KB-0500: How to use MoveTree utility on Centrify Zone-enabled users or groups
Problem:
Movetree is used to move one or more objects from one part of a forest to another. If you move a Zone-enabled AD user from one domain to another, then the Zone information for that user is lost. The same is also true for groups.
Note: In some cases the DirectControl Admin Console may show the AD user as still being correctly Zone-enabled but this is functionally not correct and the linkage has been lost.
Workaround:
1. Go to Active Directory Users and Computers and open the Properties for the AD user to be moved. Click on the Centrify Profile tab and make a note of the Unix Profile information for each Zone. 2. Remove all Zones that the AD user belongs to. 3. Run MoveTree as normal. 4. Zone-enable this AD user (now in the new domain) to the same Zone(s) with same Unix Profile information that was noted in step 1.
The above steps are the same for Zone-enabled AD groups that are moved using the MoveTree utility.