Background
Following the merger of two regional healthcare organizations, the new combined entity inherited three separate Active Directory forests spanning 12,000 user accounts, 1,400 workstations, and six physical sites. Each forest had its own DNS structure, Group Policy framework, and application landscape.
The IT leadership needed a path to a single, unified AD environment — without disrupting clinical systems or patient-facing services.
The Challenge
Scale: 12,000 user accounts, 1,400 computers, 600+ group policy objects across three forests.
Dependencies: Clinical applications tightly bound to specific domain structures, including patient record systems, radiology workstations, and nurse-calling systems.
Timeline: Leadership required a 14-month completion timeline to align with an office consolidation project.
Availability requirements: Clinical systems must maintain 24/7 availability. Weekend downtime windows were limited to 4 hours maximum.
Our Approach
Phase 1: Environment Assessment (Weeks 1–6)
Conducted a full inventory of all three AD environments using a combination of PowerShell scripts and ADRecon. Key findings:
- 47 service accounts with hardcoded domain credentials in application configurations
- 12 GPOs with conflicting settings between domains
- 3 legacy applications that required NTLM and could not be migrated to Kerberos
All dependencies were documented in a migration matrix before a single account was moved.
Phase 2: Target Environment Design (Weeks 7–10)
Designed the target AD forest with input from the IT team and application vendors:
- New functional level: Windows Server 2019
- New OU structure aligned with the merged organization’s HR structure
- Trust relationships established between all three source forests and the target
- DNS conditional forwarders deployed across all sites
Phase 3: Pilot Migration (Weeks 11–14)
Migrated 80 non-clinical IT staff accounts across all three source domains. Validated:
- Domain login on all workstation types
- Access to file shares via SID history
- Email delivery (Exchange hybrid configuration)
- All 47 service accounts reconfigured in test environment
Phase 4: Wave Migrations (Weeks 15–48)
Migrated users in 22 department-level waves, scheduled to avoid clinical peaks:
| Wave | Department | Accounts | Result |
|---|---|---|---|
| 1–3 | IT & Admin | 480 | No issues |
| 4–8 | Finance & HR | 1,200 | 2 minor GPO issues resolved |
| 9–15 | Clinical support | 4,800 | Successful with 30-min extended support coverage |
| 16–22 | Clinical frontline | 5,520 | Successful; 1 legacy app required special handling |
Results
- 12,000 accounts migrated across 22 waves over 14 months
- Zero clinical incidents attributable to the migration
- 4-hour maximum downtime per wave achieved in all cases
- Three forests retired on schedule
- Security posture improved via new GPO baseline and privileged access model
Key Takeaways
- Service account inventory is the most underestimated task — always do it first, always.
- Trust + SID history = zero access disruption when set up correctly before the first wave.
- Clinical IT requires dedicated support coverage during migration windows — not just general helpdesk.
- A wave-based approach compounds learning — later waves are faster and smoother than early ones.
Interested in a structured approach to your AD migration? Get in touch.