Solved

Copying an account to child domain keeping SID history

Posted on 2012-04-11
4
699 Views
Last Modified: 2013-12-17
I have a forest with a parent domain which we will call "Shared" and three child domains (Field Test, Production, and Production Test) I want to use Production Test as a debug environment for Production. One of the applications I run requires a service account in AD and it looks at the SID on the account so for it to work in Production Test I need to copy the user and the SID history. I have tried using the ADMT 3.2 Account Migration Wizard but when it runs in the same forest it moves the account not copies. I need the account to exist in each child domain and have the same SID history. Is there a way to copy the account with SID? Import/Export options? Or is there a way to copy SID history and apply it to a user in the other domain? OS on all servers is Windows Server 2008 R2.

Shared Domain manages Admin User access for users like sys admins and support servers like AV and WSUS.

Child Domains Field Test, Production, and Production Test contain end user accounts and service accounts specific to each environment.

Thanks for any help!!!
0
Comment
Question by:Sparcedge
  • 2
4 Comments
 
LVL 17

Expert Comment

by:Anuroopsundd
ID: 37834057
Clone principal can help in copying the account information..

Note:--- it duplicates the object from source domain to target domain... does not delete..

you can  find more details in below link if it fullfills your requirement..

http://technet.microsoft.com/en-us/library/cc773393(v=ws.10).aspx
0
 

Author Comment

by:Sparcedge
ID: 37834072
Clone Principal is from Server 2000 and 2003, do they still make it or include it in support tools for 2008 R2? Or would the 2003 version work on a 2008 R2 domain?
0
 
LVL 17

Accepted Solution

by:
Anuroopsundd earned 500 total points
ID: 37834191
it may require some testing. in below link they are providing how to run on windows 2008 machine..but again test in lab first..

http://daddyr.blogspot.com/2011/09/migrate-sidhistory-for-domain-admins.html

http://www.rutter-net.com/news/tips-tricks/migrate-sidhistory-for-domain-admins-and-domain-users-cross-forest/
0
 
LVL 17

Expert Comment

by:Tony Massa
ID: 37834346
First link is correct, but you need to use the sidHistory script (from clone principal tool) to copy it.
Sidhist.vbs. Sample script that adds the SID of a source account to the SIDHistory of a destination account.
See Also: http://msdn.microsoft.com/en-us/library/ms677982%28v=vs.85%29.aspx

Apparently, you can use ADMT to do this though:
http://social.technet.microsoft.com/Forums/en/winserverDS/thread/c0bf3fa8-e379-4241-bf82-7dae2ea2a8fc
0

Featured Post

Are your AD admin tools letting you down?

Managing Active Directory can get complicated.  Often, the native tools for managing AD are just not up to the task.  The largest Active Directory installations in the world have relied on one tool to manage their day-to-day administration tasks: Hyena. Start your trial today.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
NTFS Permissions 6 48
exchange, active directory 4 25
Whitelisting applications 2 23
need assistance with this powershell script 4 43
While rebooting windows server 2003 server , it's showing "active directory rebuilding indices please wait" at startup. It took a little while for this process to complete and once we logged on not all the services were started so another reboot is …
This article runs through the process of deploying a single EXE application selectively to a group of user.
This tutorial will show how to configure a single USB drive with a separate folder for each day of the week. This will allow each of the backups to be kept separate preventing the previous day’s backup from being overwritten. The USB drive must be s…
This tutorial will walk an individual through setting the global and backup job media overwrite and protection periods in Backup Exec 2012. Log onto the Backup Exec Central Administration Server. Examine the services. If all or most of them are stop…

803 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question