ad, entra id and device migration

Active Directory, Entra ID and device migration

Migrating Active Directory and Entra ID with the right AD migration tool is one of the most challenging parts of enterprise M&A and modernization. On Demand Migration (ODM) lets you migrate users, groups and devices across Active Directory, Entra ID and hybrid environments without trusts, servers or downtime, while maintaining visibility and control throughout the migration.

Migrate and modernize identity and devices

ODM enables you to turn migration into a repeatable process without trusts or installing servers. You can safely run your Active Directory, Entra ID or hybrid environment migration during normal business hours while your users can keep working without interruption.

Highlighted Features

Active Directory and Entra ID migration

Migrate users, groups and directories across AD and Entra ID with synchronization maintained throughout the process.

  • Merge AD environments without a trust relationship
  • Support one-to-one, one-to-many, many-to-one and many-to-many configurations
  • Migrate objects, settings, properties, workstations and servers within and between forests
  • Auto-update permissions on migrating and remaining resources
ad and entra id migration
entra device migration

Entra device migration

Modernize and migrate devices to the cloud as part of identity migration without disrupting end users.

  • Migrate Windows 10 and 11 devices to Entra without reimaging
  • Migrate to traditional AD, hybrid Entra ID, or cloud-only environments
  • Migrate remote users via simple wizard; no office visit needed
  • Pre-schedule migrations with users experiencing only a brief restart prompt

Domain migration

Migrate domains between tenants with this AD migration tool, without impacting mail delivery or causing downtime, including hosted Exchange scenarios.

  • Schedule migrations during normal business hours or after-hours
  • Run custom scripts and commands to update files, folders and registry settings
  • Avoid remote procedure calls (RPCs) and remote registry access and minimize open firewall ports
domain migration

Subscription plans

Body

Choose from our family of device migration solutions to meet your different needs. For example, if you're:

  • Converting existing hybrid to cloud-only for AD Mod - you may be interested in ODM Entra ID Devices
  • Migrating devices from one environment to another and don't require any coexistence - you may be interested in ODM AD Express
  • Performing a full AD migration that requires customization and/or coexistence - ODMAD is full-featured to meet the most advanced scenarios

The below table may help you in understanding how your needs could match the Quest device solutions.

Feature ODM ADODM Entra ID Devices
Device Migration

 

Wizard-drive project setup

 

System-managed workflows

 

Discover and Match with CSV

Intune-compatible

Device migration from AD or hybrid to Entra ID

Device migraion from any source to AD or hybrid

Devices + AD Migration

 

 

Target user creation (minimal attributes*)

 

Target group creation (minimal attributes* and membership)

 

VPN migration using offline domain join

 

Intra-forest device migration

 

Server migration from AD to AD

 

Agent servers required for AD environments

 

Advanced Data Functionality

 

 

Target object provisioning (full attribute sync, as-is or transformed)

 

Ongoing directory sync

 

Password sync

 

SID History migration

 

Contact migration

 

NAS File Share ReACL, AD Processing Wizard

 

Customizable workflows

 

*ODM AD Express can create target user and group ojects with a minimal set of attributes to facilitate a successful device ReACL.

AD minimal attributes: objectClass, userPrincipalName, displayName, givenName, sn, userAccountControl, pwdLastSet, DistinguishedName, samAccountName, name, mailNickname, groupType, and member.

Entra ID minimal attributes: objectClass, UserPrincipalName, DisplayName, FirstName, LastName, AccountEnabled, Password, Name, Alias, GroupType, RecipientTypeDetails, RecipientType, and Member.

Subscription plans

Subscription plans ODM

Knowledge Center

A Guide to AD Migrations and Directory Synchronization

Top reasons enterprises are adopting data products

Quest® Toad® AI Insights is a suite of AI-powered capabilities built directly into Toad Solutions.

Read more

On Demand Migration Directory Sync

Attack Tested Identity Recovery

But with On Demand Migration (ODM) Directory Sync, you can ensure productivity across your on-premises, cloud or hybrid environment on Day One of your merger, acquisition or consolidation project.

Read more

FAQ

Performing an AD migration or consolidation with the right AD migration tool can help strengthen your AD security, centralize your domain management, and improve end user experience.  If your company currently maintains separate domains for different departments or regions, you can combine the domains to provide standardized management and security policies, while still maintaining the ability to provide granular access to the consolidated resources. 

Conversely, you might be managing multiple Active Directory domains because of a merger, acquisition, or divestiture.  Configuring integration between the domains can help provide coexistence by syncing passwords and providing cross-domain resource access, but this can result in increased risk and management effort.  If you are maintaining separate domains after a tenant-to-tenant migration, your end users might struggle with managing multiple identities.  You should always make sure Active Directory domain consolidation is part of your tenant-to-tenant migration discussions.

Active Directory is Microsoft’s original on-premises enterprise solution for organizing and managing a company’s resources such as users, groups, and devices.  Active Directory objects are configured within organizational units that belong to a domain, which can itself belong to another domain or forest.  Active Directory is managed by domain controllers, which can physically reside in a company office or data center or can run as virtual machines.  When users need to access resources and applications on Active Directory servers, they must have direct network access or connect to a virtual private network.

Entra ID fully resides in the cloud and removes the need for domain controllers, organizational units, and direct network access to physical servers.  Microsoft maintains the infrastructure for your Entra ID tenant, scaling up as needed to support your company’s tenant activity. Users, groups, devices, and other resources are created and managed in the tenant, and users only need Internet connectivity to access cloud resources. Microsoft Entra ID can also serve as an extension to Active Directory by enabling synchronization between the two environments, allowing users to authenticate to Active Directory for local resources while also having access to the cloud-only resources in Entra ID.

Microsoft 365 and Microsoft Entra ID tenants are complex cloud platforms that include many different components and resources. Microsoft supports tenant-to-tenant migrations for many of its individual workloads; however, you cannot migrate an entire tenant as-is, and there are many configurations and resources that must be directly configured in another tenant. 

When it comes to AD migration, Microsoft supports migrating Entra ID objects such as users, groups, contacts, guests, and Entra ID-joined devices from one tenant to another.  Microsoft also supports tenant-to-tenant migrations for Microsoft 365 content such as mailboxes, OneDrive, Teams, and SharePoint.  You can use an AD migration tool to perform these migrations, enable cross-tenant coexistence, and replicate resource access.   Although there is no direct migration path for Azure applications, virtual servers, and most tenant policies and configurations, the Microsoft community has built a tool for exporting and importing many tenant settings to assist with your tenant migration, and a dedicated AD migration tool can help fill in the gaps.

Body

Ready to take the next step?