The Active Directory Migration Tool allows you to copy user accounts and groups from one domain to another. This product provides many options to help you migrate the user accounts and groups exactly as you need. For example, you can specify how the Active Directory Migration Tool handles the passwords for the copied user accounts. You can also test the process first to examine the user accounts and groups without copying them to the target domain.
Warning: When you migrate user accounts and groups, the tool creates all the accounts before copying the properties of those accounts. This process ensures Windows 2000 accounts that reference the distinguished names of other Windows 2000 objects in their properties, such as the Manager property, are correctly migrated. For example, if UserA is the manager of UserB, and you migrate both accounts at the same time, UserA and UserB need to exist before the tool can correctly set the Manager property of UserB. If you interrupt the migration process before it is finished, accounts may exist without the properties correctly set. You should allow the migration process to finish completely. |
When the tool migrates user accounts, the tool sets the User must change password at next logon property for each migrated user account. If the Password never expires property is set for a user account, the tool clears the Password never expires property for that user account.
Notes:
|
Local groups can contain members defined in other domains. Therefore, processing local groups can be a bit more complicated than processing global groups and user accounts. When adding a local group member in the target domain, the Active Directory Migration Tool processes the group members in the following manner:
Note: If you have mapped a group to a different group in the target domain, and then you migrate that group from the source domain to the target domain, the mapping information is replaced. The group is then mapped to the migrated group in the target domain. |