ADDS trusted forests.domains A. OnPrem EX2013 B.Office 365 into new ADDS and New 0365 Tenant?

%3CLINGO-SUB%20id%3D%22lingo-sub-1547049%22%20slang%3D%22en-US%22%3EADDS%20trusted%20forests.domains%20A.%20OnPrem%20EX2013%20B.Office%20365%20into%20new%20ADDS%20and%20New%200365%20Tenant%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1547049%22%20slang%3D%22en-US%22%3E%3CP%3EGreetings.%3CBR%20%2F%3EWe%20have%20two%20company's%20(each%20with%20their%20own%20forest%20and%20single%20domain)%20that%20have%20operated%20in%20a%20trusted%20ADDS%20forest%20configuration.%20Each%20forest%20contains%20their%20own%20respective%20mail%20system.%20One%20has%20on-premise%20Exchange%202013.%20The%20other%20ADDS%20forest%20has%20O365%20and%20uses%20Azure%20AD%20Connect%20to%20sync%20on-premise%20ADDS%20users%20to%20o365.%20These%20mail%20systems%20are%20utilizing%20Galsync%20(enow)%20to%20support%20cross%20forest%20GAL's.%3CBR%20%2F%3EWe%20are%20not%20(yet)%20using%20o365%20SharePoint%2C%20one%20drive%2C%20or%20other%200365%20services%20other%20than%20email.%20*We%20will%20later%20in%20the%20new%20named%20entity.%3CBR%20%2F%3EWe%20are%20now%20going%20to%20merge%20these%20two%20environments%20(ADDS%20forest(s)%20%2F%20domain(s))%20into%20a%20new%20named%20ADDS%20entity%20(forest%20and%20domain)%20-%20and%20new%20o365%20tenant.%20This%20new%20named%20entity%20will%20utilize%20many%20of%20the%20o365%20offerings.%3CBR%20%2F%3EI%20have%20migrated%2Fmerged%20trusted%20forests%2C%20and%20Exchange%20on-premise%202010%2F2013%20systems%20together%20via%20ADMT%20and%20mailbox%20moves.%20This%20looks%20to%20be%20a%20bit%20more%20challenging.%3CBR%20%2F%3EHas%20anyone%20performed%20a%20similar%20migration%2Fmerge%3F%20Would%20they%20be%20willing%20to%20share%20how%20they%20did%20it%3F%3CBR%20%2F%3EAny%20insight%2C%20links%2C%20or%20thoughts%20are%20very%20much%20appreciated.%3CBR%20%2F%3EI%20found%20something%20similar%20in%20a%20forum%20on%20reddit%20-%3CA%20href%3D%22https%3A%2F%2Fwww.reddit.com%2Fr%2FOffice365%2Fcomments%2F93f4oq%2Fcross_forest_office_365_migration%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noreferrer%22%3Ehttps%3A%2F%2Fwww.reddit.com%2Fr%2FOffice365%2Fcomments%2F93f4oq%2Fcross_forest_office_365_migration%2F%3C%2FA%3E%3CBR%20%2F%3EThanks%20in%20advance%2C%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1547049%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECross%20forest%20Office%20365%20Migration(s)%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1547244%22%20slang%3D%22en-US%22%3ERe%3A%20ADDS%20trusted%20forests.domains%20A.%20OnPrem%20EX2013%20B.Office%20365%20into%20new%20ADDS%20and%20New%200365%20Tenant%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1547244%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F161769%22%20target%3D%22_blank%22%3E%40Kevin%20Watkins%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3ECouple%20of%20questions%20here%2C%20Are%20you%20planning%20to%20keep%20on-premises%20exchange%20post%20merger%20%3F%20or%20is%20it%20just%20going%20to%20be%20office%20365%20with%20objects%20being%20synchronized%20from%20on-premises%20active%20directory%20with%20AADConnect%20%3F%20are%20there%20plans%20to%20consolidate%20on-premises%20active%20directory%20as%20well%20(%20like%20AD%20user%20migration%20from%20one%20on-premises%20active%20directory%20to%20another)%20%3F%20AADconnect%20does%20support%20synchronizing%20objects%20from%20two%20different%20on-premises%20active%20directories%20via%20single%20AADconnect%20server%20(%20There%20are%20a%20few%20prerequisites%20though).%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1548456%22%20slang%3D%22en-US%22%3ERE%3A%20ADDS%20trusted%20forests.domains%20A.%20OnPrem%20EX2013%20B.Office%20365%20into%20new%20ADDS%20and%20New%200365%20Tenant%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1548456%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F161769%22%20target%3D%22_blank%22%3E%40Kevin%20Watkins%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHere%20is%20an%20article%20which%20explains%20about%20adding%20an%20additional%20directory%20in%20AADConnect%20%3A%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fwww.mustbegeek.com%2Fsetup-azure-ad-connect-to-synchronize-multiple-active-directory-forests%2F%22%20target%3D%22_blank%22%20rel%3D%22nofollow%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fwww.mustbegeek.com%2Fsetup-azure-ad-connect-to-synchronize-multiple-active-directory-forests%2F%3C%2FA%3E%3C%2FP%3E%3CP%3EThere%20are%20other%20links%20in%20the%20article%20talking%20about%20prerequisites%20like%20Trust%20between%20the%20forests%2C%20conditional%20forwarder%20etc.%20You%20can%20achieve%20the%20configuration%20without%20trust%20as%20well%2C%20the%20article%20is%20a%20bit%20old%20(and%20has%20a%20few%20ads%20now%20agggh)%20but%20still%20works%20well.%20Will%20drop%20response%20to%20your%20other%20query%20in%20some%20time%20a%20bit%20occupied%20right%20now.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1548276%22%20slang%3D%22en-US%22%3ERE%3A%20ADDS%20trusted%20forests.domains%20A.%20OnPrem%20EX2013%20B.Office%20365%20into%20new%20ADDS%20and%20New%200365%20Tenant%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1548276%22%20slang%3D%22en-US%22%3EHowdy%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F67895%22%20target%3D%22_blank%22%3E%3C%2FA%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F67895%22%20target%3D%22_blank%22%3E%3C%2FA%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F67895%22%20target%3D%22_blank%22%3E%40harveer%20singh%3C%2FA%3E%20Thank%20you%20for%20the%20response.%20To%20answer%20your%20questions%3A%201)%20We%20do%20NOT%20plan%20to%20keep%20any%20on-premise%20exchange%20post%20merger.%202)%20It%20will%20be%20office%20365%20with%20objects%20being%20synchronized%20from%20on-premises%20active%20directory%20with%20AADConnect.%203)%20YES%20-%20The%20plan%20is%20to%20consolidate%20on-premises%20(both%20forests)%20active%20directory%20as%20well%20(%20like%20AD%20user%20migration%20from%20one%20on-premises%20active%20directory%20to%20another)%20Would%20you%20please%20tell%20me%20more%20re%3A%20AADconnect%20does%20support%20synchronizing%20objects%20from%20two%20different%20on-premises%20active%20directories%20via%20single%20AADconnect%20server%20(%20There%20are%20a%20few%20prerequisites%20though).%20Thanks%20again%20for%20your%20help%20%3A)%3C%2Fimg%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1554823%22%20slang%3D%22en-US%22%3ERE%3A%20ADDS%20trusted%20forests.domains%20A.%20OnPrem%20EX2013%20B.Office%20365%20into%20new%20ADDS%20and%20New%200365%20Tenant%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1554823%22%20slang%3D%22en-US%22%3E%3CP%3EAppreciate%20your%20help%20very%20much%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F67895%22%20target%3D%22_blank%22%3E%40harveer%20singh%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1557411%22%20slang%3D%22en-US%22%3ERE%3A%20ADDS%20trusted%20forests.domains%20A.%20OnPrem%20EX2013%20B.Office%20365%20into%20new%20ADDS%20and%20New%200365%20Tenant%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1557411%22%20slang%3D%22en-US%22%3E%3CP%3EHey%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F161769%22%20target%3D%22_blank%22%3E%40Kevin%20Watkins%3C%2FA%3E%26nbsp%3B%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ESorry%20to%20keep%20you%20waiting%2C%20a%20few%20more%20question%20for%20you%2C%20are%20you%20planning%20to%20migrate%20both%20the%20ADs%20(%20one%20with%20exchange%202013%20and%20the%20other%20with%20Dirsync)%20to%20a%20new%20forest%20all%20together%2C%20or%20are%20you%20simply%20merging%20the%20two%20forests%20%3F%20Going%20with%20merge%20would%20certainly%20remove%20quite%20some%20complexity%20and%20would%20make%20the%20plan%20a%20bit%20simpler.%26nbsp%3B%20Also%20is%20it%20a%20compliance%20requirement%20to%20move%20away%20from%20the%20office%20365%20tenant%20you%20already%20have%3F%20If%20you%20can%20stick%20to%20the%20same%20tenant%20and%20simply%20add%20the%20new%20domain%20in%20the%20same%20tenant%20%2C%20it%20would%20again%20ease%20your%20work%20and%20you%20wont%20have%20to%20perform%20a%20tenant%20to%20tenant%20mailbox%20migration%20(%20I%20am%20assuming%20you%20have%20mailboxes%20in%20office%20365%20for%20the%20other%20forest).%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1559980%22%20slang%3D%22en-US%22%3ERE%3A%20ADDS%20trusted%20forests.domains%20A.%20OnPrem%20EX2013%20B.Office%20365%20into%20new%20ADDS%20and%20New%200365%20Tenant%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1559980%22%20slang%3D%22en-US%22%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHello%20%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F67895%22%20target%3D%22_blank%22%3E%40harveer%20singh%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20don't%20believe%20we%20could%20rename%20the%20existing%20tenant%20-%20correct%3F%3C%2FP%3E%3CP%3EWe%20will%20migrate%20both%20into%20a%20new%20forest%20-%20yes.%26nbsp%3B%20It%20will%20be%20a%20new%20company%20name.%26nbsp%3B%20We%20need%20a%20new%20tenant%20name%20to%20follow%20the%20name%20for%20the%20new%20company.%26nbsp%3B%3C%2FP%3E%3CP%3Ecompanya.local%3C%2FP%3E%3CP%3Ecompanyb.local%3C%2FP%3E%3CP%3Einto%20mynewcompany.org%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1560932%22%20slang%3D%22en-US%22%3ERE%3A%20ADDS%20trusted%20forests.domains%20A.%20OnPrem%20EX2013%20B.Office%20365%20into%20new%20ADDS%20and%20New%200365%20Tenant%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1560932%22%20slang%3D%22en-US%22%3EYup%2C%20a%20tenant%20can't%20be%20renamed%20as%20of%20now.%20Okay%2C%20there%20a%20few%20ways%20to%20achieve%20the%20target%20state%2C%20In%20my%20opinion%20the%20simplest%20one%20would%20be%20using%20a%20third%20party%20migration%20tool%20like%20Bittitan%20etc.%20Lets%20say%20your%20forest%20setup%20is%20A-F-B%20where%20A%20is%20forest%20with%20exchange%202013%2C%20B%20is%20forest%20with%20office%20355%20and%20F%20is%20the%20final%20forest.%20The%20high%20level%20approach%20incase%20of%20'third%20party'%20migration%20tool%20would%20be%3A%3CBR%20%2F%3E1.%20Install%20Aadconnect%20in%20forest%20F%20with%20new%20tenant.%20FILTER%20OUT%20masexchmailboxguid%20from%20synchronization.%20Add%20the%20new%20domain%20in%20new%20tenant.%3CBR%20%2F%3E2.%20Migrate(copy)%20users%20on-premises%20from%20Forest%20A%20and%20B%20to%20new%20forest%20F%20using%20ADMT%2Fother%2C%20preserve%20the%20object%20guid%20but%20project%20the%20users%20with%20new%20upn%20user1%40newdomain.com%20in%20the%20target%20forest%20F.%3CBR%20%2F%3E3.%20Now%20once%20you%20have%20users%20in%20Forest%20F%2C%20sync%20them%20to%20office%20365%20without%20mailbox%20guid%2C%20next%20when%20you%20assign%20a%20license%20in%20office%20365%2C%20mailbox%20would%20be%20provisioned%20and%20office%20365%20mailboxes%20will%20be%20ready%20for%20data%20to%20be%20imported.%3CBR%20%2F%3E4.%20Now%20use%20third%20party%20tool%20to%20pull%20data%20directly%20into%20mailboxes%20from%20exchange%20and%20office%20365%20forest.%20Using%20a%20third%20party%20tool%20would%20allow%20you%20to%20do%20an%20incremental%20migration%20as%20well%2C%20so%20the%20users%20in%20exchange%20and%20old%20office%20365%20remain%20in%20production%20to%20the%20very%20last%20day%2C%20incase%20the%20migration%20runs%20for%20a%20few%20weeks.%20Lastly%20you%20will%20have%20to%20remove%20the%20old%20domain%20from%20old%20tenant%20and%20add%20it%20into%20the%20new%20tenant.%3CBR%20%2F%3EAs%20i%20said%20this%20is%20one%20of%20the%20methods%20to%20achieve%20this%2C%20I%20suggest%20using%20a%20third%20party%20tool%20as%20one%20of%20your%20sources%20is%20office%20365%20and%20for%20migrating%20out%20of%20office%20365%20thirdy%20party%20tools%20serve%20better.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20you%20want%20to%20take%20the%20hybrid%20route%20there%20is%20added%20complexity%2C%20approach%20from%20forest%20B%20with%20office%20365%20remains%20the%20same%20as%20above%2C%20things%20would%20change%20for%20exchange%20forest%20though%2C%20high%20level%20overview%3A%3CBR%20%2F%3EInstall%20Aadconnect%20in%20forest%20F%2C%20add%20forest%20A%20as%20remote%20directory(article%20previously%20shared)%2C%20once%20users%20are%20synced%2C%20setup%20hybrid%2C%20move%20all%20mailboxes%20to%20office%20365%2C%20decom%20exchange%20on-premises%2C%20move%20users%20from%20forest%20A%20to%20destination%20forest%20deleting%20source%2C%20so%20that%20Aadconnect%20sees%20only%20one%20instance%20of%20user%20object.%20Please%20note%20that%20with%20this%20approach%20you%20will%20also%20have%20to%20manage%20mailbox%20guids%20for%20two%20forests%20seperately%2C%20as%20exchangemailbox%20guid%20must%20be%20synced%20to%20office%20365%20for%20hybrid%20migration%2C%20but%20for%20office%20365%20to%20office%20365%20migration%20you%20don't%20want%20to%20sync%20mailbox%20guid%20from%20on-premises.%3CBR%20%2F%3EThis%20is%20just%20a%20high%20level%20overview%20to%20get%20you%20started%2C%20a%20lot%20more%20can%20go%20into%20this%20discussion%20to%20fill%20out%20any%20gaps.%3C%2FLINGO-BODY%3E
Occasional Contributor

Greetings.
We have two company's (each with their own forest and single domain) that have operated in a trusted ADDS forest configuration. Each forest contains their own respective mail system. One has on-premise Exchange 2013. The other ADDS forest has O365 and uses Azure AD Connect to sync on-premise ADDS users to o365. These mail systems are utilizing Galsync (enow) to support cross forest GAL's.
We are not (yet) using o365 SharePoint, one drive, or other 0365 services other than email. *We will later in the new named entity.
We are now going to merge these two environments (ADDS forest(s) / domain(s)) into a new named ADDS entity (forest and domain) - and new o365 tenant. This new named entity will utilize many of the o365 offerings.
I have migrated/merged trusted forests, and Exchange on-premise 2010/2013 systems together via ADMT and mailbox moves. This looks to be a bit more challenging.
Has anyone performed a similar migration/merge? Would they be willing to share how they did it?
Any insight, links, or thoughts are very much appreciated.
I found something similar in a forum on reddit -https://www.reddit.com/r/Office365/comments/93f4oq/cross_forest_office_365_migration/
Thanks in advance,

7 Replies

Hey @Kevin Watkins ,

Couple of questions here, Are you planning to keep on-premises exchange post merger ? or is it just going to be office 365 with objects being synchronized from on-premises active directory with AADConnect ? are there plans to consolidate on-premises active directory as well ( like AD user migration from one on-premises active directory to another) ? AADconnect does support synchronizing objects from two different on-premises active directories via single AADconnect server ( There are a few prerequisites though). 

Howdy @harveer singh Thank you for the response. To answer your questions: 1) We do NOT plan to keep any on-premise exchange post merger. 2) It will be office 365 with objects being synchronized from on-premises active directory with AADConnect. 3) YES - The plan is to consolidate on-premises (both forests) active directory as well ( like AD user migration from one on-premises active directory to another) Would you please tell me more re: AADconnect does support synchronizing objects from two different on-premises active directories via single AADconnect server ( There are a few prerequisites though). Thanks again for your help :)

Hey @Kevin Watkins ,

 

Here is an article which explains about adding an additional directory in AADConnect : https://www.mustbegeek.com/setup-azure-ad-connect-to-synchronize-multiple-active-directory-forests/

There are other links in the article talking about prerequisites like Trust between the forests, conditional forwarder etc. You can achieve the configuration without trust as well, the article is a bit old (and has a few ads now agggh) but still works well. Will drop response to your other query in some time a bit occupied right now.

 

Thanks

Hey @Kevin Watkins ,

 

Sorry to keep you waiting, a few more question for you, are you planning to migrate both the ADs ( one with exchange 2013 and the other with Dirsync) to a new forest all together, or are you simply merging the two forests ? Going with merge would certainly remove quite some complexity and would make the plan a bit simpler.  Also is it a compliance requirement to move away from the office 365 tenant you already have? If you can stick to the same tenant and simply add the new domain in the same tenant , it would again ease your work and you wont have to perform a tenant to tenant mailbox migration ( I am assuming you have mailboxes in office 365 for the other forest). 

 

Hello @harveer singh 

I don't believe we could rename the existing tenant - correct?

We will migrate both into a new forest - yes.  It will be a new company name.  We need a new tenant name to follow the name for the new company. 

companya.local

companyb.local

into mynewcompany.org

 

 

 

Yup, a tenant can't be renamed as of now. Okay, there a few ways to achieve the target state, In my opinion the simplest one would be using a third party migration tool like Bittitan etc. Lets say your forest setup is A-F-B where A is forest with exchange 2013, B is forest with office 355 and F is the final forest. The high level approach incase of 'third party' migration tool would be:
1. Install Aadconnect in forest F with new tenant. FILTER OUT masexchmailboxguid from synchronization. Add the new domain in new tenant.
2. Migrate(copy) users on-premises from Forest A and B to new forest F using ADMT/other, preserve the object guid but project the users with new upn user1@newdomain.com in the target forest F.
3. Now once you have users in Forest F, sync them to office 365 without mailbox guid, next when you assign a license in office 365, mailbox would be provisioned and office 365 mailboxes will be ready for data to be imported.
4. Now use third party tool to pull data directly into mailboxes from exchange and office 365 forest. Using a third party tool would allow you to do an incremental migration as well, so the users in exchange and old office 365 remain in production to the very last day, incase the migration runs for a few weeks. Lastly you will have to remove the old domain from old tenant and add it into the new tenant.
As i said this is one of the methods to achieve this, I suggest using a third party tool as one of your sources is office 365 and for migrating out of office 365 thirdy party tools serve better.

If you want to take the hybrid route there is added complexity, approach from forest B with office 365 remains the same as above, things would change for exchange forest though, high level overview:
Install Aadconnect in forest F, add forest A as remote directory(article previously shared), once users are synced, setup hybrid, move all mailboxes to office 365, decom exchange on-premises, move users from forest A to destination forest deleting source, so that Aadconnect sees only one instance of user object. Please note that with this approach you will also have to manage mailbox guids for two forests seperately, as exchangemailbox guid must be synced to office 365 for hybrid migration, but for office 365 to office 365 migration you don't want to sync mailbox guid from on-premises.
This is just a high level overview to get you started, a lot more can go into this discussion to fill out any gaps.