Still celebrating National IT Professionals Day with 3 months of free Premium Membership. Use Code ITDAY17

x
?
Solved

Merge two Independent AD domains/forests & Exchange

Posted on 2010-09-21
5
Medium Priority
?
1,424 Views
Last Modified: 2012-05-10
I have two independent domains/forests, call them A.ORG.COM & B.ORG.COM; there is no common 'root' forest/domain.  Each forest/domain has been operating independently for years, now management wants to merge B.ORG.COM with A.ORG.COM and keep A.ORG.COM as the domain name.  
B.ORG.COM has over 25 AD servers and Exchange servers due to it being spread over a WAN with slow links.  Each site has it's own mailboxes; some sites are as small as 10 and others are around 300 users.  This was done so that the Users would see their email ‘leave’ as soon as they hit Send as well as to help with logon.  
I have searched for days for good articles concerning what I am trying to accomplish but cannot seem to find one that fits my scenario.  The articles I have read thus far are about establishing trusts to share resources or migrating both forests/domains to a new name.  I would love to just establish the two way trusts, but management is insistent that they no longer want B.ORG.COM to exist.
Thanks in advance.
0
Comment
Question by:haiven20
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
5 Comments
 
LVL 11

Expert Comment

by:Marc Dekeyser
ID: 33723378
Well if you use ADMT (active directory migration tool) you can move the users from B to A. Trusts will be needed for this. Depending on your exchange version you could do an interOrg migration to move the exchange data. Plan this carefully as it could prove to be a headache!
0
 
LVL 5

Expert Comment

by:smartsid
ID: 33723615
first, you need to create a trust between forests. You should go for uni-directional trust rather than birectional as Forest B.org.com will not be required after migration.
Then you can plan for Exchange routing. Are there two exchange organizations involved ?
0
 
LVL 9

Accepted Solution

by:
Chev_PCN earned 2000 total points
ID: 33723795
This is going to be a long-term project that will require careful planning.
I would suggest that you think about making B a child domain of A to ease the migration.
You will need to consider how the move will affect share permissions, databases, applications, and other shared resources using B's AD credentials.

Exchange is going to be a nightmare I'm afraid. From what I remember you cannot move an exchange server from one domain to another.

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q_22610895.html
http://www.petri.co.il/forums/showthread.php?t=25747
http://support.microsoft.com/kb/812453

You're also going to want to keep the @B email addresses for some time in parallel with the new A addresses to ensure smooth transition with no loss of comms from external contacts, which means changing your public DNS / MX records

You will also need to consider the infrastructure such as DNS servers, policies, DHCP, WINS, replication between sites
0
 

Author Comment

by:haiven20
ID: 33724168
Thanks to all three of you thus far, keep it coming.  I am hoping that they will let me either put a bidirectional trust in and be done with it, or maybe a root domain (ORG.COM) and have both A & B become a child of it.  But, also, if they stay this course I want to be able to give them all the information so that if things turn ugly....
0
 
LVL 9

Expert Comment

by:Chev_PCN
ID: 33724262
Putting in a root domain has both benefits and pitfalls.
One benefit is gaining extremely tight control of your top-level accounts like Enterprise admins.
You would also gain your 2-way transitive trust and be able to start your migration.
One consideration is that you can never get rid of the root domain. Once it's in, it's in for ever.

Some resources:
http://technet.microsoft.com/en-us/library/mergers_acquisitions_active_directory_prune_and_graft_restructuring_support_limitations%28WS.10%29.aspx
http://technet.microsoft.com/en-us/library/cc974332%28WS.10%29.aspx
http://technet.microsoft.com/en-us/library/aa996077%28EXCHG.65%29.aspx
0

Featured Post

Office 365 Training for IT Pros

Learn how to provision tenants, synchronize on-premise Active Directory, implement Single Sign-On, customize Office deployment, and protect your organization with eDiscovery and DLP policies.  Only from Platform Scholar.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A couple of months ago we ran into an issue that necessitated re-creating our Edge Subscriptions. However, when we attempted to execute the command: New-EdgeSubscription -filename C:\NewEdgeSub_01.xml we received an error indicating that the LDAP se…
One-stop solution for Exchange Administrators to address all MS Exchange Server issues, which is known by the name of Stellar Exchange Toolkit.
Exchange organizations may use the Journaling Agent of the Transport Service to archive messages going through Exchange. However, if the Transport Service is integrated with some email content management application (such as an antispam), the admini…
This video shows how to use Hyena, from SystemTools Software, to update 100 user accounts from an external text file. View in 1080p for best video quality.
Suggested Courses

705 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question