Migrate and modernize identity and devices
ODM enables you to turn migration into a repeatable process without trusts or installing servers. You can safely run your Active Directory, Entra ID or hybrid environment migration during normal business hours while your users can keep working without interruption.
Highlighted Features
Active Directory and Entra ID migration
Migrate users, groups and directories across AD and Entra ID with synchronization maintained throughout the process.
- Merge AD environments without a trust relationship
- Support one-to-one, one-to-many, many-to-one and many-to-many configurations
- Migrate objects, settings, properties, workstations and servers within and between forests
- Auto-update permissions on migrating and remaining resources
Entra device migration
Modernize and migrate devices to the cloud as part of identity migration without disrupting end users.
- Migrate Windows 10 and 11 devices to Entra without reimaging
- Migrate to traditional AD, hybrid Entra ID, or cloud-only environments
- Migrate remote users via simple wizard; no office visit needed
- Pre-schedule migrations with users experiencing only a brief restart prompt
Domain migration
Migrate domains between tenants with this AD migration tool, without impacting mail delivery or causing downtime, including hosted Exchange scenarios.
- Schedule migrations during normal business hours or after-hours
- Run custom scripts and commands to update files, folders and registry settings
- Avoid remote procedure calls (RPCs) and remote registry access and minimize open firewall ports
Subscription plans
Choose from our family of device migration solutions to meet your different needs. For example, if you're:
- Converting existing hybrid to cloud-only for AD Mod - you may be interested in ODM Entra ID Devices
- Migrating devices from one environment to another and don't require any coexistence - you may be interested in ODM AD Express
- Performing a full AD migration that requires customization and/or coexistence - ODMAD is full-featured to meet the most advanced scenarios
The below table may help you in understanding how your needs could match the Quest device solutions.
| Feature | ODM AD | ODM Entra ID Devices |
| Device Migration |
| ✓ |
| Wizard-drive project setup |
| ✓ |
| System-managed workflows |
| ✓ |
| Discover and Match with CSV | ✓ | ✓ |
| Intune-compatible | ✓ | ✓ |
| Device migration from AD or hybrid to Entra ID | ✓ | ✓ |
| Device migraion from any source to AD or hybrid | ✓ | ✓ |
| Devices + AD Migration |
|
|
| Target user creation (minimal attributes*) | ✓ |
|
| Target group creation (minimal attributes* and membership) | ✓ |
|
| VPN migration using offline domain join | ✓ |
|
| Intra-forest device migration | ✓ |
|
| Server migration from AD to AD | ✓ |
|
| Agent servers required for AD environments | ✓ |
|
| Advanced Data Functionality |
|
|
| Target object provisioning (full attribute sync, as-is or transformed) | ✓ |
|
| Ongoing directory sync | ✓ |
|
| Password sync | ✓ |
|
| SID History migration | ✓ |
|
| Contact migration | ✓ |
|
| NAS File Share ReACL, AD Processing Wizard | ✓ |
|
| Customizable workflows | ✓ |
|
*ODM AD Express can create target user and group ojects with a minimal set of attributes to facilitate a successful device ReACL.
AD minimal attributes: objectClass, userPrincipalName, displayName, givenName, sn, userAccountControl, pwdLastSet, DistinguishedName, samAccountName, name, mailNickname, groupType, and member.
Entra ID minimal attributes: objectClass, UserPrincipalName, DisplayName, FirstName, LastName, AccountEnabled, Password, Name, Alias, GroupType, RecipientTypeDetails, RecipientType, and Member.
Subscription plans
Knowledge Center
A Guide to AD Migrations and Directory Synchronization
Quest® Toad® AI Insights is a suite of AI-powered capabilities built directly into Toad Solutions.
On Demand Migration Directory Sync
But with On Demand Migration (ODM) Directory Sync, you can ensure productivity across your on-premises, cloud or hybrid environment on Day One of your merger, acquisition or consolidation project.
FAQ
Performing an AD migration or consolidation with the right AD migration tool can help strengthen your AD security, centralize your domain management, and improve end user experience. If your company currently maintains separate domains for different departments or regions, you can combine the domains to provide standardized management and security policies, while still maintaining the ability to provide granular access to the consolidated resources.
Conversely, you might be managing multiple Active Directory domains because of a merger, acquisition, or divestiture. Configuring integration between the domains can help provide coexistence by syncing passwords and providing cross-domain resource access, but this can result in increased risk and management effort. If you are maintaining separate domains after a tenant-to-tenant migration, your end users might struggle with managing multiple identities. You should always make sure Active Directory domain consolidation is part of your tenant-to-tenant migration discussions.
Active Directory is Microsoft’s original on-premises enterprise solution for organizing and managing a company’s resources such as users, groups, and devices. Active Directory objects are configured within organizational units that belong to a domain, which can itself belong to another domain or forest. Active Directory is managed by domain controllers, which can physically reside in a company office or data center or can run as virtual machines. When users need to access resources and applications on Active Directory servers, they must have direct network access or connect to a virtual private network.
Entra ID fully resides in the cloud and removes the need for domain controllers, organizational units, and direct network access to physical servers. Microsoft maintains the infrastructure for your Entra ID tenant, scaling up as needed to support your company’s tenant activity. Users, groups, devices, and other resources are created and managed in the tenant, and users only need Internet connectivity to access cloud resources. Microsoft Entra ID can also serve as an extension to Active Directory by enabling synchronization between the two environments, allowing users to authenticate to Active Directory for local resources while also having access to the cloud-only resources in Entra ID.
Microsoft 365 and Microsoft Entra ID tenants are complex cloud platforms that include many different components and resources. Microsoft supports tenant-to-tenant migrations for many of its individual workloads; however, you cannot migrate an entire tenant as-is, and there are many configurations and resources that must be directly configured in another tenant.
When it comes to AD migration, Microsoft supports migrating Entra ID objects such as users, groups, contacts, guests, and Entra ID-joined devices from one tenant to another. Microsoft also supports tenant-to-tenant migrations for Microsoft 365 content such as mailboxes, OneDrive, Teams, and SharePoint. You can use an AD migration tool to perform these migrations, enable cross-tenant coexistence, and replicate resource access. Although there is no direct migration path for Azure applications, virtual servers, and most tenant policies and configurations, the Microsoft community has built a tool for exporting and importing many tenant settings to assist with your tenant migration, and a dedicated AD migration tool can help fill in the gaps.