Solved

script export+import group and user from forest A to Forest B

Posted on 2014-04-17
5
1,730 Views
Last Modified: 2014-05-13
hello,

i need to export user and group from my Active directory production forest to my lab forest.

AD 2008 R2.

i need to export all group  and user from specific organisationnel unit.

i need to keep the member of group from forest a to forest b.

thanks
0
Comment
Question by:cawasaki
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 3
  • 2
5 Comments
 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 40006300
Hi,

Use LDIFDE to import and export directory objects to Active Directory. its very easy.

firstly export groups then users.

CSVDE -f adusers.csv

CSVDE -i -f Newport.csv


http://support.microsoft.com/kb/237677
0
 

Author Comment

by:cawasaki
ID: 40006936
hello,

ok i have success to export and inport user, but i have a problem to import group, so any one have a working script to export and import group with memeber if possible?
0
 
LVL 13

Accepted Solution

by:
Santosh Gupta earned 500 total points
ID: 40007187
ldifde -f c:\LDIFDE_export\export_Groups_WITH_Members.ldf -s <DC NAME> -d "<DOMAIN DN>" -p subtree -r "(&(ObjectCategory=group)(objectClass=group)(name=*)(member=*))" -l "member" -j c:\

http://social.technet.microsoft.com/Forums/windowsserver/en-US/1b24edf2-9af5-447c-9f15-631e88eefe8c/exporting-users-groups-and-their-members-from-a-currently-installed-and-importing-them-to-a-new
0
 

Author Comment

by:cawasaki
ID: 40008303
i have already test this and import not work:

Logging in as current user using SSPI
Importing directory from file "c:\temp\export_Groups_WITH_Membersv3.ldf"
Loading entries......................
Add error on entry starting on line 244: Unwilling To Perform
The server side error is: 0x209a Access to the attribute is not permitted becaus
e the attribute is owned by the Security Accounts Manager (SAM).
The extended server error is:
0000209A: SvcErr: DSID-031A0FBB, problem 5003 (WILL_NOT_PERFORM), data 0

0 entries modified successfully.
An error has occurred in the program
No log files were written.  In order to generate a log file, please
specify the log file path via the -j option.

Open in new window

0
 
LVL 13

Expert Comment

by:Santosh Gupta
ID: 40009146
Hi,

see the url for import error.. http://support.microsoft.com/kb/276382
0

Featured Post

How Do You Stack Up Against Your Peers?

With today’s modern enterprise so dependent on digital infrastructures, the impact of major incidents has increased dramatically. Grab the report now to gain insight into how your organization ranks against your peers and learn best-in-class strategies to resolve incidents.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Always backup Domain, SYSVOL etc.using processes according to Microsoft Best Practices. This is meant as a disaster recovery process for small environments that did not implement backup processes and did not run a secondary domain controller that ne…
Did you know that more than 4 billion data records have been recorded as lost or stolen since 2013? It was a staggering number brought to our attention during last week’s ManageEngine webinar, where attendees received a comprehensive look at the ma…
The viewer will learn how to look for a specific file type in a local or remote server directory using PHP.
This video shows how to use Hyena, from SystemTools Software, to bulk import 100 user accounts from an external text file. View in 1080p for best video quality.

751 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question