Solved

Joining / Merging 2 companies AD's

Posted on 2013-12-16
7
123 Views
Last Modified: 2014-03-27
Hey guys,

Really hoping you guys can help me out here..

Our company has just been bought out by another and I have been asked to look at and prepare a document on how to join the 2 AD domains together.

I believe that both AD forests are at 2003 level and both companies run an internal Exchange 2010 server.

I've never had to deal with something like this so I am looking forward to the challenge. From my brief readings it seems that there are a few ways to go about this and are based on what outcome you want to achieve.

If someone has had to do a similar thing, could you be so kind in giving me some info on the pro/con of the different methods and any link to materiels you used for the process

Thanks
0
Comment
Question by:QuazzieM
  • 3
  • 3
7 Comments
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39722910
Start by looking at the Microsoft ADMT guide

http://blogs.technet.com/b/askds/archive/2010/06/19/admt-3-2-released.aspx

also be aware that the new ADMT is coming out in Q1 2014, the ds team just blogged about it on Fri

http://blogs.technet.com/b/askds/archive/2013/12/13/an-update-for-admt-and-a-few-other-things-too.aspx

Having said that there are also third party migration tools like Quest that are a bit more mature.   Quest is not cheap but you should at least look at it.

Setup a lab and start testing migrations.  

Do they want you all to migrate into their infrastructure or build a new infrastructure and migrate the two into that?

Thanks

Mike
0
 

Author Comment

by:QuazzieM
ID: 39722942
That's the million dollar question ATM. I've gone back to my new CIO and requested some clarification as to what the really want to achieve from the process.

I asked if they simply want each site to be able authenticate against each other. So that users from each forest have the ability to log into either sites Terminal servers or if they want to consume our forest into there's. I cant see them wanting to create another new domain forest as they are lot bigger then us.

From what I can tell, doing a 2 way forest trust should allow for users from both sites to authenticate and access things like terminal servers and I believe this is what they'll want, as I believe we'll still operate as single entity, but they'll just need access to our systems (once I join the two Telstra MPLS networks)

My only real concern for this is the exchange side of things.
0
 
LVL 57

Expert Comment

by:Mike Kline
ID: 39722947
How big are the two companies?
0
Best Practices: Disaster Recovery Testing

Besides backup, any IT division should have a disaster recovery plan. You will find a few tips below relating to the development of such a plan and to what issues one should pay special attention in the course of backup planning.

 

Author Comment

by:QuazzieM
ID: 39722957
We have about 500 AD users and about 400 Exchange mailboxes and over 1200 PC's

Them I have nfi.. I would presume a lot more.

From what I can tell, they simply just need to be able to authenticate against our domain, so that they can log into our Terminal servers and what not from their location.

I don't think they will want to consume the company as they've bought out multiple companies and they still operate under there original names once this new conglomerate buys them out.
0
 
LVL 57

Accepted Solution

by:
Mike Kline earned 250 total points
ID: 39722967
You may also get away with just establishing a trust relationship between the two.
0
 
LVL 25

Assisted Solution

by:Mohammed Khawaja
Mohammed Khawaja earned 250 total points
ID: 39723126
My suggestion would be the following:

1.  Use ADMT tools and migrate AD objects from one domain to the other
2.  Read http://msexchangeteam.com/archive/2006/11/02/430289.aspx and http://technet.microsoft.com/en-us/library/aa997145.aspx to ensure you follow the correct migration path
0
 

Author Comment

by:QuazzieM
ID: 39723224
OK so the CIO finally got back to me.

It seems that they want a simple solution, which is the ability for AD user accounts from either domain to be able to log in and access Terminal servers and what not.
0

Featured Post

Netscaler Common Configuration How To guides

If you use NetScaler you will want to see these guides. The NetScaler How To Guides show administrators how to get NetScaler up and configured by providing instructions for common scenarios and some not so common ones.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Restoring deleted objects in Active Directory has been a standard feature in Active Directory for many years, yet some admins may not know what is available.
This article runs through the process of deploying a single EXE application selectively to a group of user.
The basic steps you have just learned will be implemented in this video. The basic steps are shown to configure an Exchange DAG in a live working Exchange Server Environment and manage the same (Exchange Server 2010 Software is used in a Windows Ser…
how to add IIS SMTP to handle application/Scanner relays into office 365.

786 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question