Directory Service directory migration between accounts

0

Hello to anyone reading,

I have a question about the following, imagine that an AWS customer creates their account and chooses to use the Directory Service service for their Microsoft AD.

Over the years, this company was purchased by a company and its account became a daughter account.

Is it possible to migrate as a replica the Directory service with all the records of groups, users and everything else? Taking into account that after migration the Directory has to be deleted from the child account.

Thank you very much.

질문됨 2년 전681회 조회
1개 답변
-1

Good day, there

Yes, you can now use the Active Directory Migration Toolkit (ADMT) along with the Password Export Service (PES) to migrate your self-managed AD to AWS Directory Service for Microsoft Active Directory, also known as AWS Managed Microsoft AD, since the company was purchased and running their AD's on premises.This makes it easier for you to move AD objects and encrypted passwords for your users.Please see the attached document for more information.

Resource: https://aws.amazon.com/blogs/security/how-to-migrate-your-on-premises-domain-to-aws-managed-microsoft-ad-using-admt/

답변함 2년 전
  • This answer is incorrect, you cannot migrate password out of AWS Managed AD, you could migrate the users themselves from one directory to another but SID history and passwords would not be synced to the new managed Active Directory environment.

로그인하지 않았습니다. 로그인해야 답변을 게시할 수 있습니다.

좋은 답변은 질문에 명확하게 답하고 건설적인 피드백을 제공하며 질문자의 전문적인 성장을 장려합니다.

질문 답변하기에 대한 가이드라인

관련 콘텐츠