Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

To move users from a child domain into its parent domain, use the Active Directory Migration Tool (ADMT) 3.2 User Account Migration Wizard, then validate logon and resource access before disabling the source accounts. The move changes each user’s SID; if existing resources still grant access to the old SID, plan and configure sIDHistory before migrating. ADMT 3.2 supports migrations within the same forest, but Microsoft describes its support on modern Windows versions as limited, so pilot the exact versions and security settings in your environment.

What changes when a user moves to the parent domain?

In this procedure, the child domain is the source and the parent domain is the target. This is an intra-forest domain restructuring: ADMT 3.2 can migrate users, groups, and computers between domains in the same forest as well as between forests.

The migrated account belongs to the parent domain and has a target-domain SID. Resources whose access control lists (ACLs) refer to the user’s former child-domain SID may no longer recognize that identity. If access to those resources must continue without immediately rewriting their ACLs, include sIDHistory in the migration design and meet its prerequisites. Do not assume that moving the account alone preserves access.

Prepare the domains and migration plan

Inventory accounts and dependencies

Freeze the migration scope and export a baseline before making changes. Include each user’s enabled state, UPN, sAMAccountName, group memberships, proxy addresses, manager, and department. Identify service dependencies, profile locations, delegated rights, applications, scheduled tasks, certificates, and cloud synchronization dependencies. Record which file, print, application, and other resource ACLs still contain child-domain SIDs.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
#1 Best Overall
Microsoft Windows Server 2025 Standard Edition 64-bit, Base License, 16 Core - OEM
  • 64 bit | 1 Server with 16 or less processor cores | provides 2 VMs
  • For physical or minimally virtualized environments
  • Requires Windows Server 2025 User and/or Device Client Access Licenses (CALs) | No CALs are included
  • Core-based licensing | Additional license packs required for servers with more than 16 processor cores or to add VMs | 2 VMs whenever all processor cores are licensed.
  • Product ships in plain envelope | Activation key is located under scratch-off area on label |Beware of counterfeits | Genuine Windows Server software is branded by Microsoft only.

Choose a small pilot that represents the real workload. Include ordinary users as well as privileged users, service accounts, users with large group memberships, and users whose access depends on old SIDs.

Check versions, naming, and connectivity

  • Record the source and target domain names, DNS zones, NetBIOS names, domain controllers, functional levels, and the Windows versions that will host ADMT and Password Export Server (PES).
  • Verify hostname and NetBIOS name resolution between the domains from the planned ADMT host. Resolve failures before starting a migration.
  • Confirm the trust configuration required for your topology and security policy. An existing forest relationship does not by itself confirm that every ADMT wizard dependency is met.

Delegate accounts and permissions

Have source-domain credentials with the rights needed to read and migrate the users. Delegate target-domain credentials to create objects in the destination container. If you plan to migrate sIDHistory, the migration credentials also need the target-domain MigratesIDHistory extended right or equivalent administrator rights.

Rank #2
Windows Server 2025 User CAL 5 pack
  • Offers quick and easy installation on PC
  • The software is licensed for 5 User CAL

Decide whether to migrate sIDHistory

Make this decision based on the ACL inventory and the organization’s security policy. When sIDHistory is required, prepare success and failure auditing in both domains. Microsoft’s documented prerequisites include an empty source-domain group named {SourceNetBIOSDom}$$$ and the HKLMSystemCurrentControlSetControlLSATcpipClientSupport registry value set to 1 on the source domain’s primary domain controller (PDC). Restart that controller after changing the value.

Validate the prerequisites and permissions before running the wizard. Treat sIDHistory as a controlled security decision, not as an automatic way to make every access problem disappear.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Plan password handling and recovery

If users need their existing passwords, plan PES deployment and encryption-key handling, including a secure method to transfer the key. Test the key and password migration with a pilot account. When ADMT and PES migrate a user’s password, the account is configured to require a password change at the next logon by design; tell pilot users and the help desk to expect that prompt.

Back up the ADMT server before making changes, as Microsoft recommends. Define rollback and acceptance criteria before the first batch, and retain the source-account state, target-object identifiers, and migration logs.

Rank #4
Microsoft Windows Server 2025 Standard Edition 64-bit, Base License, 24 Core - OEM
  • 64 bit | 1 Server with 24 or less processor cores | provides 2 VMs
  • For physical or minimally virtualized environments
  • Requires Windows Server 2025 User and/or Device Client Access Licenses (CALs) | No CALs are included
  • Core-based licensing | Additional license packs required for servers with more than 16 processor cores or to add VMs | 2 VMs whenever all processor cores are licensed.
  • Product ships in plain envelope | Activation key is located under scratch-off area on label |Beware of counterfeits | Genuine Windows Server software is branded by Microsoft only.

Run the migration in controlled batches

  1. Validate the path. From the planned ADMT host, test DNS and NetBIOS name resolution and confirm that the source and target credentials work. Correct name-resolution or permission errors before proceeding.
  2. Install and consult ADMT documentation. Use ADMT 3.2 and Microsoft’s migration guide as the procedural reference. The guide is versioned June 2014 and was listed on Microsoft’s download page on July 15, 2024; check that its steps fit the Windows versions and security configuration you will use.
  3. Configure trust and sIDHistory prerequisites. Complete the trust, auditing, source-group, PDC registry, restart, and target-permission steps that apply to your approved design before launching the wizard.
  4. Configure PES only if needed. If password continuity is part of the plan, set up PES and test the encryption key and first pilot account before migrating a production batch.
  5. Run the User Account Migration Wizard for the pilot OU. Select the attribute, password, and sIDHistory options approved for the migration. Save the ADMT logs and reports, and record exceptions rather than silently skipping failed objects.
  6. Review the pilot before expanding. Check the acceptance items below, investigate failures, and rerun only the affected objects after correcting the underlying cause.
  7. Expand gradually. Migrate users in controlled batches. Keep source accounts available but controlled until the relevant business owners accept the results.

Validate user access and account behavior

Compare a post-migration export with the baseline and use a written acceptance checklist for each pilot or batch:

  • Can the user sign in to the parent domain, and does the password behave as expected?
  • Are the UPN, group memberships, and required account attributes correct?
  • Where sIDHistory was approved, is it present as intended?
  • Can the user reach representative files, printers, applications, mapped drives, and other resources?
  • Do profile behavior, scripts, scheduled tasks, certificates, endpoint management, and synchronization work as expected?

Use the results to resolve migration-specific exceptions before moving on to a larger batch. Retain the reports and logs with the change record.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Windows Server 2025 User CAL
  • Unlock all the features by installing this product on PC
  • The software is licensed for 1 User CAL
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Know the ADMT 3.2 limitations before production use

Microsoft’s support article, updated February 12, 2026, describes ADMT as a tool released for Windows 2000 and Windows Server 2003-era systems that has not been updated for Windows 10, Windows 11, Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, or Windows Server 2022. Microsoft characterizes support as limited and warns that behavior depends on the Windows versions involved. Its documented issues include:

  • Delegation: Unconstrained delegation on domain controllers is not a recommended design. In the documented scenario, running ADMT applications on the target domain controller removes the need for delegation.
  • LSA protection: Password migration fails when LSA protection is enabled. Do not change this security setting without security-team review, a backup, and a tested rollback plan.
  • Security Translation and modern applications: Security Translation can prevent modern applications from starting. Microsoft notes that uninstalling and reinstalling Store applications may be required.
  • Local profiles: ADMT 3.2 Security Translation does not migrate local profiles; Microsoft documents this as by design.
  • Objects with child objects: A parent object can fail to migrate with error 7422 when it has child objects. Microsoft says the blocking child object must be deleted before migrating the parent.
  • TLS: Some ADMT paths may require TLS 1.0 to be enabled temporarily. Consult the security team before changing TLS settings.

Because behavior varies with the source and target Windows versions, test on the exact versions, configurations, and security controls planned for production. Microsoft’s guidance does not establish a universal success rate or performance expectation.

Close out only after acceptance

After business owners confirm the acceptance checks, disable source accounts according to the change plan and verify that resource access remains correct. Do not delete source accounts or remove sIDHistory until required resources and applications have been confirmed to work with the target identity. Schedule any sIDHistory cleanup as a separate, tested security project.

Quick Recap

Bestseller No. 1
Microsoft Windows Server 2025 Standard Edition 64-bit, Base License, 16 Core - OEM
Microsoft Windows Server 2025 Standard Edition 64-bit, Base License, 16 Core - OEM
64 bit | 1 Server with 16 or less processor cores | provides 2 VMs; For physical or minimally virtualized environments
$949.99
Bestseller No. 2
Windows Server 2025 User CAL 5 pack
Windows Server 2025 User CAL 5 pack
Offers quick and easy installation on PC; The software is licensed for 5 User CAL
$252.99
SaleBestseller No. 3
Bestseller No. 4
Microsoft Windows Server 2025 Standard Edition 64-bit, Base License, 24 Core - OEM
Microsoft Windows Server 2025 Standard Edition 64-bit, Base License, 24 Core - OEM
64 bit | 1 Server with 24 or less processor cores | provides 2 VMs; For physical or minimally virtualized environments
$1,499.99
Bestseller No. 5
Windows Server 2025 User CAL
Windows Server 2025 User CAL
Unlock all the features by installing this product on PC; The software is licensed for 1 User CAL
$69.99

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.