Re: NT4 domain migration to Active Directory questions

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance

From: ptwilliams (ptw2001_at_hotmail.com)
Date: 02/22/05


Date: Tue, 22 Feb 2005 18:18:51 -0000

I don't quite follow your questions, but I'll answer this:

> Would it still be possible to migrate the NT4 users, groups and computers
> into this AD domain at a later
date? Would SID loss occur resulting in broken security? In other words,
is it possible/practical to migrate an NT4 domain into an existing domain?
The AD domain would no longer be pristine at the time of the migration.

Yes, nothing wrong with that. The domain doesn't have to be empty to
migrate into (although it has to be in Native mode for ADMT). Remember,
some of us consolidate multiple NT domains into a single, flat forest
(domain). This means that at some point, the domain is far from empty...

-- 
Paul Williams
http://www.msresource.net/
http://forums.msresource.net/
"Leroy Pierce" <LeroyPierce@discussions.microsoft.com> wrote in message 
news:1C552D47-5D73-4220-B56D-E55E5B68F6F9@microsoft.com...
Our existing network is based on a single WindowsNT4 domain for employees.
Our web portal project will be based entirely on an Active Directory tree.
We have the forest root and a single portal subdomain already established
with the idea of migrating the NT domain into a separate subdomain.  Due to
timelines, development of the portal project including the employee 
subdomain
will occur prior to the actual migration of the NT4 employee domain.
What is the best way to give the functionality of the employee subdomain
prior to the actual migration of the NT4 domain?  Several options have been
discussed including:
1. Create a pristine version of the employee subdomain and populate it with
groups and OUs appropriate to the portal project.  Later move/migrate the 
NT4
domain users, groups and computers into it.  This would allow the portal
security to be established immediately.  Would it still be possible to
migrate the NT4 users, groups and computers into this AD domain at a later
date?  Would SID loss occur resulting in broken security?  In other words, 
is
it possible/practical to migrate an NT4 domain into an existing domain?  The
AD domain would no longer be pristine at the time of the migration.
2. Migrate a copy of the NT4 domain into the new AD subdomain.  While the
domains would not be in sync, SIDs and security associations may be
preserved.  Would it be possible to effectively resync on the NT4 domain is
migrated?
Any suggestions or answers would be greatly appreciated.
Thanks,
--Leroy


Relevant Pages

  • NT4 domain migration to Active Directory questions
    ... Our existing network is based on a single WindowsNT4 domain. ... prior to the actual migration of the NT4 employee domain. ... What is the best way to give the functionality of the employee subdomain ... it possible/practical to migrate an NT4 domain into an existing domain? ...
    (microsoft.public.windows.server.migration)
  • Re: Upgrading from NT 4.0 to Server 2003
    ... In-place upgrade of the NT domain to AD ... SID of the security principals (user, groups and computers does not change. ... and a migration tool like ADMT is also not needed. ... existing NT4 domain. ...
    (microsoft.public.windows.server.active_directory)
  • The target domain is not native mode - Query
    ... I am currently working on our NT4 Domain to W2K3 AD Domain migration ... Does that mean that I must set my W2K3 AD domain to native mode? ... access my NT4 Domain server via the current 2-way trust relationship? ... Windows Server 2003? ...
    (microsoft.public.windows.server.migration)
  • RE: NT4 domain password migration to 2003 AD domain
    ... allow non complex password in order to migrate user accounts from NT4 ... When you migrate from NT4 to 2003, in User Account Migration Winzard, there ... NT4 domain password migration to 2003 AD domain ...
    (microsoft.public.windows.server.migration)
  • Re: NT4 domain migration to Active Directory questions
    ... > Assuming only the second question was not clear... ... > use this new subdomain for our web portal project; ... > employee users using the NT4 domain, then later migrate the NT4 domain ... >> The AD domain would no longer be pristine at the time of the migration. ...
    (microsoft.public.windows.server.active_directory)