See the following articles for information on migrating users from Active Directory (AD):
- Export Users from Active Directory
- Import Users into ºÚÁϺ£½Ç91Èë¿Ú from CSV
- Convert Windows System Active Directory Domain Accounts to Local User Accounts
- ºÚÁϺ£½Ç91Èë¿Ú Agent Support for Active Directory Joined Windows Devices
Migrating Windows Devices from AD to ºÚÁϺ£½Ç91Èë¿Ú
You can migrate your Active Directory (AD) OnPrem Windows devices to your ºÚÁϺ£½Ç91Èë¿Ú org while keeping them protected and secure. From a high level, to do so:
- Create the policies you need for your devices in ºÚÁϺ£½Ç91Èë¿Ú.
- Bind the ºÚÁϺ£½Ç91Èë¿Ú policies to all of the AD On Prem Windows devices in scope.
You may receive error messages regarding the following policies:
- Rename Local Administrator Account
- Enable/Disable Local Administrator Account
- Rename Local Guest Account
- Enable/Disable Local Guest Account
This is expected behavior, because the device is still bound to Active Directory at this time.
- Unbind the devices from Active Directory.
Migrating Mac Devices from AD to ºÚÁϺ£½Ç91Èë¿Ú
The ºÚÁϺ£½Ç91Èë¿Ú ADMU doesn't support Mac devices, but you can follow these steps to manually migrate devices from AD to ºÚÁϺ£½Ç91Èë¿Ú:
- On the macOS device, open System Settings.
- Go to Users & Groups.
- Go to Network account server and click Edit...
- Select Open Directory Utility.
- In the bottom left of the Directory Utility app, click the lock icon and enter the administrator password.
- Select the Active Directory entry that corresponds to the domain that the Mac is joined to.
- At the bottom left, click the minus (-) to remove the Mac from AD.
- Enter the administrator password to confirm the removal.
- Once the Mac has been removed from AD, close the Directory Utility app and System Settings.
After removing the device from AD, you'll need to convert any mobile user accounts to local user accounts to avoid password sync issues. You can use the following tool: .
- Alternatively, you can use the following script to perform both actions automatically - remove the device from AD and convert the user from a mobile to local account: .
- Note that ºÚÁϺ£½Ç91Èë¿Ú does not maintain or support these third-party tools.