Problem solve Get help with specific problems with your technologies, process and projects.

Synchronizing two AD domains

We recently acquired a company and are in the process of testing our network setup. Our forest master and Exchange are on Domain A. Domain B is trying to access e-mail in Domain A. So there is a user account on Domain B and a user account with an Exchange mail store on Domain A. Right now, they are set up as a tree in our forest. I want to see if it is possible to synchronize Domain A's Active Directory with Domain B's Active Directory, so we don't have to change passwords in two domains. How do we accomplish this?
If Domain A trusts Domain B, you should just be able to give all the Domain B accounts rights to access the Domain A mailboxes. That way, you don't need to worry about the passwords for Domain A accounts. In other words, the only accounts you'd need to manage for the time being are Domain B accounts. To set this up:

  1. Launch Active Directory Users and Computers (ADUC) on a machine with Exchange System Manager installed and connected to Domain _.

  2. View the properties of each mailbox and switch to the Exchange Advanced tab. (If you don't see this tab in ADUC, see KB article 326894, How to Access the Exchange Advanced Tab in Active Directory Users and Computers).

  3. Now select Mailbox Rights.

  4. Make sure the Domain B account is added to the list of security principals having access (typically only "self") in order to facilitate the two-domain coexistence scenario.

Essentially, you're asking how to simplify management of your users' identities across multiple accounts and passwords. Various solutions exist focused on identity management. Microsoft has a solution called Microsoft Identity Integration Server (MIIS) that permits exactly what you're asking, namely synchronization of passwords across multiple domains as you described.

More importantly, in your case, I believe you can use a free scaled down version of MIIS called the Identity Integration Feature Pack 1a for Microsoft Windows Server Active Directory, which can synchronize passwords across Active Directory, ADAM and Exchange Server environments. You'll also want to install the update.

If you want a more sophisticated solution that will do all this plus assist once you start migrating users from Domain B into Domain A, I suggest looking at third-party migration solutions.

Do you have comments on this Ask the Expert Q&A? Let us know.

Dig Deeper on Exchange Server setup and troubleshooting