Background

Following the merger of two regional healthcare organizations, the new combined entity inherited three separate Active Directory forests spanning 12,000 user accounts, 1,400 workstations, and six physical sites. Each forest had its own DNS structure, Group Policy framework, and application landscape.

The IT leadership needed a path to a single, unified AD environment — without disrupting clinical systems or patient-facing services.


The Challenge

Scale: 12,000 user accounts, 1,400 computers, 600+ group policy objects across three forests.

Dependencies: Clinical applications tightly bound to specific domain structures, including patient record systems, radiology workstations, and nurse-calling systems.

Timeline: Leadership required a 14-month completion timeline to align with an office consolidation project.

Availability requirements: Clinical systems must maintain 24/7 availability. Weekend downtime windows were limited to 4 hours maximum.


Our Approach

Phase 1: Environment Assessment (Weeks 1–6)

Conducted a full inventory of all three AD environments using a combination of PowerShell scripts and ADRecon. Key findings:

  • 47 service accounts with hardcoded domain credentials in application configurations
  • 12 GPOs with conflicting settings between domains
  • 3 legacy applications that required NTLM and could not be migrated to Kerberos

All dependencies were documented in a migration matrix before a single account was moved.

Phase 2: Target Environment Design (Weeks 7–10)

Designed the target AD forest with input from the IT team and application vendors:

  • New functional level: Windows Server 2019
  • New OU structure aligned with the merged organization’s HR structure
  • Trust relationships established between all three source forests and the target
  • DNS conditional forwarders deployed across all sites

Phase 3: Pilot Migration (Weeks 11–14)

Migrated 80 non-clinical IT staff accounts across all three source domains. Validated:

  • Domain login on all workstation types
  • Access to file shares via SID history
  • Email delivery (Exchange hybrid configuration)
  • All 47 service accounts reconfigured in test environment

Phase 4: Wave Migrations (Weeks 15–48)

Migrated users in 22 department-level waves, scheduled to avoid clinical peaks:

WaveDepartmentAccountsResult
1–3IT & Admin480No issues
4–8Finance & HR1,2002 minor GPO issues resolved
9–15Clinical support4,800Successful with 30-min extended support coverage
16–22Clinical frontline5,520Successful; 1 legacy app required special handling

Results

  • 12,000 accounts migrated across 22 waves over 14 months
  • Zero clinical incidents attributable to the migration
  • 4-hour maximum downtime per wave achieved in all cases
  • Three forests retired on schedule
  • Security posture improved via new GPO baseline and privileged access model

Key Takeaways

  1. Service account inventory is the most underestimated task — always do it first, always.
  2. Trust + SID history = zero access disruption when set up correctly before the first wave.
  3. Clinical IT requires dedicated support coverage during migration windows — not just general helpdesk.
  4. A wave-based approach compounds learning — later waves are faster and smoother than early ones.

Interested in a structured approach to your AD migration? Get in touch.

← All case studies
active-directorymigrationsmergerwindows