6.2

Table Of Contents
Migrating User and Group Identities
Standard users and groups are migrated, provided that the target system exists in the same domain as
the source system or the target domain has identical trusts as the source system.
Other users and roles are captured in the reports and are not migrated.
Local machine users are not migrated. Built-in user accounts, such as BUILTIN\Administrator or
BUILTIN\Everyone, are also not migrated. However, for resources that belong to a built-in administrator
account and for which a machine has been provisioned, that machine is migrated and assigned to the
tenant administrator.
For user names that the migration process cannot translate, the migration process performs the following
actions:
n
Replaces the user name with the UPN of the default tenant
n
Reports the occurrence in the pre-migration and migration reports
Although the group names are not changed during migration, some classification terms have changed.
Table 13. Group Name Terms Before and After Migration
vCloud Automation Center 5.2 Group Name vRealize Automation Group Name
Enterprise group Fabric group
Provisioning group Business group
Migrating User Security Settings
Windows Security Identifier data in the User Authorization Manager data store is extracted from the
source system and converted to User Principal Name format. This data is migrated to the target
vRealize Automation system.
Role membership identifies users and groups who are using Windows Security Identifier (SID) format. In
vRealize Automation, this information is stored in a Single Sign-on (SSO) authorization store. The SSO
store identifies each user and group by using a UPN format. All security identifiers are migrated to the
SSO store in the target system.
The following table contains an example of the two formats.
Table 14. Example of User Name Equivalent in SID and UPN format
Source SID Domain Format Sample User Target UPN Format Sample User
mycompany.local\joe.user joe.user@mycompany.local
vRealize Automation only accepts security identifiers in UPN format.
During the process of migrating user information, vCloud Automation Center 5.2 security data in Windows
Security Identifier format is extracted and converted to UPN format by connecting and querying the Active
Directory domain for UPN identifiers. The converted fully qualified UPN identifiers are cached in
temporary tables to be committed to the vRealize Automation authorization store.
Migrating vCloud Automation Center 5.2.3 to vRealize Automation 6.2
VMware, Inc. 13