Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations bkrike on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Is it possible to move security groups from one domain to another?

Status
Not open for further replies.

waros

IS-IT--Management
Apr 6, 2005
3
SE
Got a tricky problem.

I've got a large filestructure on one server in a NT domain.

What I'm investigating is if it's possible to copy the entire structure to another server in another nt-domain and at the same time move all groups & accounts to the new domain.

The users will now logon to the new domain and get access to the same files & folders before the move.

The first domain must not be destroyed as it is still wanted for other things.

Sounds impossible to me but is it?

// Ralph

 
You could create a trust relationship between the domains and then have people logging onto one domain but accessing the resources on the other.

This would probably be the easiest way of doing what you want, or do you want to stop people from accessing the other domain completely?

If you need more info, please ask.
 
Yes I'm sorry I was a bit unclear... after the move is completed these domains will not be physically connected. But while moving groups they will be (if it's even possible that is).
 
quest/aelita might have the tool you need... but why on earth spend the thousands of dollars to move the deck chairs when what you need is a new ride... NT4 is going down... you really ought to migrate to W2K-SP4 or preferably 2K3-SP1...

Setnaffa is an MCSE-2k3 (working on Messaging now) with a few other certs, too...
 
We've recently done exactly what you're trying to do. We were integrating our local domain from NT into A global AD domain. We used a product called Security Explorer from Small Wonders software. It's very easy to use. You create the users in your new domain then tie those new user accounts to your old ones. It then goes and sets the permissions on the basis of - if the old account has access, give the new one the same access. It does it on both user and group level.
 
Ahh thank you for that answer, I'll try that some day. We finally decided to solve it by simply installing a new bdc promote it to pdc and then pull the plug, move it and change the name of the domain and then promote another bdc to pdc in the original domain.

Of course migrating to 2k/2k3 is an option for some, but at the moment it's not going to happen in my company.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top