Our client currently have two AD forest, A and B.
Data will be copied from forest A to forest B with third party software
to preserve NTFS security. After moving data, ACL on folders and subfolders
in target domain will look like domainA\groupname.
Using ADMT with SID to migrate global groups, I wonder if ACL on folders and
subfolders in target domain
will look like domainB\groupname ? That's what we want.
It will be too much work to recreate hundreds global groups
and applicate NTFS security as well!
An external trust exist between both forest, it is an outgoing trust
from B to A. It is not configurated in both ways. I think this way, ADMT
will not operate.
Any suggestion ?
|