Convert Resource Domain to User Domain ?

DomainA is a Resource Domain(RD) and DomainB used to
be the Master Doman(MD).  Now DomB is going away, so DomA is its own user domain.  I've to recreate all the users in DomA.
But, my resource permissions is DomA used to be from MD. It means, permissions are set for DomB\UserX or DomB\GroupX.  Now, I have to re-apply all the permissions back from DomB\UserX to just UserX.  Luckily 90% of my permissions are Group based, so all I have to do is to re-define the local group memberships.  But, in some cases, there are explicit out of domain references.  How should I find where these are ? and change the references.
I tried to use, SHOWACLS, SHOWMBRS etc.. from RKit but they don't work properly for wildcards !  I am thinking of
manually go through directories and check for permissions which might take a century by the time I am done.

Any easy solution to this?  If so, please let me know.  I am in desperate need.  Thank you.

Srini.
LVL 5
snimmagaAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

y96andhaCommented:
Use
 CACLS *.* /T >filename.txt
and then search the resulting textfile for references to the old domain name.

If you really have lots of permissions to change, it might be faster to write a program for it, but as I understand it, there are not many places to change, just many places to look in that might need to be changed?
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
snimmagaAuthor Commented:
Thank you, though the answer gives me a direction to look into, I was expecting a more detailed easier way.
ThanX again..
0
y96andhaCommented:
Do you need to search anything else than files?
0
Learn Ruby Fundamentals

This course will introduce you to Ruby, as well as teach you about classes, methods, variables, data structures, loops, enumerable methods, and finishing touches.

snimmagaAuthor Commented:
Actually, there is a global group from the Master User domain which has permissions (varying) on all the directories in the Resource domain.  Now, after I drop the Trust, I need to create a local group with the same members in the RD and replace the original Group with this new local group in all the acls.
This is just one example.  There are other scenarios similar to this.  Now, I should list all the directories which are referencing the old Global group and make changes to those directories, alone.  OR I should replace everywhere in my RD, the old group with the new group.  
What happens, if it is a single user from a different domain who has permissions set on a resource in the RD?  How many scenarios do I have?  I don't know.  I have to study.  It looks quite tedious to me and am wondering if there any 3rd party tools or something which can help make things easier.
Thank you for your continued interest.
Srini.
0
y96andhaCommented:
Well, using cacls *.* /t will at least show you what you are dealing with. If you are lucky, you'll only find a few references to the domain name in this file.

If you find there are too many, maybe it would be possible to write some kind of program. It very much depends on how many different changes need to be made, only replacing one group with an other is simple.
0
snimmagaAuthor Commented:
Thank you, I will look into this.  I need some time to evaluate my options.  I will let you know, once I find an easy way out.

Thanks again.
Srini.
If you want me to e-mail to you in future, please send me you e-mail.  My email is, snimmaga@ford.com

0
snimmagaAuthor Commented:
Thank you, I will look into this.  I need some time to evaluate my options.  I will let you know, once I find an easy way out.

Thanks again.
Srini.
If you want me to e-mail to you in future, please send me you e-mail.  My email is, snimmaga@ford.com

0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows Networking

From novice to tech pro — start learning today.