Active Directory Domain Migration Checklist
Active Directory Domain Migration Checklist
Active Directory Domain Migration Checklist
Throughout this document, the terms source domain and target domain mean the domain from
which the objects are being migrated from and the destination domain being where the objects
are being migrated to.
Establish a two way trust relationship between the source domain and target domain
Verify the trust relationship – To verify, check that you are able to list accounts from
each domain in each domain
Add the source domain’s Domain Admins group to the target domain’s Administrators
group
Add the target domain’s Domain Admins group to the source domain’s Administrators
group
In the target domain check and verify that the domain Password Policy is equal to or less
restrictive then the source domain’s password policy.
In both the source domain and target domain, enable Account Management Audit for
success and failure at both the domain level and the domain controller level. You must
reboot the PDC emulator for the policy to take effect.
Verify that Account Auditing is working in each domain. Create a test user and delete
the users. Check that each event has been recorded in the security logs.
In the source domain create a domain local group with the NetBIOS name of the domain
followed by three dollar signs with no members. Example DOMANNAME$$$
In the target domain create a domain local group with the NetBIOS name of the domain
followed by three dollar signs with no members. Example DOMANNAME$$$
In the source domain and the target domain verify or add the Everyone group as a
member of the Pre-Windows 2000 Compatible Access group.
NetBIOS Naming Resolution Requirements
Install a WINS server on the target domain PDC Emulator (still required for Windows
2008 domains)
In the TCP/IP Advanced Network Card Properties of the source and target domain
controllers, add the IP Address of the target domain controller under the WINS server
tab.
Enable NetBIOS over IP for both the source and target domain‘s PDC Emulator
Verify that all domain controllers both source and target have Enable lmhost Lookup
enabled
In the TC/IP DNS advanced settings of both the source and target domain controllers,
verify that the DNS server of both domains are entered with the first entry as the
domain name that the domain controller belongs to.
Append the domain suffix list to include the DNS name of both domains with the first
entry as the domain name that the domain controller belongs to.
Enter the domain name for the DNS suffix for this connection
Check Register this connection’s addresses in DNS
Create a Domain Group Policy to disable Windows Firewall in both the source and target
domain. (See appendix 1)
Verify IP Filtering is disabled for both the source and target domain controllers in the
Advanced TCP\IP Options Setting to Permit All
For Windows 2008 domain controllers, disable User Account Control (UAC)
Logon to the migration computer in the target domain as a member of the target domain’s
Domain Admins group and install WADMigrator.
Once WADMigrator is installed, updated to the latest build and the domain migration options
have been set, verify that all the pre-migration internal checks have a green check mark beside
each prerequisite.
Create a new Group Policy object, and give the object a descriptive name (for example, ITS-
Turn off Windows Firewall).
WinzeroTech: http://www.winzero.ca
Support Blog: http://winzerofaqs.blogspot.com
Migration blog: http://domainreconfigure.blogspot.com
Twitter Updates: http://twitter.com/winzerotech/
Akos Sandor
Winzero Technologies
Domain Migration Checklist, Domain Migration, Active Directory Migration, WADMigrator
Active Directory Domain Migration Checklist
Windows 2000-2003-2008 Pre-Domain Migration Checklist
8/18/2009