<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Migrating to a new Active Directory, testing it out in Managing Users</title>
    <link>https://community.cisco.com/t5/managing-users/migrating-to-a-new-active-directory-testing-it-out/m-p/4879188#M474</link>
    <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Yes, you can set up an additional AD sync to &lt;A href="http://new.com"&gt;new.com&lt;/A&gt; domain that coexists with the &lt;A href="http://old.com"&gt;old.com&lt;/A&gt; sync.&lt;/P&gt;
&lt;P&gt;The only catch is that the &lt;A href="http://new.com"&gt;new.com&lt;/A&gt; sync can’t manage any users or groups that would cause a naming conflict with &lt;A href="http://old.com"&gt;old.com&lt;/A&gt; users or groups.&lt;/P&gt;
&lt;P&gt;So, if you test with a new and unique &lt;A href="http://new.com"&gt;new.com&lt;/A&gt; user and group, that doesn’t also exist in &lt;A href="http://old.com"&gt;old.com&lt;/A&gt;, you should be fine.&lt;/P&gt;&lt;/DIV&gt;</description>
    <pubDate>Thu, 06 Jul 2023 22:11:17 GMT</pubDate>
    <dc:creator>DuoKristina</dc:creator>
    <dc:date>2023-07-06T22:11:17Z</dc:date>
    <item>
      <title>Migrating to a new Active Directory, testing it out</title>
      <link>https://community.cisco.com/t5/managing-users/migrating-to-a-new-active-directory-testing-it-out/m-p/4879187#M473</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Hello all,&lt;/P&gt;
&lt;P&gt;We are moving to a new AD that our parent company has, &lt;A href="http://new.com" rel="noopener nofollow ugc"&gt;new.com&lt;/A&gt;.&lt;/P&gt;
&lt;P&gt;We currently use directory sync with &lt;A href="http://old.com" rel="noopener nofollow ugc"&gt;old.com&lt;/A&gt;. I understand that we have to remove old com and ensure that we have the same variables in new com so that new com AD will take over management.&lt;/P&gt;
&lt;P&gt;What I’m not clear on is if we can test side by side? Ideally I would like to setup a user that doesn’t exist on old com in new com and sync only that user. Have old com as a suffix on new com. Then test out our existing applications. We intend to keep &lt;A href="http://old.com" rel="noopener nofollow ugc"&gt;old.com&lt;/A&gt; as the main mail attribute for users on the new com domain. We currently use the mail attribute so we would just set that to testuser@old com.&lt;/P&gt;
&lt;P&gt;Does that logic make sense? We aren’t so worries about the AD migration so much as we are worried about losing the ability to pass old com to 100+ applications for SSO/2FA.&lt;/P&gt;
&lt;P&gt;Maybe I’m wrong on all this, would love some input. Thank you!&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Mon, 26 Jun 2023 13:17:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/migrating-to-a-new-active-directory-testing-it-out/m-p/4879187#M473</guid>
      <dc:creator>pedrotor</dc:creator>
      <dc:date>2023-06-26T13:17:48Z</dc:date>
    </item>
    <item>
      <title>Re: Migrating to a new Active Directory, testing it out</title>
      <link>https://community.cisco.com/t5/managing-users/migrating-to-a-new-active-directory-testing-it-out/m-p/4879188#M474</link>
      <description>&lt;DIV class="duo-migrated-content"&gt;&lt;P&gt;Yes, you can set up an additional AD sync to &lt;A href="http://new.com"&gt;new.com&lt;/A&gt; domain that coexists with the &lt;A href="http://old.com"&gt;old.com&lt;/A&gt; sync.&lt;/P&gt;
&lt;P&gt;The only catch is that the &lt;A href="http://new.com"&gt;new.com&lt;/A&gt; sync can’t manage any users or groups that would cause a naming conflict with &lt;A href="http://old.com"&gt;old.com&lt;/A&gt; users or groups.&lt;/P&gt;
&lt;P&gt;So, if you test with a new and unique &lt;A href="http://new.com"&gt;new.com&lt;/A&gt; user and group, that doesn’t also exist in &lt;A href="http://old.com"&gt;old.com&lt;/A&gt;, you should be fine.&lt;/P&gt;&lt;/DIV&gt;</description>
      <pubDate>Thu, 06 Jul 2023 22:11:17 GMT</pubDate>
      <guid>https://community.cisco.com/t5/managing-users/migrating-to-a-new-active-directory-testing-it-out/m-p/4879188#M474</guid>
      <dc:creator>DuoKristina</dc:creator>
      <dc:date>2023-07-06T22:11:17Z</dc:date>
    </item>
  </channel>
</rss>

