Windows IT Pro is the authoritative and independent resource for windows nt, windows 2000, windows 2003, windows xp. Features a collection of resources and magazines for windows IT professionals.
  
  
  Advanced Search 


June 2005

Make Your Move

Get your AD deployment off on the right foot with one of these 4 migration tools
RSS
Subscribe to Windows IT Pro | See More Active Directory (AD) Articles Here | Reprints
Or get the Monthly Online Pass—only $5.95 a month!

With the discontinuation of hotfix development and phasing out of support for Windows NT 4.0 and the release of Windows Server 2003 Service Pack 1 (SP1), now is a great time for those of you still running NT domains to consider switching to Active Directory (AD). To help you with the transition, Microsoft offers the free Active Directory Migration Tool (ADMT), which you can download from http://www.microsoft.com/downloads/details.aspx?FamilyID=788975b1-5849-4707-9817-8c9773c25c6c&DisplayLang=en. Third-party products from Quest Software, BindView, and NetIQ provide such features as project management, SID history clean-up, and more functional GUIs—all of which can make them worth the price.

Migration involves moving user and computer accounts from one or more source domains to a target domain. You might find yourself performing a migration to move away from NT or to consolidate two or more AD domains. Migrated accounts get a new SID in the target domain, so migration tools also provide a way to ensure that the new account inherits the same access to resources. All the tools I tried maintain SID history and repermission files, folders, and the registry, as well as provide common functionality to deal with other necessary migration tasks. All the reviewed products can migrate user accounts, passwords, local and global groups, computer accounts, and trusts; repermission the file system, registry, and Microsoft Exchange Server mailboxes; join workstations to a new domain; maintain SID history; and run scripted migration tasks. Table 1 sums up each product's features.

I tested each product by migrating a set of NT users and groups, a file share, and a workstation to a Windows 2003 AD domain. I evaluated each product according to its ease of use, its ability to help plan the migration (i.e., migration-project management), and whether the new accounts in the target domain could access the correct resources on both the file share and the workstation after the migration.

ADMT
ADMT supported all the basic functionality I needed to migrate users and computers between domains but provided only a minimal installation process and GUI. Most notably, the product lacks migration-project management, SID history cleanup, and robust reporting. ADMT is probably suitable for smaller migrations, but if you need to keep track of hundreds of users, the tool will require extra work—both in troubleshooting and project management.

Installing ADMT wasn't as simple as you might think. At first glance, I thought the process just involved deploying a Windows Installer package. However, a thorough read of the accompanying documentation revealed that I also needed to configure a slew of permissions and registry settings, designate and configure a Password Export Server in the source domain, and reboot a domain controller (DC) in both the source and target domains. In retrospect, the ease of configuring the other tools made ADMT's setup seem complex and error prone.

As Figure 1 shows, ADMT consists of a set of wizards that let you test or perform each migration task. However, the tool didn't provide a way to save my test settings, so I had to rerun the wizards and recreate the options I'd chosen during my tests. When I tested the process of migrating small batches of users, this lack of project management also made it difficult to plan which users I wanted to migrate in each batch.

ADMT has a minimal but useful set of reports. The Account Name Conflicts report helped me predict some of the errors I ran into and the Migrated User and Groups and Migrated Computer Accounts reports helped me figure out which users I'd already migrated. I would have liked to see reports that compared source and target domains (e.g., something that showed me which users hadn't been migrated yet).

I spent a lot of time troubleshooting ADMT. When a migration task encounters errors, ADMT provides only a text-based log file of the actions it performed. Among the errors I encountered were problems with the configuration of the Password Export Server and SID History permissions. ADMT has a Retry Task Wizard, but the Wizard didn't let me modify a failed task's settings before retrying the task. Also, the Wizard let me retry only distributed tasks, such as computer migrations; I couldn't use the Wizard to retry user migrations that had encountered errors or successful test migrations. Furthermore, ADMT supports undo only for the most recent migration task. Once I got everything working, however, ADMT successfully migrated users, without any permissions problems on the file share or local profiles.

Microsoft Active Directory Migration Tool 2.0
Contact: Microsoft
Web: http://www.microsoft.com
Price: Free
Summary
Pros: Performs most necessary migration tasks; free
Cons: Setup can be complex; doesn't offer project-management capabilities; can undo only the most recent migration task; doesn't clean up SID history
Rating: 2 out of 5
Recommendation: Suitable only for small organizations or those that have the time and talent to script larger migrations.

BindView bv-Admin for Windows Migration
bv-Admin for Windows Migration is a project-based migration tool that offers good migration planning, great translation of source-account properties, and complex mapping of migrated objects into organizational units (OUs). This product was the most flexible of those I tested, in terms of organizing accounts in the target AD structure and standardizing account names and properties, but its trial migrations didn't catch errors that occurred during the actual migration. Though troubleshooting wasn't difficult, I was disappointed that it was necessary during my actual migration rather than during the trial migration. This problem, along with its higher price, kept bv-Admin out of the top spot in this review.

The bv-Admin console consists of a set of projects that are organized according to the type of object being migrated. Each project I created represented a set of users, groups, computers, and migration settings. As Figure 2 shows, I could choose a separate destination OU in the target domain for each object to be migrated, and I could set account properties—including the common name (CN), SAM, and user principal name (UPN)—by using an expression that included source-account properties. Additionally, bv-Admin automatically set the first name and last name fields in AD by breaking NT's Full Name field at spaces. None of the other products automatically populated these fields in AD.

After I'd created a project, I could use it to perform either a trial or a real migration. Though the trial migration succeeded, my first real migration produced two errors, one involving permissions for enabling SID history and the other because of the length of the CN field. bv-Admin offered useful error messages, so I was able to resolve both problems easily, but I was frustrated that the trial worked but the actual migration failed. After the real migration succeeded, I turned my project into a template that let me use the same settings for a new project involving different user accounts.

To migrate the file share and workstation, bv-Admin automatically installed agents to apply ACLs and join the workstation to the new domain. Rebooting after the migration was optional, and I didn't encounter any errors during this process.

The product's reporting capabilities impressed me. The reporting tool is called Action Reports and includes a useful set of customizable reports for both domain and migration projects. These reports included data about non-migrated objects, SID history, successfully executed projects, and resources that were skipped during project execution. I could also customize the reports to get data from multiple domains or projects. Furthermore, the reports were actionable when appropriate. For example, right-clicking the SID History report let me launch a SID History clean-up task.

BindView bv-Admin for Windows Migration 7.2
Contact: BindView * 713-561-4000 * 800-813-5869
Web: http://www.bindview.com
Price: $9.95 per user
Summary
Pros: Offers robust account-translation options
Cons: Trial migrations don't accurately predict the success of actual migrations
Rating: 3 out of 5
Recommendation: A robust migration tool with good project-management capabilities, but migration errors and inaccurate trial-migration functionality required some troubleshooting. Consider this product if renaming accounts during migration is a priority.
   Previous  [1]  2  Next 


Reader Comments

You must log on before posting a comment.

If you don't have a username & password, please register now.




Top Viewed ArticlesView all articles
The iPhone as a Mail Device

An Exchange administrator and self-proclaimed "Windows Mobile device wrangler" gives you the scoop on how well the iPhone 3G works for enterprise email, and points out some surprising omissions in Apple's latest release. ...

WinInfo Short Takes: Week of July 21, 2008

An often irreverent look at some of the week's other news, including an iPhone 3G defeat, 180 million copies of Windows Vista in the wild, Microsoft earnings some more Yahoo silliness, Wii vs. Xbox 360, EU vs. Intel, AMD ousts its CEO, and so much more ...

Top Vista Tricks from the Vista Masters

Learn how to work around Windows Vista's User Account Control, create multiple GPOs, and use Task Manager smartly, with these 8 Vista tricks. ...


Active Directory (AD) Whitepapers An Introduction to Windows Server 2008 Server Manager

Get More from Active Directory—Easily Audit Changes, and Secure and Restore Objects

User Provisioning: Get the Most Bang for your IT Buck

Related Events Check out our list of Free Email Newsletters!

Windows OSs eBooks Understanding and Leveraging Code Signing Technologies

Keeping Your Business Safe from Attack: Monitoring and Managing Your Network Security

Windows 2003: Active Directory Administration Essentials

Related Active Directory (AD) Resources Become a VIP member of the Windows IT Pro community!
Get it all with the VIP CD and VIP access. A $500+ value for only $279!

Subscribe to Windows IT Pro!
Solve your toughest technical problems with our experts and access 10,000 + articles online. 30% off

Monthly Online Pass - Only $5.95!
Get instant access to 10,000+ articles from Windows IT Pro Magazine!

TechNet Virtual Labs
Evaluate and test Microsoft's newest products.


ADS BY GOOGLE SPONSORED LINKS FEATURED LINKS

Shortcut Guide to SQL Server Infrastructure Optimization
With right tools and techniques, you can have a top-performing SQL Server infrastructure without having to cram your data centers so that they're overflowing. Download this eBook to learn how.

WinConnections Conference Fall 2008
Don’t miss the premier event for Microsoft IT Professionals in Las Vegas, November 10-13. Register and book your room by August 25 and receive a FREE room night (based on a three night minimum stay).

Become a fan of Windows IT Pro on Facebook!
Join us on Facebook and be a fan of Windows IT Pro!

Continuous Data Protection and Recovery for Exchange
Read this white paper to learn about Continuous Data Protection (CDP), Exchange 2007's local continuous replication and cluster continuous replication features.

Rev Up Your IT Know-How with Our Recharged Magazine!
The improved Windows IT Pro provides trusted IT content with an enhanced new look and functionality! Get comprehensive coverage of industry topics, expert advice, and real-world solutions—PLUS access to over 10,000 articles online. Order today!

Tips to Managing Messaging
Discover three fundamental mail and messaging management services - security, availability and control services - and how you can implement them in a Microsoft-centric mail and messaging environment.

Get It All with Windows IT Pro VIP
Stock your IT toolbox with every solution ever printed in Windows IT Pro and SQL Server Magazine plus bonus Web-exclusive content on hot topics. Subscribe to receive the VIP CD and a subscription to your choice of Windows IT Pro or SQL Server Magazine!



Drag & Drop Data Mapping Tool
Try this award-winning data mapping, & transformation tool that supports multiple databases, flat files, Web services, EDI, Excel 2007, & more! Free trial for 30 days!

Overcome bloated Windows file systems
Crossroads FMA delivers powerful yet inexpensive data migration

Bandwidth Monitoring Tool from SolarWinds
Identify largest bandwidth users in seconds. Get the free download now.

Speed Deployment of Vista and Microsoft Office
Read this white paper to learn how you can maximize your Vista and Office investments while lowering costs and increasing efficiency.

Integrated Virtualization Done Right
Download this white paper on server virtualization to begin improving resource utilization and lowering operating costs.

Order Your Fundamentals CD Today!
Gain an introduction to Exchange, learn server security requirements, and understand how unified communications can play a role in your messaging strategies with this free Exchange CD.

KVM over IP Solutions
Learn about a KVM over IP solution that is specifically designed to meet the needs of the distributed IT environment.
Windows IT Pro Home Register FAQ for Windows WinInfo News
Europe Edition About Us Contact Us/Customer Service Media Kit Affiliates / Licensing  
SQL Server Magazine Office & SharePoint Pro Windows Dev Pro IT Job Hound
IT Library Technical Resources Directory Connected Home Windows Excavator SuperSite 
 
 Windows IT Pro is a Division of Penton Media Inc.
 Copyright © 2008 Penton Media, Inc., All rights reserved. Terms and Use | Privacy Statement | Reprints and Licensing