that exists in both the source and target domains, if the account in the target domain already has a value for a particular property and the account in the source domain does not have a value for that property, the value of the property in the target domain will be preserved. It will not be overwritten by the null-value of the property in the source domain.</LI>
<LI>You should migrate the security IDs (SIDs) to the target domain when migrating users and groups. This will update the <A ID="wPopup" HREF="HELP=ADMTGlos.hlp TOPIC=SIDHistory">SID History</A> of the accounts. If you migrate accounts and do not update SID History for those accounts, the new accounts do not have the access the original accounts had until you translate security and the Exchange directory.</LI>
<LI>During the migration process, this tool truncates user account names that are more than 20 characters long.</LI>
<LI>Password complexity functions may limit the passwords the tool can assign to a user account. The tool can generate complex passwords that meet the minimum password length requirement and contain at least 3 lowercase letters, 3 uppercase letters, 3 numerical digits, and 3 symbols. If the generated password does not comply with the password complexity rules in the target domain, the tool disables the migrated user account.</LI>
</UL>
<P><A ID="relTopics" HREF="CHM=DomainMig.chm META=a_admtchkbeforeusing; a_ADMTBestPractices; a_ADMTRunWizard; a_ADMTInterforestResMig; a_admtbeforeintermig; a_admtunderstandtrust; a_TasksRetry; a_TasksUndoLast; a_ADMTOverview; a_ADMTUnderstandMigration; a_ADMTInterforestMig; a_ConceptDomMigSecurityIssues; a_conceptmigratingusersgroup; a_ADMTUnderstandTrust; a_ADMTSystemReq; a_ADMTBeforeInterMig">Related Topics</A></P>
</BODY>
</HTML>