Solved

Export Groups from old AD (windows 2000) and import into Windows 2012 AD

Posted on 2015-01-23
3
311 Views
Last Modified: 2015-01-23
hi guys

I'm transferring people from an old system on to a new one.

The old domain is on Windows 2000 and I wanted to know how I could export all of the distribution groups and security that exist there and then have them re-imported into the new AD environment on 2012?

Otherwise it would mean having to go in and create things manually!

Thanks for your help
Yashy
0
Comment
Question by:Yashy
3 Comments
 
LVL 24

Accepted Solution

by:
Mohammed Khawaja earned 250 total points
ID: 40566081
If you wish to migrate users, groups and potentially passwords then use ADMT (AD Migration Tools) and move objects across domains.

If that is not what you wish to do then you could use LDIFDE or CSVDE utilities to export the required objects.  Refer to following links for more info:

https://technet.microsoft.com/en-ca/library/cc731033.aspx
https://technet.microsoft.com/en-us/library/cc732101.aspx
0
 
LVL 3

Assisted Solution

by:Waddah Dahah
Waddah Dahah earned 250 total points
ID: 40566085
Hello Yashy,

well you can use the free built-in tool LDIFDE or create a VBScript or a third party tool,

if you want to use LDIFDE tool try the following;

 Export Groups (only groups with members) from Source Domain
a.    Syntax:

ldifde -f c:\LDIFDE_export\export_Groups_WITH_Members.ldf -s <DC NAME> -d "<DOMAIN DN>" -p subtree -r "(&(ObjectCategory=group)(objectClass=group)(name=*)(member=*))" -l "member" -j c:\

Modify Process:
Search / Replace all exported data sets.  Search for old domain name DN and replace with new domain DN.  You will have to "massage" the exported data sets to properly format them so they can be used as the import source data sets.  The LDIFDE export process adds extraneous carriage return line feeds (0d0a) to the data sets.  You will have to remove those with your favorite hex editor.

Import process:

Import Groups members to destination domain
a.      Syntax:

ldifde -i -k -f c:\import\export_Groups_WITH_Members.ldf -s <domaincontroller> -v –j c:\<destinationdir>

Note: All imported users will be disabled.  This process does not import user passwords.  You will want to run a script that will set the flag to force all users to change their passwords upon initial authentication.

Third party tool;

this tool will help you to export the data from AD only.

http://www.dovestones.com/active-directory-export/

I hope this will help.
Waddah.
0
 
LVL 1

Author Closing Comment

by:Yashy
ID: 40566098
Much thanks guys.

I'll go ahead and configure the ADMT server right now!:) Good to know the LDIFDE command too. Cheers
0

Join & Write a Comment

What to do when Windows Update is not working correctly? What tools can I use to detect the cause of the malfunction problem? What does this numeric error code mean? These and other questions that you have been asking in the past are answered here (…
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of installing of Data Protection Manager on a server running Windows Server 2012 R2, including the prerequisites. Microsoft .Net 3.5 is required. To install this feature, go to Server Manager…

760 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now