Merge users from two ADDS Forest

Siddhesh Sawant 46 Reputation points
2020-07-29T08:00:58.853+00:00

My company split from ABC.com to XYZ.com few months back. Many of our applications, servers and portals are still there in ABC.com environment and still in planning stage to migrate in XYZ domain. Both the domains have separate Active directory servers, where we have created new User accounts (Instead of Migrate them) of few existing employees in XYZ.com. Now we have same user in both the Forest AD with different domain name for example, User1.ABC.com is authorize to access all the applications, servers and company portal of ABC domain. After Split instead of Deactivate in ABC domain and Migrate to XYZ domain, we create new account User1.XYZ.com in XYZ domain.

Now, when users from XYZ domains wanted to access resources in ABC domain, they have to use their ABC.com credentials and for XYZ domain they use XYZ Credentials. As it is difficult to remember multiple credentials every time, we propose them to setup trust relationship between these two domains. But doing so, one should have to identify User1.ABC.com permissions in ABC.com and assign same permissions to User1.XYZ.com for all the users.

Is there any way/tool, using which we can map same users from both the domains? For example, we will map User1.ABC.com with User1.XYZ.com. So that whenever User1.XYZ.com wants to access resources from ABC domain, he/she will simply provide XYZ credentials and access all the resources (only those resources on which User1.ABC.com has permissions).

Any suggestions are welcome.

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
6,382 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Fan Fan 15,326 Reputation points Microsoft Vendor
    2020-07-30T02:27:26.767+00:00

    Hi,
    Based om my experience, there is not such a way to map the users .
    In your situation, i would suggest :
    1,Assign the same password to the accounts: User1.ABC.com User1.XYZ.com
    2,Create a forest and assign the permission to the resource.

    Best Regards,


  2. Siddhesh Sawant 46 Reputation points
    2020-09-28T12:14:15.417+00:00

    Thanks for your help @Fan Fan

    i found an alternate solution. where i can migrate User SID history attribute using ADMT tool to achieve this.


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.