RE: interesting migration scenario

Tech Tip: Click here to run a free scan for Windows Errors and optimize PC performance



Matt,

SIDHistory doesn't (or didn't in 2000) persist multiple values so you would
lose the original SID and only have the intermediate SID in the final
location. This may have changed with some of the schema changes done in
2003, but I have run into this problem before in multi-domain joins.

If you are just moving Accounts and Groups, I think the risk is lower doing
the intra-forest migration with ADMT. This works well and risk can be
managed.

In any case, the key here is testing and grouping your migrations into
smaller, manageable waves.

Best wishes,
--
Ryan Hanisco
MCSE, MCTS: SQL 2005, Project+
Chicago, IL

Remember: Marking helpful answers helps everyone find the info they need
quickly.


"matt_heff" wrote:

I am trying to relocate an OU from a 2003 child domain to another 2003 child
domain in the same forest. I do not wish to do an intra-forest migration
because this will MOVE the OU from one domain to the other. I would rather
the OU is COPIED over to the other domain, maintaining SID history of course,
(so it is easier to roll back if necessary) but this is only possible in
inter-forest migrations.

So, I plan to migrate (copy) my OU out to a temp domain in a separate
forest, and then migrate (copy) it again to the target child domain back in
the original forest. With the trusts in place, this should make
rollback a snap if necessary.

I'll use gpmc to copy the GPOs once the trusts are in place.

Has anyone ever tried this or know an easier way to do this?

Thanks,

Matt

.



Relevant Pages

  • Re: is it posible to change users sid
    ... Again, as Jorge mentions, the GUID and SID for any two objects are ... Active Directory also attempts to enforce uniqueness on a per ... domain or per forest basis for a number of other identity related ...
    (microsoft.public.windows.server.active_directory)
  • Re: Urgent: Add a user from a trusted forest to a Group in my forest
    ... You'll need to query the other forest to get the SID ... Co-author of "The .NET Developer's Guide to Directory Services Programming" ... But how will i get the SID of an user from the trusted forest? ...
    (microsoft.public.windows.server.active_directory)
  • RE: Unknown GUID in User List
    ... It sounds like you are seeing the SID for a user who either no longer ... or who belongs to another forest which may have ... Please provide more information about the environment if this does not ... | control but the GUID has not been resolved to a user name. ...
    (microsoft.public.win2000.active_directory)
  • Re: Change IP and subnet mask of DC
    ... Populate SIDHistory of new user objects of SID from old domain ... *** So you propose to add a new domain to the same forest and then migrate ... OU with their SID. ... Are you mixing test and prod on the same network ...
    (microsoft.public.windows.server.active_directory)
  • Re: ADAM userProxy objectclass
    ... We will match a sIDHistory too. ... a sIDHistory value of some sid, and there is a proxy with that sid, ADAM ... > either in the same domain, or same forest, or a trusted domain/forest. ...
    (microsoft.public.windows.server.active_directory)