Sys-Manage Logo
SSL | Register | Login Monday, May 17, 2021 Flag en-US 

Sys-Manage CopyRight2 Active Directory Migration Features Explained


CopyRight2 is a market leading Active Directory domain migration tool. Migrate users, groups, distribution lists, contacts, organizational units (OU) and containers easily, reliably and securely between domains in the same or across different domain forests.

The Migration of NTFS and File Share Resource Permissions

CopyRight2 offers the ability to replace source accounts used in file share and NTFS level permissions with the accounts migrated to the target domain. Either on-the-fly while migrating data or in-place if the data should remain in the current location.

Why Not To Migrate Active Directory with ADMT?

CopyRight2 is a lot easier to use and does not have the complexity and overhead of ADMT. Watching the 12 minute video below, will explain all you need to know, to perform a migration. Opposed to Microsoft's ADMT, the CopyRight2 Active Directory Migration tool does not require a trust between source and target domains. Neither does it require any agents that have to be installed, nor does it require an SQL server instance. As CopyRight2 supports sidHistory-less migrations, there is no security risk attached to it and no need for a sidHistory clean-up either.

Active Directory Migration With sidHistory or Without sidHistory?

However, if desired, it can equally perform an Active Directory migration using sidHistory in intra- and interforest migration scenarios. If using sidHistory, CopyRight2 can assist you during the necessary sidHistory clean-up phase. At that stage the original SIDs of accounts migrated to the target domain are still being referenced in share and NTFS permissions. So before the sidHistory attribute can be emptied, to properly complete the Active Directory migration, they need to be gradually replaced with the SIDs of the target accounts. This can again either occur on-the-fly while you use CopyRight2 to migrate the data to a new location or in-place if the data should remain in the same place.

Which Source and Target Active Directories Does It Support?

In addition to Windows Active Directory, CopyRight2 supports Azure AD Connect, AWS Directory Service, Synology Active Directory Server and Univention's UCS Active Directory Domain Controller Appliance as source or target.

CopyRight2 Domain Migration - Main Feature List

With CopyRight2 you can migrate Active Directory users (including passwords), groups (including members), distribution lists (including members), contacts, organizational units and containers. The product supports all existing types of Active Directory groups, no matter if it is local, global, universal, security or distribution list groups.

CopyRight2 can be installed on any computer, preferably on a domain controller of the source or the destination domain. Once the software is installed, it can be used right away to define and interactively run Active Directory migration jobs or schedule jobs for background execution at a specified time.

In case there is a problem using the software, you can contact Sys-Manage's support at any time. Our experienced support engineers have helped thousands of customers to complete their migrations successfully. You can contact us at any time using email or by telephone.

CopyRight2 allows you to migrate...

  • ...all accounts from the source Active Directory.
  • ...accounts selected from the Active Directory tree.
  • ...accounts provided in a specified input text file.
  • ...accounts returned from a LDAP query, by specifying a query root and a query filter condition.

Select Objects To Migrate in Low Resolution

CopyRight2's attribute in- and exclusion list allows you to define which attributes you want to migrate by object class type. You can also provide an empty attribute list, in which case all class specific attributes defined in the Active Directory schema will be copied.

CopyRight2 Active Directory Attribute Settings

Using CopyRight2 you can migrate accounts to the default "Users" container or into a specified container, optionally while retaining the original OU and container hierarchy structure.

CopyRight2 Active Directory OU Settings in Low Resolution

CopyRight2 can migrate the permissions set on any Active Directory objects, such as users, groups, contacts, distribution lists, organizational units and containers. It migrates the permissions (DACL), auditing information (SACL) and the owner.

CopyRight2 Object Security Settings in Low Resolution

You can schedule any Active Directory migration jobs to run automatically in the background at specified intervals. Receive email notifications for the job in case of success and/or error.

Copyright2 Task Scheduler Settings in Low Resolution

CopyRight2 supports Windows sidHistory Active Directory attribute to separate the account migration from the resource migration and computer roll-out. Using this feature allows migrated user and group accounts to access resources still located in the source environment having permissions for the original source accounts only. Beyond that, you can use CopyRight2 to reassign NTFS and file share permissions to use the migrated new accounts and to cleanup the sidHistory attribute once it is no longer needed. Interforest migrations If the source and destination domain are located in different domain forests, you create a clone of each source user or group in the destination domain, having the sidHistory attribute set to the corresponding SID of the original account. Intraforest migrations If the source and destination domain reside in the same forest, for example a parent <-> child domain relationship, the user and group accounts will be moved between the source and destination domain, causing accounts to get a new SID, but also having the sidHistory attribute set to the corresponding SID of the original accounts. You can find more information about using the sidHistory attribute in the CopyRight2 Documentation.

CopyRight2 sidHistory Settings

It is, however, not a requirement to use the sidHistory attribute with CopyRight2. You can also directly migrate user and group accounts and reassign NTFS and file share permissions of any data on-the-fly while copying or by processing permissions without moving data.


AD Migration With CopyRight2 Tutorial Video:

Active Directory Migration Video Thumb

Download the Free 30-Day Trial Version of CopyRight2 Now

Convince yourself and visit the download section of our web site to get the free 30-day trial version of Sys-Manage CopyRight2 now.

Do You Have Any Questions or Suggestions?

In case of any questions or suggestions, please feel free to contact us at We like hearing from you.
What types of Active Directory objects does it migrate?
What types of Active Directory objects does it migrate?
CopyRight2 can migrate users, contacts, groups (global, local, universal), distribution lists, members, OUs and optionally object permissions (ACL). You can define which attributes you want to migrate per object type. For extensibility you can define small scripts to transform objects during the migration.
Does it require a trust?
Does it require a trust?
No, it does not require a trust between domains. It works though if a trust is in place, but it is not a requirement. You can also migrate objects from a member or workgroup mode system to a domain with it.
Does it support sidHistory?
Does it support sidHistory?
Yes, it does. If using sidHistory there is a bunch of requirements that need to be fulfilled, for example a trust. Please check the documentation for those. However, you can also migrate without sidHistory and optionally migrate your data using a data migration job, replacing the original accounts with the accounts of the target domain.
  Logo Certifications  
Download CopyRight2 File Server Migration Software
  Buy Now  

Buy CopyRight2 File Server Migration Software
Copyright © Sys-Manage, 1998-2021. All Rights Reserved.

Privacy Statement
Terms Of Use