Migrates managed service accounts from a source domain that you specify to a target domain that you specify.
Admt managedserviceaccount is a command-line tool that is available in the Active Directory® Migration Tool (ADMT).
For examples of how you can use this command, see Examples.
Syntax
admt managedserviceaccount /n "<MSAName>"[ "<MSAName2>"] /sd:<SourceDomain> /td:<TargetDomain> admt managedserviceaccount /n "<MSAName>"[ "<MSAName2>"] /o:<OptionFilename>
Parameters
Parameter | Description | ||||
---|---|---|---|---|---|
/{o|optionfile}:"<OptionFilename>" |
Specifies to use an options file. You can specify the following value for this parameter:
|
||||
/{if|intraforest}:{yes|no} |
Specifies whether the migration is within a single forest. You can specify the following values for this parameter:
|
||||
/{sd|sourcedomain}:"<SourceDomain>" |
Specifies the NetBIOS (Network Basic Input/Output System) or Domain Name System (DNS) name of the source domain from which to migrate objects. |
||||
/{sdc|sourcedomaincontroller}:"<SourceDomainControllerName>" |
Specifies the NetBIOS or DNS name of the domain controller in the source domain to use to migrate objects.
|
||||
/{so|sourceou}:"<OUName>" |
Specifies the name of organizational unit (OU) in the source domain. You use this parameter only for Active Directory source domains. |
||||
/{td|targetdomain}:"<TargetDomain>" |
Specifies the NetBIOS or DNS name of the target domain to which to migrate objects. |
||||
/{tdc|targetdomaincontroller}:"<TargetDomainControllerName>" |
Specifies the NetBIOS or DNS name of the domain controller in the target domain to use to migrate objects.
|
||||
/{to|targetou}:"<OUName>" |
Specifies the name of OU in the target domain. This parameter is required for both interforest and intraforest migrations. |
||||
/{mss|migratesids}: {yes|no} |
Specifies whether the source managed service account security identifier (SID) migrates to the SID history of the target account. You can specify the following values for this parameter:
|
||||
/{uur|updateuserrights}: {yes|no} |
Specifies whether to set the user rights of the target account to match the user rights of the source managed service account. You can specify the following values for this parameter:
|
||||
/{mgs|migrategroups}: {yes|no} |
Specifies whether to migrate to the target domain the groups of which the source managed service account is a member. When ADMT uses this parameter to migrate a group, it does not migrate group members. You can specify the following values for this parameter:
|
||||
/{umo|updatepreviouslymigratedobjects}: {yes|no} |
Specifies whether to migrate groups again during this migration that ADMT migrated previously. ADMT performs this operation only when you specify the yes value with the /migrategroups parameter during subsequent migration operations. You can specify the following values for this parameter:
|
||||
/{fgm|fixgroupmembership}: {yes|no} |
Specifies whether to add migrated managed service accounts to target domain groups if those managed service accounts were members of groups that ADMT migrated from the source domain. You can specify the following values for this parameter:
|
||||
/{n|includename} "<MSAName>" ["<MSAName2>"] |
Specifies a managed service account or a list of managed service accounts to migrate. You can specify the following value for this parameter:
|
||||
/{f|includefile}: <FileName> |
Specifies the name of a file that contains a list of managed service accounts to migrate. You can specify the following value for this parameter:
|
||||
/{d|includedomain}: [recurse] |
Specifies an entire source domain or OU of accounts. This parameter specifies to enumerate the source OU for managed service accounts. If you do not specify the source OU, ADMT enumerates the entire source domain. You can specify the following value for this parameter:
|
||||
/{en|excludename} "<MSAName>" ["<MSAName2>"] |
Specifies which managed service accounts to exclude from migration. You can specify the following value for this parameter:
|
||||
/{ef|excludefile}: <FileName> |
Specifies the name of a file that contains the list of managed service accounts to exclude from the current migration operation. You can specify the following value for this parameter:
|
Remarks
In addition to the admt managedserviceaccount command-line tool, you can use the User Account Migration Wizard to migrate managed service accounts from a source domain that you specify to a target domain that you specify.
Examples
The following example migrates a managed service account named SQL-Srv1 from the CONTOSO domain to the TREYRESEARCH domain.
admt managedserviceaccount /n "SQL-Srv1" /sd:CONTOSO /td:TREYRESEARCH
The following example migrates managed service accounts by using an include file that is located at C:\temp\MyListOfAccounts.txt.
admt managedserviceaccount /o:C:\temp\MyListOfAccounts.txt