User migration

    With ADManager Plus, you can migrate user accounts across domains in the trusted forest using GUI-based actions. You can perform migrations using the native Active Directory Migration Tool (ADMT) or from ADManager Plus directly. When a user account is migrated, all the corresponding attributes—along with the password and SID History attribute—are also migrated. Additionally, the domain and domain controller user rights will be updated for the migrated users.

    Note: Inter-forest migration is only supported with the Migrate using ADMT option.

    Steps to migrate users from ADManager Plus console

    1. Log in to ADManager Plus and navigate to the Management tab.
    2. In the left pane, click Migration.
    3. Under Migration, click User Migration.
    4. Under Source Settings, specify the Source Domain from the drop-down menu and select the list of users to be migrated using the respective checkboxes.
    5. Under Target Settings, specify the Target Domain from the drop-down menu, select the Target OU using the radio button, then click OK.
    6. Under OU Option, choose one of the following:
      • Migrate objects directly to the selected Target OU as a flat list: This option migrates the user as it is into the selected target OU.
      • Migrate objects along with their OU hierarchy to the selected Target OU: This option migrates the user along with the OU the user is a part of in the source to the target domain.
    7. Under Conflict Handling, select one of the following options to avoid any duplication during migration.
      • Apply this Naming Format: Select the naming format to be used while migrating the user from the drop-down. Click Advanced Settings to specify the order in which naming formats must be applied.
      • You have the option to either append or increment the suffix of the user's conflicted attribute value.
      • Note: If you choose append, click Advanced settings to specify the suffix length and the characters to fill the length deficit.

      • Do not migrate if conflict is detected: Choose this option if you prefer not to migrate the duplicate user.
    8. Domain Suffix of UPNs: Enter or select the domain suffix for the user being migrated from the dropdown. Select Same as Source to retain the suffix from the source domain controller. For example, if the user's User Principal Name (UPN) is johndoe@domain1.com, it will change to johndoe@domain2.com when domain2.com is entered as the suffix or selected from the drop-down menu.
    9. In Password Handling, select the desired password type for the user being migrated from the drop-down menu.
      • Copy Password: The same password will be copied from the source.
        • Password Export Server: In case of inter-forest migrations, enter the name of the source domain controller where the Password Export Server (PES) service is running. The service must be up and running for Copy Password to work.
        • Note: This field is unavailable for intra-forest migrations, as the Password Export Server is not required in such scenarios.

      • Random Password: A random password will be generated as per the configured password policy.
      • Note: By default, ADMT stores new complex passwords that are created in the <default drive>\Program Files\Active Directory MigrationTool\Logs\Password.txt file.

      • Type a Password: Type a desired password.
      • Same as User Logon Name: The user logon name will be set as the password.
      • Enabling Restore user password settings reapplies Password Never Expires and User Cannot Change Password if they were enabled on the source account. It also removes the User must change password at next logon setting, which may be enabled during migration by ADMT.
    10. You have two options for migration:
      • If you wish to migrate using ADManager Plus directly, uncheck the Migrate Using ADMT box. If you want the migrated users to match the users' rights from the source domain, check the Update user rights box.
      • If you wish to migrate using ADMT, click the Migrate Using ADMT checkbox. For assistance with ADMT installation, click here.
      • Note:
        • If you choose to migrate using ADMT, ADManager Plus should be configured in the domain controller's source or target domain where ADMT is also installed.
        • The Associated Accounts tab will not be displayed when using the Migrate Using ADMT option, as the ADMT tool will autonomously handle the migration of all associated accounts.
    11. Click More Options to make changes to the User Options and Account Transition Options. Under User Options:
      • Update user rights: Sets the rights from the source domain to the migrated users.
      • Translate roaming profiles: Copies the roaming profiles from the source to target domains.
      • Fix user's group memberships: Adds the migrated user accounts to target domain groups if those users are group members in the source domain.
      • Migrate associated user groups: Creates groups associated with the user being migrated accounts and maintains group membership in the target domain.
      • Update previously migrated objects: Associates group memberships even for those groups that have been migrated previously.
      • Migrate users' SIDs to target domain: Copies the users' SIDs from the source domain to the SID history in the target domain.
      • Migrate SID without using ADMT: Migrates SIDs through Windows Native API.

      Under Account Transition Options:

      • Enable Target Accounts: Migrated user accounts are enabled in the target domain once the migration is complete.
      • Disable Source Accounts: Migrated user accounts are disabled on the source domain once the migration is complete. This option can be checked in instances where the migrated user account serves no purpose in the source domain, avoiding duplicate logins.
    12. Click Preview to view and edit the list of conflicts, selected users, and associated accounts, then click Review to view the final migration list.
    13. Click Migrate Now to migrate the selected accounts.

    Don't see what you're looking for?

    •  

      Visit our community

      Post your questions in the forum.

       
    •  

      Request additional resources

      Send us your requirements.

       
    •  

      Need implementation assistance?

      Try OnboardPro