ADMT USER MIGRATION


I have a pre-created user accounts in the target domain.  Their logon name (samAccoutnName) is different in the target domain.  My goal to migrate an account from the source domain, merge it with the corresponding account in the target domain and maintain the source SID in the migrated object.
Migration Plan:
My plan is to use an input file (include file) for the migration.  This file contains a mapping between source and target user account.  I am using a TXT file. You can use CSV or any other format.  Here is an example of my include file:

Migration Procedure:

1.  Open Active Directory Migration Tool console. 

2.  Right click on the Active Directory Migration Tool node and select User Account Migration Wizard. 

image

3.  On the Welcome window, select the correct source and target domains and domain controllers.  Click Next

image

4.  Select Read object from an include file option on the User Selection Option window.  Click Next

image

5.  In the Input File Selection window, click Browse and select the previously created include file.  Click Next

image

6.  On the Organization Unit Selection window, select the correct destination OU.  Click Next

image

6.  Select appropriate option on the Password Options window.  Click Next

image

7.  Select appropriate option on the Password Options window. Make sure to select Migrate user SIDs to target domain option.  Click Next.

image

8.  On the User Account window, enter the proper credentials.  Click Next

image

9.  Select appropriate options on the User Options window.  Click Next. 

image

10. Select appropriate options on the Object Properties Exclusion window. Click Next.

image

11.  Select the following options on the Conflict Management window.  Click Next

    • Migrate and merge conflicting objects
    • Uncheck Before merging remove user rights for existing target account – I have some pre-assigned groups and don’t want to remove those. 
    • select Move merged objects to the specified target Organizational Unit – I am moving user objects from a pre-created OU to Migrated OU after the migration. 

image

12.  Click Finish to complete the user migration process. 

image
13.  You will see the migration status on the Migration Process window. 

image

Your target account should be merged and have the same SID in the sIDHistory attribute. 
Sid and sIDHisotry Info:
When a User object migrated from one domain to another, a new SID must be generated for the user account and stored in the ObjectSID property. Before the new value is written to the property, the previous value (ObjectSID from source domain) is copied to another property of a User object, sIDHistory in the Target domain. So you can use the sIDHistory value to search the Source domain using the ObjectSID attributes to identify the corresponding user in the Source domain. In other words, the sIDHistory value will be equal to the source ObjectSID.  You can SID and sIDHistory using the following procedure:

image

Advertisements

Leave a Reply

Fill in your details below or click an icon to log in:

WordPress.com Logo

You are commenting using your WordPress.com account. Log Out / Change )

Twitter picture

You are commenting using your Twitter account. Log Out / Change )

Facebook photo

You are commenting using your Facebook account. Log Out / Change )

Google+ photo

You are commenting using your Google+ account. Log Out / Change )

Connecting to %s

%d bloggers like this: