<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Migrating Filer to new AD Domain in Network and Storage Protocols</title>
    <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Migrating-Filer-to-new-AD-Domain/m-p/141581#M9068</link>
    <description>&lt;P&gt;Hey all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've been tasked with an Active Directory consolidation project from a M&amp;amp;A. I use Active Directory Migration Tool (ADMT) from Microsoft to migrate the users, groups, and computers which does a security translation during the migration process and utilizes SID History to preserve access during the project.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With Windows File Servers ADMT deploys an agent and does the Security Translation which re-ACLs all of the shares, folders, and files. This won't work on the NetApp Filer I need to move. Do any of you know of a good way to do the security translation on the NetApp filer? I'm not a Storage guy, so I'm not sure. Any tools/products you use? I did a search on the forum but just found some old topics that didn't provide what I was looking for.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any feedback is really appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks much!&lt;/P&gt;</description>
    <pubDate>Wed, 04 Jun 2025 13:30:06 GMT</pubDate>
    <dc:creator>BPurchell</dc:creator>
    <dc:date>2025-06-04T13:30:06Z</dc:date>
    <item>
      <title>Migrating Filer to new AD Domain</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Migrating-Filer-to-new-AD-Domain/m-p/141581#M9068</link>
      <description>&lt;P&gt;Hey all,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've been tasked with an Active Directory consolidation project from a M&amp;amp;A. I use Active Directory Migration Tool (ADMT) from Microsoft to migrate the users, groups, and computers which does a security translation during the migration process and utilizes SID History to preserve access during the project.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;With Windows File Servers ADMT deploys an agent and does the Security Translation which re-ACLs all of the shares, folders, and files. This won't work on the NetApp Filer I need to move. Do any of you know of a good way to do the security translation on the NetApp filer? I'm not a Storage guy, so I'm not sure. Any tools/products you use? I did a search on the forum but just found some old topics that didn't provide what I was looking for.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Any feedback is really appreciated.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Thanks much!&lt;/P&gt;</description>
      <pubDate>Wed, 04 Jun 2025 13:30:06 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Migrating-Filer-to-new-AD-Domain/m-p/141581#M9068</guid>
      <dc:creator>BPurchell</dc:creator>
      <dc:date>2025-06-04T13:30:06Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating Filer to new AD Domain</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Migrating-Filer-to-new-AD-Domain/m-p/141667#M9082</link>
      <description>&lt;P&gt;Hi&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i assume that if you don't remove the SID history from the Users and Groups. you can avoid the RE-ACL&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;i'm not aware of a NetApp way to do re-acl. maybe other tool can do.&amp;nbsp; also have a quick look on this to see if re-acl actually a good idea:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://pshirwin.wordpress.com/2017/06/13/the-lowdown-on-sidhistory/" target="_blank"&gt;https://pshirwin.wordpress.com/2017/06/13/the-lowdown-on-sidhistory/&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Gidi&lt;/P&gt;</description>
      <pubDate>Mon, 23 Jul 2018 18:57:47 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Migrating-Filer-to-new-AD-Domain/m-p/141667#M9082</guid>
      <dc:creator>GidonMarcus</dc:creator>
      <dc:date>2018-07-23T18:57:47Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating Filer to new AD Domain</title>
      <link>https://community.netapp.com/t5/Network-and-Storage-Protocols/Migrating-Filer-to-new-AD-Domain/m-p/141672#M9083</link>
      <description>&lt;P&gt;-As&amp;nbsp;&lt;a href="https://community.netapp.com/t5/user/viewprofilepage/user-id/38137"&gt;@GidonMarcus&lt;/a&gt;&amp;nbsp;mentioned&amp;nbsp;&lt;SPAN&gt;if you don't remove the SID history from the Users and Groups. you can avoid the RE-ACL part.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;- First join the filer in the new DOMAIN.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Regarding&amp;nbsp;NetApp way to do re-acl&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;first I like to ask what version of ONTAP it is 7 mode or CDOT.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;regarding the ra-acl then I can comment for the groups part of the shares like (domain admins/or admins groups) then there is a way to do the re-acl the shares on netapp side&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Here is the link for the documentation(this is for ONTAP 9 or CDOT) :&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="http://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-cmpr-910%2Fvserver__security__file-directory__show.html" target="_blank"&gt;http://docs.netapp.com/ontap-9/index.jsp?topic=%2Fcom.netapp.doc.dot-cm-cmpr-910%2Fvserver__security__file-directory__show.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;if it is 7mode filer then re-acl for groups then you need to download secedit tool from tool chest and use it.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 24 Jul 2018 00:21:02 GMT</pubDate>
      <guid>https://community.netapp.com/t5/Network-and-Storage-Protocols/Migrating-Filer-to-new-AD-Domain/m-p/141672#M9083</guid>
      <dc:creator>naveens17</dc:creator>
      <dc:date>2018-07-24T00:21:02Z</dc:date>
    </item>
  </channel>
</rss>

