Home > Ask the Microsoft Exchange Experts > David Sengupta: Server Administration Questions & Answers > Synchronizing two AD domains
Ask The Exchange Expert: Questions & Answers
EMAIL THIS

Synchronizing two AD domains

David Sengupta EXPERT RESPONSE FROM: David Sengupta

Pose a Question
Other Exchange Categories
Meet all Exchange Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 12 April 2005
We recently acquired a company and are in the process of testing our network setup. Our forest master and Exchange are on Domain A. Domain B is trying to access e-mail in Domain A. So there is a user account on Domain B and a user account with an Exchange mail store on Domain A. Right now, they are set up as a tree in our forest. I want to see if it is possible to synchronize Domain A's Active Directory with Domain B's Active Directory, so we don't have to change passwords in two domains. How do we accomplish this?


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Microsoft Exchange Server User Settings
Email issues after configuring hosted Exchange server on laptop
Control Outlook 2007 in cached mode settings with group policies
Group policy settings for Outlook 2007 in cached mode
Restrict access to Outlook Web Access via Exchange System Manager
How to custom-configure a Microsoft Outlook 2007 install using OCT
Expand Microsoft Outlook email rules with the Auto-Mate add-on tool
Exchange 2007 out-of-office (OOF) feature adds usability and security
Managing Microsoft Outlook search folder functionality
Back up and restore Microsoft Outlook settings
Managing Microsoft Outlook's AutoComplete option

Exchange Server Deployment and Migration Advice
Exchange Server 2010 bows with improved recovery
Leapfrogging from Exchange 2003 to Exchange 2010
Two useful tools for documenting an Exchange Server installation
Avoid these Exchange Server migration pitfalls
Why it's important to document your Exchange installation
Exchange Server 2007 support ends at Windows Server 2008
Best practices for moving mailboxes in Exchange Server
Exchange Server 2007: Email archiving tips and hosted services trends
Exchange Insider e-zine
ExMerge gotchas to watch for when migrating Exchange 2003 mailboxes

David Sengupta: Server Administration
Show hidden email addresses in a GAL on Exchange Server 2003
Message date and send times showing incorrectly in Outlook and OWA
Changing email address formats in Exchange Server 2003
Should you remove .STM files from Exchange Server 2003?
Exchange users receiving email addressed to legacy users
Pushing a public calendar out from a private Exchange account
Import and export .PST files in Exchange Server 2007
Editing Exchange Server public folder permissions
Search and index Microsoft Outlook 2007 public folders
Troubleshooting Microsoft Exchange Server Event ID error 6009

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
rehoming  (SearchExchange.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


If Domain A trusts Domain B, you should just be able to give all the Domain B accounts rights to access the Domain A mailboxes. That way, you don't need to worry about the passwords for Domain A accounts. In other words, the only accounts you'd need to manage for the time being are Domain B accounts. To set this up:

  1. Launch Active Directory Users and Computers (ADUC) on a machine with Exchange System Manager installed and connected to Domain _.

  2. View the properties of each mailbox and switch to the Exchange Advanced tab. (If you don't see this tab in ADUC, see KB article 326894, How to Access the Exchange Advanced Tab in Active Directory Users and Computers).

  3. Now select Mailbox Rights.

  4. Make sure the Domain B account is added to the list of security principals having access (typically only "self") in order to facilitate the two-domain coexistence scenario.

Essentially, you're asking how to simplify management of your users' identities across multiple accounts and passwords. Various solutions exist focused on identity management. Microsoft has a solution called Microsoft Identity Integration Server (MIIS) that permits exactly what you're asking, namely synchronization of passwords across multiple domains as you described.

More importantly, in your case, I believe you can use a free scaled down version of MIIS called the Identity Integration Feature Pack 1a for Microsoft Windows Server Active Directory, which can synchronize passwords across Active Directory, ADAM and Exchange Server environments. You'll also want to install the update.

If you want a more sophisticated solution that will do all this plus assist once you start migrating users from Domain B into Domain A, I suggest looking at third-party migration solutions.


Do you have comments on this Ask the Expert Q&A? Let us know.




Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Outlook Web Access (OWA) Tips and Advice
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersIT Downloads
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2004 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts