Copy SID of User from One domain to another

Archived from groups: microsoft.public.win2000.active_directory,microsoft.public.windows.server.active_directory (More info?)

I have Users A in domain A and User B in domain B (in separate forest) -
same user just different accounts in different forest/domain.

I will be collapsing / geting rid of Domain A - how can I merge the SID of
User A into his User B account?

thanks.
1 answer Last reply
More about copy user domain another
  1. Archived from groups: microsoft.public.win2000.active_directory,microsoft.public.windows.server.active_directory (More info?)

    you'll need to leverage SIDhistory in Domain B - i.e. you're Domain B users
    will have an additional SID of the Domain A users, after you've added Domain
    A user's SID to the SIDhistory attribute of the respective Domain B user.
    But don't forget, that the User's SID is often the least of your worries =>
    it's the groups that typically grant most access for users so you'll want to
    merge their SID to appropriate groups in the other forest as well and (just
    as important) add the Domain B users to the appropriate groups that the
    Domain A users belonged to.

    This can be done via script (leveraging the ClonePrincipal API -
    http://www.microsoft.com/resources/documentation/Windows/2000/server/reskit/en-us/Default.asp?url=/resources/documentation/Windows/2000/server/reskit/en-us/deploy/dgbf_upg_ojiy.asp)
    or by using more powerful tools which do it UI based and much more
    automated.

    Microsoft's ADMTv3 (still beta) is quite powerful and it's worth to use the
    beta instead of ADMTv2. Also have a look at third party tools such as Quest
    Migration Manager.

    /Guido

    "Randy R." <rcrose@varco.com> wrote in message
    news:%23Y4FkDM5EHA.2568@TK2MSFTNGP11.phx.gbl...
    > I have Users A in domain A and User B in domain B (in separate forest) -
    > same user just different accounts in different forest/domain.
    >
    > I will be collapsing / geting rid of Domain A - how can I merge the SID of
    > User A into his User B account?
    >
    > thanks.
    >
    >
Ask a new question

Read More

Domain Microsoft Active Directory Windows