Move a Windows-linked user group to a different domain

Windows
-linked user group accounts, and the user accounts they contain, can move from one domain to another while keeping security permissions for the group accounts intact. Delete individual
Windows
-linked user accounts and recreate the accounts in the new domain. This causes all security permissions for the user accounts to be lost.
TIP:
Moving
Windows
-linked user group accounts to a new domain in one directory does not move them in the other. To move the accounts in both directories, move them in one directory then log off that directory. Log on to the other director, and then move them in the second directory.
Prerequisites
Obtain these permissions in the
User Groups
folder in
FactoryTalk Administration Console
Explorer
:
  • Common > List Children
  • Common > Read
  • Common > Write
To move a
Windows
-linked user group to a different domain
  1. In the new
    Windows
    domain, create a user group with the same name as the one currently linked in the
    FactoryTalk
    system. For details, see
    Windows
    Help.
  2. In
    FactoryTalk Administration Console
    Explorer
    , expand
    System
    >
    User Groups
    , right-click
    the
    Windows
    -linked user group, and select
    Properties
    .
  3. In
    General User Group Properties
    , select
    Change Domain
    .
  4. In
    Select
    Windows
    Domain
    , select the target domain for the
    Windows
    -linked user group, select
    OK
    .
    The new domain must already contain a user group with the same name as the user group in the old domain, otherwise cannot move the group.
  5. In
    User Group Properties
    , select
    OK
    .
Provide Feedback
Have questions or feedback about this documentation? Please submit your feedback here.
Normal