2000 to 2003 migration to NEW domain

Tech-Archive recommends: Repair Windows Errors & Optimize Windows Performance

From: Gary Heller (zookeeper_at_gmail.com)
Date: 08/02/04


Date: 2 Aug 2004 13:35:01 -0700

While most people are upgrading to 2003, we're tasked with also moving
people to a new domain (was previously just a single domain forest).

 My question arises from security.

 As JOEUSER gets processed thru the ADMT meat packing plant, out comes
a sausage with a new SID and also a SIDhistory so they can access old
resources across this bi-directional trust we've established for the
domains.

 So when the old 2000 Domain-1 goes away and there is only the new
2003 Domain-2 left, what comes of the old security? Especially on
people with, say, laptops that have to access local stuff? Does the
SIDhistory go away? And if it does, will they still be able to access
everything?

 Just concerned since most people do this kind of thing one piece at a
time, not simultaneously. The brass want people logging onto this
"new domain" as soon as possible. Gotta love company politics.

Thanks,
Gary Heller
Philadelphia, PA



Relevant Pages

  • Re: Migrate computer acounts and profiles
    ... The use of SIDhistory is temporary so that users can still access resources ... security on the client, and translate profiles (at this moment users start ... For more info on migrating to an AD domain also see: ... > So you would not do security translation when using sidHistory? ...
    (microsoft.public.windows.server.active_directory)
  • Re: W2k3 AD migration to W2k3 AD - HELP HELP!!
    ... Setup trusts (if an external trust is configured and sidhistory is used, ... Install and configure migration tooling ... user accounts with passwords and group memberships (with ... Translate security of the data/resources from source security ...
    (microsoft.public.windows.server.migration)
  • Re: W2k3 AD migration to W2k3 AD - HELP HELP!!
    ... Setup trusts (if an external trust is configured and sidhistory is used, ... Install and configure migration tooling ... Translate security of the data/resources from source security ...
    (microsoft.public.windows.server.migration)
  • Re: root forest AD DC crashed
    ... it is another forest root domain. ... Setup trusts (if an external trust is configured and sidhistory is used, ... Install and configure migration tooling ... Translate security of the data/resources from source security ...
    (microsoft.public.win2000.active_directory)
  • Re: Migrate computer acounts and profiles
    ... then there is no need to re-ACL (translate security) (because the SIDs do ... ADMT is only when migrating from one domain to another ... although using SIDhistory you would still need to do security ... >> * Migrate clients from the source domain to the target domain, translate ...
    (microsoft.public.windows.server.active_directory)