Solved

Merge two Independent AD domains/forests & Exchange

Posted on 2010-09-21
5
1,352 Views
Last Modified: 2012-05-10
I have two independent domains/forests, call them A.ORG.COM & B.ORG.COM; there is no common 'root' forest/domain.  Each forest/domain has been operating independently for years, now management wants to merge B.ORG.COM with A.ORG.COM and keep A.ORG.COM as the domain name.  
B.ORG.COM has over 25 AD servers and Exchange servers due to it being spread over a WAN with slow links.  Each site has it's own mailboxes; some sites are as small as 10 and others are around 300 users.  This was done so that the Users would see their email ‘leave’ as soon as they hit Send as well as to help with logon.  
I have searched for days for good articles concerning what I am trying to accomplish but cannot seem to find one that fits my scenario.  The articles I have read thus far are about establishing trusts to share resources or migrating both forests/domains to a new name.  I would love to just establish the two way trusts, but management is insistent that they no longer want B.ORG.COM to exist.
Thanks in advance.
0
Comment
Question by:haiven20
5 Comments
 
LVL 11

Expert Comment

by:Geminon
Comment Utility
Well if you use ADMT (active directory migration tool) you can move the users from B to A. Trusts will be needed for this. Depending on your exchange version you could do an interOrg migration to move the exchange data. Plan this carefully as it could prove to be a headache!
0
 
LVL 5

Expert Comment

by:smartsid
Comment Utility
first, you need to create a trust between forests. You should go for uni-directional trust rather than birectional as Forest B.org.com will not be required after migration.
Then you can plan for Exchange routing. Are there two exchange organizations involved ?
0
 
LVL 9

Accepted Solution

by:
Chev_PCN earned 500 total points
Comment Utility
This is going to be a long-term project that will require careful planning.
I would suggest that you think about making B a child domain of A to ease the migration.
You will need to consider how the move will affect share permissions, databases, applications, and other shared resources using B's AD credentials.

Exchange is going to be a nightmare I'm afraid. From what I remember you cannot move an exchange server from one domain to another.

http://www.experts-exchange.com/OS/Microsoft_Operating_Systems/Server/2003_Server/Q_22610895.html
http://www.petri.co.il/forums/showthread.php?t=25747
http://support.microsoft.com/kb/812453

You're also going to want to keep the @B email addresses for some time in parallel with the new A addresses to ensure smooth transition with no loss of comms from external contacts, which means changing your public DNS / MX records

You will also need to consider the infrastructure such as DNS servers, policies, DHCP, WINS, replication between sites
0
 

Author Comment

by:haiven20
Comment Utility
Thanks to all three of you thus far, keep it coming.  I am hoping that they will let me either put a bidirectional trust in and be done with it, or maybe a root domain (ORG.COM) and have both A & B become a child of it.  But, also, if they stay this course I want to be able to give them all the information so that if things turn ugly....
0
 
LVL 9

Expert Comment

by:Chev_PCN
Comment Utility
Putting in a root domain has both benefits and pitfalls.
One benefit is gaining extremely tight control of your top-level accounts like Enterprise admins.
You would also gain your 2-way transitive trust and be able to start your migration.
One consideration is that you can never get rid of the root domain. Once it's in, it's in for ever.

Some resources:
http://technet.microsoft.com/en-us/library/mergers_acquisitions_active_directory_prune_and_graft_restructuring_support_limitations%28WS.10%29.aspx
http://technet.microsoft.com/en-us/library/cc974332%28WS.10%29.aspx
http://technet.microsoft.com/en-us/library/aa996077%28EXCHG.65%29.aspx
0

Featured Post

PRTG Network Monitor: Intuitive Network Monitoring

Network Monitoring is essential to ensure that computer systems and network devices are running. Use PRTG to monitor LANs, servers, websites, applications and devices, bandwidth, virtual environments, remote systems, IoT, and many more. PRTG is easy to set up & use.

Join & Write a Comment

Utilizing an array to gracefully append to a list of EmailAddresses
Follow this checklist to learn more about the 15 things you should never include in an email signature from personal quotes, animated gifs and out-of-date marketing content.
The video tutorial explains the basics of the Exchange server Database Availability groups. The components of this video include: 1. Automatic Failover 2. Failover Clustering 3. Active Manager
To add imagery to an HTML email signature, you have two options available to you. You can either add a logo/image by embedding it directly into the signature or hosting it externally and linking to it. The vast majority of email clients display l…

771 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

10 Experts available now in Live!

Get 1:1 Help Now