Get the App
SLTechnology News&Howtos  ›  Servers  › 

How to realize AD Migration between two Domain controllers

Shulou Source: shulou.com Published: 2022-06-01 06:24:40 09月28日 Update

This article mainly shows you "two domain controllers how to achieve AD migration", the content is easy to understand, clear, hope to help you solve your doubts, the following let the editor lead you to study and learn "two domain controllers how to achieve AD migration" this article.

The method of AD migration for two domain controllers is as follows:

AD user account and password migration steps

Preface

Using MicrosoftActiveDirectoryMigrationTool, users, groups, computers and other accounts can be migrated between two independent AD domains, and version 2.0 can be used to migrate user account passwords. This document describes the steps of how to migrate AD user accounts and passwords between two independent Win2KAD domains.

Operation steps

1. Establish a two-way trust relationship between the target domain and the source domain.

2. Join the system administrator account (Administrator) of the target domain to the local administrators group (Administrators) in the domain controller of the source domain.

3. Install the Win2K 128bit encryption package on the domain controller of the target domain and the source domain respectively. (I don't know if this part is necessary, but I installed the encryption package in practice. And according to Microsoft, 128bit encryption is already included in Win2K standard products.

4. Install ADMTVersion2.0 on the domain controller of the target domain.

5. Check the properties of the system built-in group "Pre-Windows2000CompatibleAccess" on the target domain and check whether Everyone is included in the "members". If not, you must add Everyone and restart the server. (this group already contains Everyone by default).

6. Check whether the security policy between the target domain and the source domain will affect the password migration, such as the password length limit. If so, adjustments need to be made accordingly.

7. Enter the following command at the command prompt of the domain controller of the target domain to save the password file: admtkeySourceDomainNameDriveLetter [Password].

Note:

Although this password file can be saved on any disk (including floppy disk, hard disk), it is recommended to keep it on floppy disk for security reasons.

If you use the asterisk "*" instead of the password, you will be prompted to enter the password.

L SourceDomainName must be the NetBIOS name of the source domain.

8. It is recommended to select a BDC as the password export server in the source domain.

9. Run Pwdmig.exe in the password export server in the source domain, and then select the password file generated in step 7 (such as inserting a floppy disk) in the appropriate prompt. If you entered the password in step 7, you must also enter the password.

10. On the password export server of the source domain, open and modify the registry, and under HKEY_LOCAL_MACHINE/System/CurrentControlSet/Control/Lsa, set the

The value of AllowPasswordExport:REG_DWORD is changed from 0 to 1. Then restart the computer.

11. Run ADMTVersion2.0 in the domain controller of the target domain, select migrate user account, select the migration password in the password option, and complete the migration of account and password according to the prompt.

The above is all the contents of the article "how to achieve AD migration between two domain controllers". Thank you for reading! I believe we all have a certain understanding, hope to share the content to help you, if you want to learn more knowledge, welcome to follow the industry information channel!

Tags: Password controller control target account step user between server prompt service input selection content file article floppy disk encryption security two Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno vpn macOS Shulou Technology Shulou Information Apple