AD migration

Need to migrate AD with multiple domains.IS there any way by which we can migrate without admin access. One way is to build a new DC and create(migrate all resources belongs to AD) but not sure how we can comletely achieve this.
sivark14Asked:
Who is Participating?
 
Will SzymkowskiConnect With a Mentor Senior Solution ArchitectCommented:
This is not achievable, and or not supported. The system state holds Active Directory info from the original domain, I don't know how you would go about using that and restore it into the new domain.

As stated there are a few things you can do that are supported and will work. If this is a production environment I would highly recommend that you proceed with either method. Trying to hack or work-a-round could just create more trouble than you are looking for, and may not even get your end results.

Will.
0
 
Will SzymkowskiSenior Solution ArchitectCommented:
You absolutely need Admin accesses to do this. Think about it if you didn't then any user in your domain could perform tasks such as this. You need domain admin rights to perform and domain level tasks Enterprise to perform high level tasks at the forest level and if you are doing schema changes then you will require schema admin rights.

If you created a new forest with a new domain you still have to have domain/enterprise admin permissions as you will need to create a forest trust with the new domain and that privilege is required to have domain/enterprise admin rights.

Permissions required for specific tasks for migration. http://technet.microsoft.com/en-us/library/cc974398(v=ws.10).aspx

Will
0
 
MaheshArchitectCommented:
You can use Microsoft ADMT tool for cross domain resource migration

You must require appropriate admins access in resource domain for that

You can use delegated access for resource migration (i.e. you can avoid domain admins and high previlage groups)

Please check ADMT guide

http://technet.microsoft.com/en-us/library/cc974332(v=ws.10).aspx

Mahesh
0
Problems using Powershell and Active Directory?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 
sivark14Author Commented:
Yes ofcourse we need admin access but I am finding a way to migrate without any kind of admin access. For example export all object details in domain and import manually or use any script. Thinking restoring system state to restore AD objects in the new forest domain and not do any trust relationship
0
 
MaheshArchitectCommented:
You cannot restore AD system state of one domain to another domain

You can export all object details and import it in new domain with csvde, Ds command tools etc

Then this is not a migration
If you want to do real migration, then ADMT is the only way

Check below links
http://www.petenetlive.com/KB/Article/0000794.htm

Mahesh
0
 
Will SzymkowskiSenior Solution ArchitectCommented:
A migration is much different than simply using powershell to export users/groups and import them into the other domain. You are basically just creating the object but none of the security principals will be tied to the users account once you have created them in the new domain.

Migration would be the best approach if you have proper credentials. If you do not then scripting with powershell doing an export of all users/groups etc and then import them in to the new domain. You will then have to manually setup all of the ACL's for the new domain moving the users back in the corresponding groups.

As for the trust after this is completed you will still need domain admin privileges in the forest root domain or enterprise admin rights to achieve this.

Will
0
 
sivark14Author Commented:
Is there any way to restore system state on new domain by having same domain name , SID value of the source domain so it will have the same configuration detail and restoration will work?

Thanks
0
 
Detlef001Commented:
Hello,
Using ADMT we can migrate. By the way, what version of AD are you try to migrate and to which version?
If you really want to know more about AD migration, I suggest you refer one of our MVP's site:http://www.sivarajan.com/admt.html
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.