To perform an intraforest account domain migration
- Migrate domain global groups using the Group Migration Wizard.
More information
- In an , when global groups are migrated from a , the groups are migrated over correctly, but are created as universal groups in the so that they can contain members from the source domain that have not been migrated yet.
- If you are migrating a distribution group (these only exist in Windows 2000) from the source domain to the target domain and the group exists in the target domain as a security group, the target group will remain a security group even if the Replace option is selected.
- Migrate users and roaming profiles using the User Migration Wizard.
More information
- On the User Options wizard page, select the Translate roaming profiles and Update user rights check boxes.
- Active Directory Migration Tool only migrates user rights in additive mode. That is, the user rights of existing users and groups in the target domain will not be removed during a migration operation.
- If there is a large number of user accounts in the domain, when the User Migration Wizard builds the list of user accounts in a domain, retrieving this information can take a significant amount of time and may cause a significant impact on your network traffic.
- The user principal name suffix attribute of migrated user accounts is left empty by default but an implicit user principal name suffix of the current domain exists by default for each domain. For example, if the target domain is microsoft.com, the implicit user principal name for users migrated to that domain is UserName@microsoft.com.
- As part of the migration process, Active Directory Migration Tool determines to which global groups the user account in the source domain belongs. The tool then checks its migrated objects table to see if any of those global groups have previously been migrated. If a match is found, that means that the group was previously migrated from the source domain, and the user is added to this group.
- Migrate local profiles on workstations using the Security Translation Wizard.
More information
- On the Translate Objects wizard page, select the User Profiles check box.
- On the Security Translation Options wizard page, select the Add check box.
- Manually migrate a domain controller from the account domain and decommission the domain.
More information
- Use the Active Directory Installation Wizard to demote the domain controllers in the . For more information about the Active Directory Installation Wizard, see Windows 2000 Server Help.
- When demoting the last domain controller in the source domain, select the This server is the last domain controller in the domain check box on the Remove Active Directory wizard page of the Active Directory Installation Wizard.
- Once a domain controller has been demoted, it can join the target domain or be promoted to domain controller in the target domain.
Important
- When performing an , first migrate , and then migrate .
- Run the wizards in the order listed for best results.
Notes
- When running the User Migration Wizard, Group Migration Wizard, or Security Migration Wizard, you must be logged on to the target domain as an administrator or member of the Administrators group.
- When migrating a user, group, or computer account that exists in both the source and target domains, if the account in the target domain already has a value for a particular property and the account in the source domain does not have a value for that property, the value of the property in the target domain will be preserved. It will not be overwritten by the null-value of the property in the source domain.
- When migrating users and groups between domains in the same forest, Active Directory Migration Tool must communicate with the Relative ID (RID) pool master in the target domain. To improve performance when migrating a large number of users or groups, you should install Active Directory Migration Tool on the RID pool master in the target domain. By default, this is the first domain controller installed in the domain. Use Active Directory Users and Computers or Ntdsutil.exe to locate the domain controller that holds the RID pool master role.
- During the migration process, this tool truncates user account names that are more than 20 characters long.
Related Topics