Migrating Domain Trusts

To enable migrated users to have the same level of access to network resources managed in multiple domains, migration of an existing domain is likely to include the migration of established domain trusts. Because Active Directory domain trusts are transitive, when migrating Windows 2000 domains, the trusts are commonly external trusts to down-level domains or trusts implemented to speed lookups between domains.

When migrating from Windows NT 4, it is common that you have both account domains and resource domains that must be migrated. Typically, the resource domains have an explicit trust relationship with the account domains, in which the resource domain trusts the account domain.

To be able to migrate the Windows NT 4 account domains and maintain the capability for users to access network resources in the established resource domains, the resource domains must also trust the new destination domain. Thus, you must establish an explicit trust relationship from each resource domain to the Windows Server 2003 destination domain prior to migrating the user accounts domain.

Likewise, when you migrate a resource domain to the new Windows Server 2003 destination domain, you must establish a trust with the existing Windows NT 4 accounts domain prior to performing the migration of the resource domains.

Groups can contain only members from domains that are trusted; thus, to migrate group accounts that exist in trusted domains, you must establish an explicit trust from the destination domain to the source Windows NT 4 accounts domain. You can use the Trust Migration Wizard to perform these domain trust migrations.

Migrating a Trust

To migrate a trust relationship to the Active Directory directory service, run the Trust Migration Wizard on the Action menu in ADMT as follows:

  1. Select the domains You must supply the source and destination domain names. Specify from which domain to obtain the trust information and to which domain to migrate it. Enter the DNS or NetBIOS names of the domains (if the destination domain is the forest root, you must provide the DNS name).

  2. Select the trusts The Trust Information dialog box is displayed (see the following screen), showing the trusts established in the selected domain. Once you select the trust to migrate, click Copy Trust to begin the trust migration. You are next prompted to supply credentials (user name and password) for an account with the authority to migrate the trust (Domain Admins).

    image with no caption
..................Content has been hidden....................

You can't read the all page of ebook, please click here login for view all page.
Reset