Subscribe to Windows IT Pro

 

Get Newsletters

  • Get the Latest News
  • Product Updates
  • Helpful Tricks
  • Productivity Tips

Subscribe Now!

November 20, 2000 12:00 AM

Domain Reconstruction Tools

Windows IT Pro
InstantDoc ID #16148
Rating: (0)

As I've discussed in previous columns, when performing a Windows 2000 migration, domain reconstruction often makes sense because many Win2K features eliminate the reasons that led you to create multiple domains under Windows NT 4.0. Usually, a restructuring project lets you perform domain consolidation (i.e., reduce the total number of domains in your environment). As one reader put it, domain consolidation has some definite advantages, but it can seem overwhelming when you consider what's involved.

Active Directory Migration Tool
To help make domain consolidation more manageable, Microsoft has provided some useful tools on the Win2K Server installation CD-ROM and at the Microsoft Web site. One tool, the Active Directory Migration Tool (ADMT), is a GUI- driven utility that lets you migrate users, groups, and computers from an NT 4.0 domain to a Win2K native mode target domain, to another Win2K forest, or to another Win2K domain in the same forest. It's useful for performing inter-forest and intra-forest migrations. ADMT's interface is straightforward, and its Help file is very comprehensive. Overall, ADMT is a great migration tool, especially considering that it’s free.

Let’s assume that you want to use ADMT to migrate user accounts from an NT 4.0 account domain to a Win2K forest. After selecting the accounts you want to migrate, you can run a test migration to identify any errors that might occur during an actual migration. This test run lets you address potential problems before they occur.

ADMT provides several options for controlling how you create users in Active Directory (AD): You can specify a target organizational unit (OU), determine how the system assigns passwords to new accounts, control how the system handles duplicate names, copy roaming profiles, and assign to user accounts the same rights they had under NT 4.0. To allow resource access, you can migrate the users’ existing SIDs to populate the SIDHistory attribute, which I discussed last week. In this scenario, you're not actually affecting the accounts in the source NT 4.0 domain; instead you're creating replicas of the accounts in the AD, which gives you ample time to perform testing and gives you something to revert to if you run into trouble.

Before you perform any restructuring, you must address certain requirements for the source and target domains. First, you have to establish an explicit trust between the two domains, and you must have administrative privileges on each. Also, the target domain must be in native mode, you must enable auditing in both source and target domains, and you must create a local group called domainname$$$ (where domainname is the name of the source domain) in the source domain. Finally, you must create the registry entry HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\LsaTcpipClientSupport:REG_DWORD:0X1 on the source domain PDC. If you're using ADMT, it creates the local group, enables auditing, and makes the registry change for you.

Additional Tools
In addition to ADMT, Microsoft provides some command-line tools that aren’t as easy to use but are useful in certain situations, especially if you need to script your migration. Clone Principals is a tool that lets you copy users from an NT 4.0 domain to a Win2K domain; Netdom is a tool that lets you manage trust relationships from a command prompt; and MoveTree is a command-line utility that lets you move AD objects between domains in the same forest.

If these tools don’t provide the functionality you need, you can turn to several third-party tools from companies such as NetIQ and FastLane (Mission Critical, which merged with NetIQ, licensed ADMT to Microsoft). If you have experience with any third-party migration tools, post your reactions, both good and bad, in response to this article.

Related Content:

ARTICLE TOOLS

Comments
  • Jan Isherwood
    9 years ago
    Nov 18, 2003

    All of these articles stop short of a key bit of information that is needed for Forest to forest migration which is how and when to migrate exchange. We are going from a 2000AD to 2003 by building a separate forest and all documents tell you how to migrate the AD across a forest but little info about Exchange. You can find info about migrating from Exchange 5.5. I know that there are two tools the Exchange Migration Wizard and the Exmerge tool. I can find the pros and cons on both but no complete migration including Exchange.

  • Giulio Ale
    11 years ago
    Oct 16, 2001

    Got the same problem as Stephen taylor, is there anyway to make a root domain child of another domain ? My company is merging and it would be very useful, is it true it will be possible with next release od windows 2000 server (XP or whatever it will be ?)

    Thx

  • Stephen Taylor
    11 years ago
    Aug 03, 2001

    Your article talks about reconstructing NT 4 domains. Are there any tools or procedures to merge Active directory domins, where one root becomes a child of another?

  • afzal lokhandwala
    11 years ago
    Feb 12, 2001

    Your article talks about using win2k, and the reconstruction tools for that. However could you maybe help me get some information on reconstructing an NT4.0 domain? Currently we have several branch domains, and we need to set up a National domain NT4.0, and migrate the existing domains into it, as a Single Master domain model. Any and all information would be welcome.

You must log on before posting a comment.

Are you a new visitor? Register Here

advertisement

advertisement

White Papers

Get your Windows 7 deployment off to the right start by implementing PC lockdown. A locked-down environment is easier and cheaper to support since users are less likely to make unnecessary changes to the core system configuration - read more here!

Essential Guides

Is your iSCSI "lossy"? The reality is that most off-the-shelf Ethernet hardware deployed for iSCSI can lose packets, resulting in slow performance or application downtime. Learn how to assess your current iSCSI infrastructure and engineer an advanced iSCSI SAN infrastructure.

Web Seminars

What's the best way to keep your network safe from malware? In this web seminar, security expert Greg Shields suggests an alternative method to the traditional blacklisting approach that is common with anti-virus and anti-malware solutions.

eLearning Series

We bring the experts direct to you to share their real-world perspective and expertise. During each event, three sessions stream in real time, so you can learn, ask questions, and get solutions.
Upcoming event: Getting the Most with Exchange 2010 with Paul Robichaux

Subscribe to Windows IT Pro!

Windows is a trademark of the Microsoft group of companies. Windows IT Pro is used by Penton Media Inc. under license from owner.