Processing by RUM and ADPW

Hello IT Consultants,

Greetings of the day!

I have questions and confusion regarding Quest Migration tools RUM and ADPW. Hope you guys will explain this.

Processing by RUM and ADPW. Let me explain what I meant to say.

Q1: Resources e.g. File/Folder/Share ACL processing is only done by RUM while moving server to target domain?

Q2: Processing by ADPW is done while adding migrated target user and groups to source domain local groups in order to access source domain resources while server is connected to source domain. What about Security Descriptor processing? When and in which domain it is performed after migration? Does security descriptor processing depends on domain membership of server as well? 

I read somewhere that "Anywhere in any trusting Active Directory where you may find a SOURCEDOM user or group that you migrated with QMM in an ACL or group membership, you want to run ADPW". So my question is how does ADPW process ACL? I think file/folder/share ACL is updated by RUM only? ADPW is only used for updating group membership, security descriptor processing, cleanup sidhistory only. Then how does ADPW process ACL? 

Q3: What about Server local group processing? When and in which domain it is performed? Do we need to add migrated target users and groups in the source server local groups? Is this only done when server is connected to source domain? What if server is moved to target domain then what needs to be done?

Q4: What about workstation processing. When, in which domain and by which tools it is performed?

Q5. Please explain other processing scenarios by ADPW and RUM.

Thanks in advance!

Top Replies

Parents
  • Hi Doug, 

    Just about every answer here is laid out in the documentation for MMAD which I've linked below.   

    Migration Manager for AD - Technical Documentation (quest.com)

  • Since I'm relatively new to Migration stuff, I was expecting answers and explanation specific to my questions. It's pretty difficult for me to get answers specific to my questions. Also I have confusions as well and that requires expert consultation where technical guide isn't much helpful. Since I'm asking valid questions related to processing tools, I will expect that I will get my questions answered and explained.

  • - with utmost respect, this Forum is not a "migration school" nor is it intended to provide on-demand consulting.  Domain migrations are complex undertakings with many variables that can influence both the need for and timing of certain activities like the use of ADPW, file system re-permissioning and so on.

     It is not possible to explain every nuance of every scenario in documentation.

    Due to this complexity and the limitations of what can be explained in documentation, customers who undertake migration projects using the Migration Manager tool will usually hire experienced Consultants to help them understand the tool and help to design their processes with them.  The experience these Consultants bring includes both advanced knowledge of Active Directory and the Migration Manager tool.

    The challenge we have with the types of questions you are asking is that they are often very broad like:

    Q5. Please explain other processing scenarios by ADPW and RUM.

    We don't have the time or the space to explain all of your options - that is what Consultants are for.

    In other cases, the initial answer is going to be one or more of:  "it depends on your process" and/or "it depends on your environment" and/or "it depends on your I.T. processes".  

    I can give you a short answer to this one:

    Q1: Resources e.g. File/Folder/Share ACL processing is only done by RUM while moving server to target domain?

    No - it can be done while the server sits in the source, the target or both.  Re-ACL'ing is not solely tied to the actual move of the server.  The move is a separate operation.  

    And to this one:

    So my question is how does ADPW process ACL? 

    The ACLs in question here are ACLs on AD objects (also sometimes called security descriptors) - ADPW can update those.  Under the covers, it works exactly the same way as it does in the file system - translate SOURCE\Objectname to TARGET\ObjectName based on mappings that QMM establishes within its Project data when you initially migrate your user and group objects.



Reply
  • - with utmost respect, this Forum is not a "migration school" nor is it intended to provide on-demand consulting.  Domain migrations are complex undertakings with many variables that can influence both the need for and timing of certain activities like the use of ADPW, file system re-permissioning and so on.

     It is not possible to explain every nuance of every scenario in documentation.

    Due to this complexity and the limitations of what can be explained in documentation, customers who undertake migration projects using the Migration Manager tool will usually hire experienced Consultants to help them understand the tool and help to design their processes with them.  The experience these Consultants bring includes both advanced knowledge of Active Directory and the Migration Manager tool.

    The challenge we have with the types of questions you are asking is that they are often very broad like:

    Q5. Please explain other processing scenarios by ADPW and RUM.

    We don't have the time or the space to explain all of your options - that is what Consultants are for.

    In other cases, the initial answer is going to be one or more of:  "it depends on your process" and/or "it depends on your environment" and/or "it depends on your I.T. processes".  

    I can give you a short answer to this one:

    Q1: Resources e.g. File/Folder/Share ACL processing is only done by RUM while moving server to target domain?

    No - it can be done while the server sits in the source, the target or both.  Re-ACL'ing is not solely tied to the actual move of the server.  The move is a separate operation.  

    And to this one:

    So my question is how does ADPW process ACL? 

    The ACLs in question here are ACLs on AD objects (also sometimes called security descriptors) - ADPW can update those.  Under the covers, it works exactly the same way as it does in the file system - translate SOURCE\Objectname to TARGET\ObjectName based on mappings that QMM establishes within its Project data when you initially migrate your user and group objects.



Children
No Data