Link to home
Start Free TrialLog in
Avatar of Bill H
Bill H

asked on

AD Corrupt - new domain needed

Hi, we inherited a network, and tried to migrate away from SBS 2011 and add a new DC, but Microsoft said AD was corrupted as the process would never complete. Now, i need to build a new domain - DC + File server - essentially "migrate" what we have now - by re-creating user accounts and shares. What's the best way to approach this? Thanks. 
Avatar of Philip Elder
Philip Elder
Flag of Canada image

I am highly suspicious of such a claim (former SBS MVP here).

Make sure SBS is not in Journal Wrap.

Make sure there's no issues with SBS and the FSMO Roles.

Run the SBS Best Practices Analyzer to make sure that SBS is as it should be.
...but Microsoft said AD was corrupted as the process would never complete.
based on what?
if there were serious login issues, domain access problems across the board, i would say something is seriously wrong
but if users were functioning ok on SBS, i would start by looking at event logs to see where problems exist

what new dc were you trying to install?  2016? 2019?
how far did you get in the process before microsoft declared it 'corrupt'?
Avatar of Bill H
Bill H

ASKER

Seth - i had senior engineers involved, it's corrupt. 2016 for OS. 
did you try dcdiag and sfc?
Avatar of Bill H

ASKER

yes, this thread is not about fixing AD. Can someone answer to my original question please? Thanks
We've worked with "senior engineers" before especially with SBS. ;0)

Okay, side-by-side.

Use ForensiT's Profile Migration Wizard to automagically set up the user's existing local profiles when the time comes.

Set up a new AD that is _not_ named the same as the SBS domain to avoid Group Policy Tattoos.

Get everything set up so that when the users log on to the old domain everything is ready for them when they flip.
 * OU structure
 * Group Policy settings
 * Mapped drive(s) and printer(s)
 * Apps & databases
I would just create the domain, make the users, robocopy the data over, unless it's sql, or maybe remove the old drive and plug it into the new setup, unless your raid.
@Cobra25,

I have never met a domain controller that can not be fixed, and I have been in the industry 20+ years.. Now that being said, I believe that it is probably something relatively simple that would take a lot less time to fix than rebuilding a new domain.. But as you are not interested in this, we can proceed to the answer to your question.. But as other Experts have stated, Senior Engineer's at Microsoft are usually from another country (India) and their skill levels GREATLY differ.

"IF" your domain is functional : https://gallery.technet.microsoft.com/migrate-ad-users-to-new-2e480804 

Migrate Active Directory Users to New Forest via Two Eminent Techniques

Organizations are often sold or integrated, sometimes the employees are transferred inside two companies. As an output, employees have reassigned the locations that are part of various domains. Thus, when this happens, users may also require to move AD users to new domain on daily basis.
This editorial discusses two different techniques of how to move Active Directory users to new domain.
To migrate AD users to new domain, first users have to allocate the Conditional Forwarders for both domains. It is assumed that the name of the old domain is domain.old and the name of the new domain is domain.new. Now, in the domain.old user has to assign Conditional Forwarder to domain.new and vice versa. Once the conditional forwards are assigned then, setup Two-way Active Directory Trust for performing authentication between both domains. Doing this will allow domains to communicate and establish the migration procedure.

Manual Technique to Transfer Active Directory Users to Another Domain

In this section, we will introduce users to the manual way to move AD users to another forest. To begin the process first, users have to download the Active Directory Migration Tool (ADMT). After that, follow the down-mentioned guidelines:
Installing ADMT software
  1. Run Active Directory Migration Tool installation window.
  2. Now, a new SQL database will be generated and it is necessary to execute the process.
  3. Hit a click on Next It will take you to License Agreement page.
  4. Here, select I Agree and click on Next button.
  5. The Customer Experience Improvement Program wizard will be displayed, again click on Next.
  6. A new Database Selection page will prompt now.
  7. In this, type the name of your SQL instance then, click on Next.
  8. This will generate the SQL database and click on Finish button.

Migrate AD Users to New Domain

  1. First, launch the ADMT tool.
  2. Go to the left pane of the primary window and hit a right-click on Active Directory Migration Tool and select User Account Migration Wizard.
  3. In migration wizard, click on Next for further process to transfer domain users to another domain.
  4. From the Domain Selection display, enter Source Domain and choose the Domain Controller for this.
  5. After this, enter the target Domain plus choose the Domain Controller for the destination domain and click Next.
  6. Select the users from Source Domain and hit Next button.
  7. Click on Add icon and choose the user accounts you are required to migrate.
  8. Once all the users are added, click on Next.
  9. Enter the full qualified name of targeted OU in the Organization Unit Selection window and click Next.
  10. From the Password Option wizard, you can choose an option that is suitable for your requirements.
  11. Also, verify that you have entered the accurate Source DC and click Next.
  12. Now, from the Account Transaction Option window, select all the required alternatives and hit Next button.
  13. Doing this will migrate active directory users to new forest.
  14. User Options wizard will open now, here select an option according to requirements and click Next.
  15. Now, you are in the Object Property option.
  16. Here you are allowed to exclude the properties that you need to eliminate and click Next.
  17. From Conflict Management wizard, choose required options from “Migrate and merge conflicting objects” or “Do no migrate source object if a conflict is detected in the target domain”.
  18. Once the steps are completed, click on Finish button to move AD users from one domain to another domain in a different forest.
  19. The procedure of migrating Active Directory users to another domain will begin now.
The migration procedure wizard will display the number of users who are successfully transferred and the total number of failures. After executing the process, the logs will display the failed account migration and causes of failure.

Automatic Technique to Migrate AD Users to New Domain

Exporting AD users via manual method will consume a lot of time to execute the procedure successfully. Also, the users are required to have some technical knowledge to follow this technique. Hence, we have come up with an easy and automatic solution to transfer Active Directory users from one domain to another domain in bulk. SysTools Active Directory Management Tool permits users to search, remove, change, rename, and generate organizational unit in the AD. The software executes the whole task very smoothly and even non-technical users also can do migration via this application.

Final Words

This write up consist one manual and one automatic way to migrate AD Users to new Domain. As the manual method is lengthy and time-taking. Thus, we recommend users to go for the mentioned third-party tool for successful and easy migration.

You basically wrote what you need to do. First, set up a new DC with a new domain name (is that right?) and install all roles you need. Then use a migration tool to migrate users (https://www.microsoft.com/en-us/download/details.aspx?id=56570). Then simply copy data and share them.

Keep in mind that you will have to add all computers and servers to a new domain.
This question needs an answer!
Become an EE member today
7 DAY FREE TRIAL
Members can start a 7-Day Free trial then enjoy unlimited access to the platform.
View membership options
or
Learn why we charge membership fees
We get it - no one likes a content blocker. Take one extra minute and find out why we block content.