how to transfer users from Domain A to Domain B without trust

Hello Domain A has 100 users. I want to transfer them to Domain B. The two domain controllers cannot communicate with each other as they have 10.x.y.z ip address. Thus i cannot create the trust.
Is there any other way to do this ?
c_hocklandAsked:
Who is Participating?
 
Krzysztof PytkoSenior Active Directory EngineerCommented:
OK, let's start :) try this

1) Log on into a Domain Controller in a domain where those groups are created
2) In command-line type this syntax to export their names to a text file

ldifde -f c:\groups.txt -d "ou=oldGroupslocation,dc=domain,dc=local" -r "(objectClass=Group)" -l "cn,groupType,objectClass" -j c:
ldifde -f c:\users.txt -d "ou=oldUserslocation,dc=domain,dc=local" -r "(objectClass=User)" -l "cn,givenName,sn,displayName,description,userAccountControl,employeeID,userPrincipalName,mail,objectClass,memberOf" -j c:

3) Copy groups.txt and users.txt  files to a Domain Controller in another domain, where you want to create groups (i.e. to C-Drive)
4) Log on into a DC for that domain where you copied text file
5) Edit a text file in a notepad. Fix dn line pointing to current OU structure in new domain. Press Ctrl+H and in Find what place ou=oldGrousplocation,dc=domain,dc=local and ou=oldUserslocation,dc=domain,dc=local and replace with new value ou=newlocation,dc=domain2,dc=local". Save changes.
6) Open command-line an use this syntax

ldifde -i -f c:\groups.txt
ldifde -i -f c:\users.txt

7) On a C-Drive you will have ldifde log, review it, if everything was created properly.
8) Run Active Directory Users and Computers snap-in to check if they really exist :)

Krzysztof
0
 
Krzysztof PytkoSenior Active Directory EngineerCommented:
If both forests have no trust, you cannot migrate accounts, sorry. For that it's required forest trust and i.e. ADMT to do that job.
Account are objects with unique SIDs/GUIDs which cannot be recreated. During migration process, SIDs/GUIDs history is set up on an object. So, first of all, you need to have forest trust, DNS stub zone or conditional forwarders for those domains (DNS name resolution is required) and routing configured between those networks.

Regards,
Krzysztof
0
 
sudheendra2001Commented:
You have to create trust explicitily, what making you to stop to do this let us know we will give solution for that. Without trust you can't do.
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
ComputerBeastCommented:
Hi all,

Build out a new dc in your source domain and allow it to replicate properly, be sure that it is a DC/GC and DNS server.  Disconnect this DC from the current domain and expect to NEVER connect to this domain again.

Do a metadata cleanup of this dc, for cleanup refer to the article:

http://blogs.dirteam.com/blogs/paulbergson/archive/2009/06/09/active-directory-cleanup-the-most-common-question-i-see.aspx

Move this DC to the new forest and now create a trust between the two domains with this newly created DC that was just removed.  You may need to seize the FMSO roles and then establish a trust and use ADMT to migrate across the accounts, etc...

If you can go this route, remember you won't be able to migrate across any of the machines and the permissions associated with the users since you didn't have the two joined at time.

If this doesn't pass regulatory issues then you will have to look at exporting your users with LDIFDE or something similar.

http://support.microsoft.com/kb/237677

Thank you
Anil
0
 
c_hocklandAuthor Commented:
Ok , guys , many thanks for the great input.

I have the users in an excel sheet. Is there any tool that i can use to import them in to the new AD ?
0
 
Krzysztof PytkoSenior Active Directory EngineerCommented:
There are many ways for that :) depends on your excel data format. You can do that using

CSVDE
LDIFDE
PowerShell
Or VB Script :)

Can you post some example of your excel file?

Krzysztof
0
 
c_hocklandAuthor Commented:
besides the users , i need to import groups. Can i do this using the same method ?
0
 
Krzysztof PytkoSenior Active Directory EngineerCommented:
Yup, users and groups can be done this way using script. If you provide some example Excel document with fields I would prepare a syntax for you

Krzysztof
0
 
c_hocklandAuthor Commented:
here is the file with one user.  1.csv
0
 
c_hocklandAuthor Commented:
so to recap so as to make sure i havent ocnfused you more

i want to export all users under OU  first_ou

lets say i have one user Tom

Then i have 1 gorup called admins

I want to export this group and when i import it to the other domain i would like to have Tom as a member again , so i wont have to go and add Tom manually to this group.
0
 
Krzysztof PytkoSenior Active Directory EngineerCommented:
Yes, it is possible. I would suggest for that ldifde command
In domain A export users and groups using that tool and then import them in a domain B using the same tool.

Wait a second and I prepare syntax for that :)

Krzysztof
0
 
Krzysztof PytkoSenior Active Directory EngineerCommented:
Hi,

does this solution work for you? Maybe you need some other help?

Krzysztof
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.