General Considerations for Migrations

Consider your source and destination (target) domains involved in the migration. The target domain must be an Active Directory domain running in Native mode (either Windows 2000 or Windows Server 2003). When evaluating your migration scenario, you must determine which types of migration you can do.

There are two types of migrations:

  • Interforest migrations Migrating from a Windows NT domain or a different Active Directory forest.

  • Intraforest migrations Migrating from an Active Directory domain within the current forest. Intraforest migration can also be used to consolidate multiple Active Directory domains into a single domain, easing management of users and groups under a single set of policies.

You must establish trust relationships between the destination domain and all domains trusted by the source domain (use the Trust Migration Wizard to assess and implement domain trusts for migration).

To be migrated, the source objects must be security principals—users, security groups (including Windows NT 4 local groups, domain local groups, and global groups), or computer accounts.

Any account (or other source object) that has a SID that already exists in the destination domain or forest cannot be migrated. For example, irrespective of the domain of origin, built-in accounts such as Administrators and Power Users cannot be migrated because they use identical SIDs.

When migrating user accounts, user names are limited to 20 characters in length—anything beyond 20 characters is ignored.

Tip

Null values in source domains do not overwrite values in the destination domain.

Commonly, when you migrate from Windows NT Server 4, the network environment is structured into Windows NT account domains and Windows NT resource domains. During the migration process, the user and group information is copied from the account domains, and the service account and local group information is copied from the resource domains. All this information is integrated into the destination domain. When migrating from Windows NT, always migrate the account domains first and then the resource domains— this will establish the user and group accounts prior to migrating resource permissions referencing those accounts.

..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset