Tips for finding Knowledge Articles

  • - Enter just a few key words related to your question or problem
  • - Add Key words to refine your search as necessary
  • - Do not use punctuation
  • - Search is not case sensitive
  • - Avoid non-descriptive filler words like "how", "the", "what", etc.
  • - If you do not find what you are looking for the first time,reduce the number of key words you enter and try searching again.
  • - Minimum supported Internet Explorer version is IE9
Home  >

KB-0500: How to use MoveTree utility on Centrify Zone-enabled users or groups

Authentication Service ,  

12 April,16 at 11:30 AM


Movetree is used to move one or more objects from one part of a forest to another. If you move a Zone-enabled AD user from one domain to another, then the Zone information for that user is lost. The same is also true for groups.

Note: In some cases the DirectControl Admin Console may show the AD user as still being correctly Zone-enabled but this is functionally not correct and the linkage has been lost.


1. Go to Active Directory Users and Computers and open the Properties for the AD user to be moved. Click on the Centrify Profile tab and make a note of the Unix Profile information for each Zone.
2. Remove all Zones that the AD user belongs to.
3. Run MoveTree as normal.
4. Zone-enable this AD user (now in the new domain) to the same Zone(s) with same Unix Profile information that was noted in step 1.

The above steps are the same for Zone-enabled AD groups that are moved using the MoveTree utility.

Additional information on MoveTree: (Provided as a Courtesy)