Intraforest user account merge with Active Directory

Posted by Neobyte on Server Fault See other posts from Server Fault or by Neobyte
Published on 2009-09-30T04:16:42Z Indexed on 2010/04/30 13:08 UTC
Read the original article Hit count: 305

I have a scenario where there is a root domain (RD) and two child domains (CD1 and CD2). Users have accounts on both CD1 and CD2, with identical samAccountNames, names etc, and various applications either use the CD1 or CD2 account for authentication to resources.

I need to collapse CD2 into CD1, so I want to merge the accounts together. However ADMT does not allow me this option (merge options are greyed out), I think because it does not support intraforest merge of accounts (although it does not explicitly state this anywhere in the documentation).

My question is - what is the easiest way for me to merge these accounts? Ultimately all I really need (I think) is for the SID of CD2\user1 to be added to the SIDHistory of CD1\user1 - is there a tool that supports this?

Computer accounts and profiles are not a concern for this scenario. Group migration is unlikely to be an issue either - CD2\user1 is usually granted resource access through membership of a group on CD1.

© Server Fault or respective owner

Related posts about active-directory

Related posts about windows-domain