Copying an account to child domain keeping SID history
Posted on 2012-04-11
I have a forest with a parent domain which we will call "Shared" and three child domains (Field Test, Production, and Production Test) I want to use Production Test as a debug environment for Production. One of the applications I run requires a service account in AD and it looks at the SID on the account so for it to work in Production Test I need to copy the user and the SID history. I have tried using the ADMT 3.2 Account Migration Wizard but when it runs in the same forest it moves the account not copies. I need the account to exist in each child domain and have the same SID history. Is there a way to copy the account with SID? Import/Export options? Or is there a way to copy SID history and apply it to a user in the other domain? OS on all servers is Windows Server 2008 R2.
Shared Domain manages Admin User access for users like sys admins and support servers like AV and WSUS.
Child Domains Field Test, Production, and Production Test contain end user accounts and service accounts specific to each environment.
Thanks for any help!!!