PeopleSoft domain Migration FAQS
Also see the List of Domain Migration documents.
Account migration is the process of integrating the existing legacy JDE and legacy PeopleSoft domains into one single Active Directory domain. The process starts with identifying each current user and creating a new user account in the PEOPLESOFT domain. That part is mandatory and except in very rare circumstances the new account in the PEOPLESOFT domain must be used. The process includes setting up permissions, profiles (work environment) and related information so that the two accounts are as identical as possible.
Maintaining a single domain will provide substantial improvements in a variety of areas including building and supporting machines, security issues, updates and more. All workstations will be migrated to the PEOPLESOFT domain.
Yes. For 99% of users domain migration will be achieved by script without any need for user intervention. In exceptional circumstances a machine may be allowed to continue using a domain other than PEOPLESOFT. The use of that other domain will be unsupported. HOWEVER that machine account must still be migrated to the PEOPLESOFT active directory domain.
No, the move will be done by script. Your preparation for the move will not be difficult, nor should you notice anything substantially different once you begin using the new domain.
1. Check the known issues to make sure none apply to you.
2. On or after your migration date begin logging into the PEOPLESOFT domain
If you are not working on the day of your go-live date, you will join the PEOPLESOFT domain on the next date that you return. Should you experience an issue, your old domain account will still exist during this migration allowing you to log off and log back into the CORP or JDEMD1 (JD Edwards) while the issue is resolved.
Remote Users (VPN, RAS, IPASS) You have some steps to take before you login to the PEOPLESOFT domain.:
When your migration date arrives do not automatically log into the PeopleSoft domain if you are accessing the network remotely (i.e. via Dial-up networking, VPN or IPASS).
Instead take the following steps.
- First, check to see if the migration tool has been run on your machine.
- You do this by searching your machine for a file called vmover.txt.
- If you find this file you are properly migrated and you can begin logging into the PEOPLESOFT domain.
- If you do not find vmover.txt you have the following choices:
(1) Come into a PeopleSoft office to make a direct network connection so your logon script with the migration tool runs.
(2) Submit a NorthStar ticket to have your machine migrated. You must be logged in to have your machine migrated so make sure to identify at least a several hour window when you will be logged in.
(3) Run the migration tool manually.
http://eureka.peoplesoft.com/html/69067.htm#vmover- You must logon to the network from the logon screen.
For VPN instructions see 54119 — How to configure Cisco VPN to log into the network automatically (for direct network connection)
For RAS and IPASS (or if the VPN solution doesn't work) see A55191 — Authenticating a remote user to the network for migration
3. It is your obligation to report problems you have using the PEOPLESOFT domain to work toward a resolution. Logging into the old domain after migration is a workaround, not a solution. It is not acceptable to continue using the old domain after migration unless the reason for the continued use has been reported.
You should not notice any differences to your work environment, except you will now be logging into the PEOPLESOFT domain. The default domain should show as PEOPLESOFT even though your old domain should remain available for a short time after migration (a week or so depending on whether you migrate on schedule).
Your user name will not change. You will use the same password initially. However, there are changes to password requirements. See Eureka! document 50001 — How to change your network password
There are some known issues you should be aware of, please review them.
Account migration is being done in phases alphabetically by your last name.
One Voice is the official communications channel regarding this migration. Users should join PEOPLESOFT domain as soon as possible after they are scheduled to do so. If there is some problem with logging into the PEOPLESOFT domain, that problem must be resolved (by correction or official exception) as soon as possible. Beginning as early as July 23 user access to the old domains will be disabled. After that time the user must use the new account in the PEOPLESOFT domain.
Asia Pacific employees should add one day to the schedule below.
Former J.D. Edwards employees who work on Enterprise One P&T development or testing should check this exemption list for your substitute date to join PeopleSoft: http://psh-aisee-02/it338/04.Project%20Deliverables/E.%20Deploy%20Phase/Exception%20List/JDE_Workstation_Exemption.htm
|
Date |
Activity |
|
June 1- June 3 |
All employees/contractors are asked to reset their passwords |
| June 4 | Password Moratorium Starts - Password aging turned off in CORP and JDMD1 |
|
June 4 |
Primary Key systems that integrate with the Active Directory will be configured. (i.e. Planet, C1, Siteminder, etc.) |
|
June 8 |
All users go live (Last Name A - Ap) |
|
June 9 |
All users go live (Last Name Aq-Be) |
|
June 10 |
All users go live (Last Name Bf-Cho) |
|
June 11 |
All users go live (Last Name Chp-Foo) |
|
June 11 |
Secondary key systems that integrate with the Active Directory will be configured (i.e. ICE, EM Central, etc.) |
| June 15 | All users go live (Last Name Fop-Hec) |
| June 16 | All users go live (Last Name Hed-Kr) |
|
June 17 |
All users go live (Last Name Ks-Mc) |
| June 18 | All users go live (Last Name Md-Pop) |
| June 19 | HRDB direct LDAP change |
|
June 22 |
All users go live (Last Name Poq-Sen) |
|
June 23 |
All users go live (Last Name Seo-Ven) |
|
June 24 |
All users go live (Last Name Veo-Z) |
| June 25 | Password Moratorium Ends |
|
June 26 |
Migration of remaining systems that come on line in CORP or JDEMD1. |
Actually users don't have much control over whether to migrate. The new account will be created and the old account disabled without requiring user intervention. At some point the user will no longer be able to access the network using the old account. If your machine is not on line during the migration period then the machine will not be migrated and your work environment will not be preserved. After migration the only available access will be via the new account in the PEOPLESOFT domain.
If your machine is still using the legacy JDEMD1 or CORP domains after that domain has been turned off, then the machine will be unable to access the network.
The migration tool preserves the current work environment for such things as drive mappings, printers, short cuts, certain applications on the Programs menu, preferences in Internet Explorer, Word, Excel and other applications, desktop appearance and similar issues. For more information see the section on User Profiles. The tool must be used while the old account is still active. Once the old account is disabled the migration tool cannot be used. The tool should be used before beginning to use the new account in the PEOPLESOFT domain. If a user logs into the PEOPLESOFT domain without using the migration tool then extra steps are required recover the original profile. Submit a NorthStar ticket or contact Technical Support Operations to get help in recovering the profile. In all cases the user can recreate the working environment manually.
No. You may log into the old domain after your migration date to the extent necessary to solve a domain related problem. The old domains will remain available for this purpose only. Logins to the old domains will be monitored to ensure that all users are migrating on schedule, and to identify problems and issues. Users experiencing issues are expected to contact Technical Support Operations for resolution.
If you are already logging into the PEOPLESOFT domain you don't need to do anything different, keep using your PEOPLESOFT domain login.
As part of the integration everyone in PeopleSoft will soon be using just one domain, the PEOPLESOFT domain. Moving to a single domain environment offers better management, better accountability, and better security.
Not much can go wrong. Problems are rare, but they could happen. Here are the solutions we know about.
Most common fix - reboot
If you experience any problems most of them can be resolved by shutting down, then rebooting and logging into the PEOPLESOFT domain using your normal username and password. If PEOPLESOFT is not the default domain, use the drop down list to change it to PEOPLESOFT.
Second most common fix - direct network connection
You can get a direct network connection by:
Some things to check
Verify that you are actually logging into the domain. If you open a command prompt window and type
set
the entry that names LOGONSERVER should display the Domain Controller's name. If it displays the local machine's name instead then the logon is to the machine instead of the network domain.
Verify that you are logging onto the network from the logon screen. Do not logon locally first, then VPN (or RAS or IPASS) in. For more information see the summary on A55191 — Authenticating a remote user to the network for migration
You must be an administrator on the machine. To find out if you are local administrator on your machine see Eureka! document 69064 — How to determine if you are an administrator on a machine. If you are not an administrator on the machine but you do need to copy over your local profile submit a NorthStar ticket or contact Technical Support Operations for assistance. If you are an administrator then see if you have MKS Toolkit installed. If you do then temporarily rename the folder and try the migration again. You may also need to add your new PEOPLESOFT account as administrator see Eureka! document 69068 — How to add someone as an administrator on a machine
If the workstation was locked when the migration began there will be a delay before you can unlock it. If the machine won't unlock using the PEOPLESOFT domain then you can unlock logging in using the old domain. In some cases the original domain will not be showing in the domain box, perhaps only the machine account and PEOPLESOFT. This can be quickly and easily resolved. For more information see Eureka! document 69089 — Cannot unlock machine after migration to PEOPLESOFT domain.
If you get an error message similar to: Windows cannot load the user's profile but has logged you on with the default profile for the system. Detail - The system cannot find the file specified. restart the machine and log in again to the PEOPLESOFT domain. For more information see Eureka! document 29090 — Windows cannot load the user's profile but has logged you on with the default profile for the system.
If you get an error message similar to: The error WIL Extender Error 1001 Basic ADSI Path Name On Line: DSSET Property (ldapmachine, "Location", sitename) WIN BATCH 32 2003 c WIL version 4.0 cda. submit a NorthStar Ticket so the Active Directory can be searched for a duplicate user or machine name. See Eureka! document 29092 — WIL Extender Error 1001 Basic ADSI Path Name ....
If you get an error
System could not log you on because the <DOMAIN NAME> domain is not available the problem is usually that you are not fully autheticating to the network. You must logon to the network from the logon screen.
For VPN instructions see
54119 — How to configure Cisco VPN to log into the network automatically (for direct network connection)
For RAS and IPASS (or if the VPN solution doesn't work) see
A55191 — Authenticating a remote user to the network for migration
If you get an error
Network path not found the problem is usually that you are not fully autheticating to the network. You must logon to the network from the logon screen.
For VPN instructions see
54119 — How to configure Cisco VPN to log into the network automatically (for direct network connection)
For RAS and IPASS (or if the VPN solution doesn't work) see
A55191 — Authenticating a remote user to the network for migration
Desktop background, shortcuts, personal settings are all missing. (Profile is missing)
The first step is to reboot. In most cases this will correct the problem and it will not reoccur. If rebooting did not correct the problem your profile may not have been copied over correctly. If your profile was not copied over correctly your desktop environment will not be the same. To correct the problem see Eureka! document 69067 — How to manually migrate your user profile to your PEOPLESOFT account.
Password, Login, Access, Administrator status?
Passwords: Passwords in the legacy domains are locked. If you change your password in the PEOPLESOFT domain it will not be changed in your old domain. Password expiration is suspended so you should not need to change your password during the migration period.
If, when you log on to your new PEOPLESOFT account, your password is refused try using the your last password. The password for your new PEOPLESOFT account is based on your password in your current domain at the time your new account is created. If you changed your password after your PEOPLESOFT account was created that new password will only work for your old domain, the PEOPLESOFT account will still have the old password. Careful about testing passwords. If you have tried to enter a password 3 times it is best to wait ten minutes before trying again or you may get locked out.
If you get a prompt that your password is about to expire: Password aging has been turned off and passwords in the legacy domains are locked. Log into PEOPLESOFT and continue using that domain.
If problems continue contact Technical Support Operations and have BOTH your PEOPLESOFT and old domain passwords reset to the same thing.
Documentum and EDS or E-Reports users may be unable to access those applications with the old domain account still active. If this problem occurs submit a NorthStar ticket or contact Technical Support Operations to get the old account disabled immediately.
If you get an error message saying that you need to be an administrator on the machine see Eureka! document 69064 — How to determine if you are an administrator on a machine.
If you have problems with network drives and printers the first step is to shutdown completely (power off) reboot. This problem is most likely to occur for people who are migrating early without being officially part of the test group. In any case you might need to remap network printers. If you get an error when you try using a printer then delete the printer and re-add it. For information on adding printers see Eureka! document 40010 — How to add printers.
You might need to remap network drives. You will need to manually disconnect and remap network drives if you get a message like:
Incorrect password or unknown username for:
network drive and directory You last connected to this computer as
DOMAINNAME\
username or
An error occurred while reconnecting
network drive letter to
network drive and directory
Microsoft Windows Network : Logon failure: Account currently disabled.
Do not try to restore the connection in the future.Do not display
further error messages. Continuing restoring connections?. Select
Do not try to restore the connection in the future. When you are finished logging in disconnect each mapped network drive, then remap them. For more information see documents
55059 — Disconnect network drive and
50003 — Map a network drive
What is a profile?
Your log-on profile contains most of the settings that personalize your work environment. Some parts of the profile are purely aesthetic. The profile includes, for example, background color, wallpaper selection, chosen screen saver, and other elements affecting appearance. Other parts of the profile are more functional. They include, for example, mapped network drives, printers, mouse settings, short cuts and files and folders stored on the desktop. The profile can also contain resources specific to one user. That would include browser cookies and favorites, user preferences for certain programs, and even access to applications via the Start > Programs menu.
Where is the profile stored?
Most of the profile is stored in folders. For Windows 2000 navigate to c:\Documents and Settings\(your username)\ Some parts of the profile are also stored in the registry.
Can I copy the profile over directly? Can I start the migration process over so I can get my work environment back?
For the most part the answer is "yes." But because some parts of the profile are stored in the registry manually copying the profile will not be perfect. Some parts will not copy over properly. There is a utility for copying profiles that will do a better job. See Eureka! document 69067 — How to manually migrate your user profile to your PEOLESOFT account.
Visit the Project IT-338 Active Directory Integration web site. http://psh-aisee-02/it338/IT338.htm. Also see the List of Domain Migration documents.
Search your machine for the file vmover.txt.
Double-click the My Computer icon on your Windows desktop to open it.
Double-click on the C: drive
On the menu bar click on Search.
In the box under Search for files or folders names: put
vmover.txt
The box under Look in should say "Local Harddrives (C:)
Click on the button Search Now.
When the search is completed any files found will appear in the right hand panel.
If the problem is not urgent submit a ticket through NorthStar or try to find the answer through Eureka!. If the problem is urgent contact Technical Support Operations at PSHx2222 or 888/54-PSHELP. If you are seeking an exception, have your manager send an email to Jeff Fesunoff. Exceptions are rare. Also see the List of Domain Migration documents.
Created by the PeopleSoft Knowledge Management Team.
Copyright © 2004
All rights reserved.
Created: db 04/16/2004
Revised: db 06/02/2004