Notices


 
 
LinkBack Thread Tools Display Modes
Prev Previous Post   Next Post Next
  #1  
Old 03-Nov-2009, 03:03 AM
Junior Member
 
Join Date: Jan 2009
Location: Norway
Posts: 6
alexmchugh 0 reputation points
Default ADMT migrate not generating delete event

Have 3 AD drivers, each to a separate AD domain. All three domains are in the same AD forest. Provisioning users only. By design a user in the ID Vault should have an account in only one of the three domains at any time. This is implemented via entitlements.

Testing using Microsoft Active Directory Migration Tool (ADMT) to migrate users in bulk from one domain to another domain within forest (intra forest migration)

I expected the following to work.
  1. Migrate user using ADMT
  2. IDM receives an add event from new domain and ignores this because we are using user account entitlement for each AD domain.
  3. IDM receives a delete event from old domain and transforms that to a remove association event.
  4. Grant entitlement to new domain, revoke entitlement to old domain. This results in associating the user object with the new domain.

My problem is that step 3 never happens. Everything else works fine. I end up with an orphaned association for the old domain.

This is an intra forest migration ADMT and does not seem to generate a delete event that the IDM driver can see. The object is no longer available in the old domain, I can't find it via Active Directory Users and Computers or a LDAP search.

Does anyone have any experience with ADMT and what it actually does with the object? The ADMT documentation says it "moves" the object. Is it possible to actually move an object between domains within an AD forest rather than implement the move as a copy/delete like I expected.

Any suggestions on workarounds? Maybe the add association event in the new domain could trigger the generation of remove association events from the other two domains?
Reply With Quote
 

Tags
ad migration tool, admt

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are Off
[IMG] code is Off
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -6. The time now is 08:20 PM.


© 2007 Novell, Inc. All Rights Reserved.

Search Engine Friendly URLs by vBSEO 3.3.0 RC2