Dear Customer,
Thank you for posting in newsgroup. And thanks to the community members for
the contribution.
According to the description, my understanding is that:
you want to clone the Active Directory entity to another domain controller
and want to know the drawbacks or any potential issues that may arise. If I
have any misunderstanding, please feel free to let me know.
Based on the experience, here is some information which may be helpful for
you.
Analysis and Suggestion:
=====================
I agree with Jorge. Since it will cause double SID issue and double GUID
issue, cloning a Active Directory entity is not recommended. Also, seizing
the Forest and Domain FSMO roles is not recommended. We suggest that you
may perform a domain migration with ADMT utility. With ADMT, you can
perform the security translation and this won't cause duplicated SID issue.
And you can also migrate the user profiles to the new domain, there is no
need to seize FSMO after we perform the domain migration with ADMT.
For your convenience, I have list the general steps to perform ADMT
migration as followed.
General Steps:
==================
1. As always, domain migrations are complicated tasks. Please perform
complete backup first for recovery purposes.
2. We are able to establish a trust relationship between the two root
domains in different forests, and then use ADMT with the following three
wizards to migrate the group accounts, user accounts, client computers and
file permissions:
Group Account Migration Wizard
User Account Migration Wizard
Computer Migration Wizard
Security Translation Wizard
3. It is recommended that we install ADMT on target domain's PDC Emulator.
And it is recommended that we use administrator credential of source domain
to logon the target domain from source domain controller.
4. ADMT checks its database file for information regarding the previously
migrated user objects and then determines how to migrate user profiles and
NTFS folders permissions when migrating computers. Therefore, it is better
to only install one ADMT host machine.
5. The account that runs ADMT must have administrator privileges on both
domains, and also need to be a member of the local administrators group
when migrating computer objects.
6. It is recommended to perform the migration in the following order:
Domain Global Group
Domain Local Group
User Account
Computer Account
7. Please migrate the groups and users separately (do not migrate the
associated group members when migrating the groups).
During the group migration, please use the following configurations
[Group Options]
Copy group members Not Checked
Fix membership of group Checked
During the user migration, please use the following configurations:
[User Options]
Migrate associated user groups Not Checked
Fix users'' group memberships Checked
Reference:
============
ADMT v3 Migration Guide
http://www.microsoft.com/downloads/d...770-3BBB-4B9E-
A8BC-01E9F7EF7342&displaylang=en
How to use Active Directory Migration Tool version 2 to migrate from
Windows 2000 to Windows Server 2003
http://support.microsoft.com/kb/326480/en-us
If this problem is urgent and important, I would like to suggest that you
contact Microsoft Product Support Services via telephone so that a
dedicated efficient Support Professional can assist with this request. You
may obtain the phone numbers for specific technology request please take a
look at the web site listed below.
http://support.microsoft.com/default...S;PHONENUMBERS
If you are outside the US please see
http://support.microsoft.com for
regional support phone numbers.
Hope the issue will be resolve soon.
David Shen
Microsoft Online Partner Support