Introduction
On Demand Migration for Active Directory (ODMAD) enables you to migrate and consolidate AD and Entra ID environments. This SaaS solution can integrate and migrate users, groups, and devices between Active Directory, Entra ID, and hybrid directory environments.
See the user guide for the solution you purchased.
Organizations and Regions
When you sign up for the On Demand service for the first time, you create an organization and you are granted the On Demand Administrator role. You can add additional organizations and administrators.
For more information about managing your organization see Managing organizations and regions in the On Demand Global Settings User Guide.
Some common actions with Organizations are reproduced here for your reference:
Creating an organization
- Sign in to Quest On Demand.
- If you have not yet created an organization, click Create Organization.

If you have created one or more organizations, the Choose an Organization page opens. Click Create New Organization.
If you have already selected an organization, click your email address at the upper-right corner of the page and then select Create Organization.
- In the Create Organization page, specify the following information:
- Organization Name - name of your organization. For example, Big Box Inc.
- Deployment Region - A Microsoft Azure region or geographic area where data centers are deployed. Not all On Demand modules are available in all regions.
- Click Create Organization.
Switching to another organization
If you have multiple organizations associated with your email address, you can select an organization from the Choose an Organization page when you sign in. If you have already selected an organization but want to work with another organization, you can switch to another organization.
- Click your email address at the upper-right corner of the page.
- Select Switch Organization. The Choose an Organization page opens.
- Highlight and click the organization to which you want to switch.
Renaming an organization
You can rename the organization to which you are currently signed in. You must be an On Demand Administrator to rename an organization.
- Sign in and select the organization that you want to change.
- Click your email address at the upper-right corner of the page.
- Click the organization name. The Edit Organization page opens.
- In the Organization Name field, enter the new name.
- Click Update Organization Name. The organization name is updated.
Deleting an organization
|
|
Caution: Deleting an organization cannot be undone. |
- Sign in and select the organization that you want to change.
- Click your email address at the upper-right corner of the page.
- Click the organization name. The Edit Organization page opens.
- Click Delete Organization. A confirmation page opens.
- Select the following check boxes to confirm that you understand the impact of deleting an organization.
- All tenants will be removed
- All user information will be lost
- Click Delete Organization.
Signing in to Quest On Demand
To get access to On Demand Migration for Active Directory, you must sign up for the Quest On Demand service.
- Go to the web page quest-on-demand.
- On the Welcome to Quest On Demand page, click Sign in with Microsoft.
|

|
NOTE: Signing in using your Microsoft MFA-enabled account
If your organization requires multi-factor authentication and you receive an authorization error, your conditional access policy may not be configured correctly. You can take one of two actions:
- Contact your IT administrator to deactivate MFA during migrations.
- Contact Microsoft support for help with conditional access policies.
|
- Accept the Software Transaction Agreement before using this product.
- As part of the signing in process with Microsoft Entra ID, you must consent to the set of minimal permissions required by the Quest On Demand application.
- Create an organization. See Creating an organization for detailed steps.
Dashboard
The Dashboard displays key information and metrics about device migration. It provides a centralized overview of important data to help administrators monitor progress, manage migration schedules, and make informed decisions.
To open the Dashboard:
- Sign in to Quest and choose an organization if you have set up multiple organizations.
- From the navigation pane, click Migrate > Integration > Device Migration.
The components of the Dashboard are described below:
Notification panel - presents relevant information and shortcuts to migration activities. Appears only when a system notification is available.
Action Menu - Allows you to perform the actions described below:
- Quick Configuration - opens the project setup wizard that helps you set up your device migration project and activate the Identity Defense feature which is available with your subscription and protects your tenants.
- If configuration changes are pending this link displays Resume Configuration.
- Click Resume Configuration and select Restart to start over or Resume to continue.
- Manage Security Integration - helps you activate or deactivate the Identity Defense feature. You must subscribe to Secure Migration to access this feature. You maintain full control over the security integration outside the Quick Configuration wizard. See Managing Security Integration for more information.
- Filter - helps you choose the environment for which information is displayed in the Dashboard. See Filtering the Dashboard for more information.
- Refresh - click
to update the Dashboard.
Dashboard tiles
- Workstations Status - presents a summary of the migration status of workstations in the source tenant. Click View All to open the Ready Devices tab pre-filtered to display more information about workstations. The status values are as follows:
- Total - number of workstations with actual device jobs such as discovery, ReACL etc.
- Registered - number of workstations that have an agent installed on the device and the agents are registered with the backend.
- Migrating - number of workstations that are being migrated.
- Discovered - number of workstations discovered in the source AD.
- ReACL Failed - number of ReACL processes that failed to update a workstation’s domain user security ACL with the matching target user ObjectSID.
- ReACL Completed - number of ReACL processes that successfully updated a workstation’s domain user security ACL with the matching target user ObjectSID.
- Cache Credentials Failed - number of Cache Credentials jobs that could not be assigned to workstation(s).
- Cache Credentials Completed- number of Cache Credentials jobs that were successfully assigned to workstation(s).
- Migration Completed- number of workstations that have been successfully migrated.
- Migration Failed - number of workstations that could not be migrated or the migration was canceled by the migration administrator.
- Server Status - presents a summary of the migration status of servers in the source tenant. Click View All to open the Ready Devices tab pre-filtered to display more information about servers. The status values are as follows:
- Total - number of servers with actual device jobs such as discovery, ReACL etc.
- Registered - number of servers that have an agent installed on the device and the agents are registered with the backend.
- Migrating - number of servers that are being migrated.
- Discovered - number of servers discovered in the source AD.
- ReACL Failed - number of ReACL processes that failed to update a server’s domain user security ACL with the matching target user ObjectSID.
- ReACL Completed - number of ReACL processes that successfully updated a server’s domain user security ACL with the matching target user ObjectSID.
- Cache Credentials Failed - number of Cache Credentials jobs that could not be assigned to workstation(s).
- Cache Credentials Completed - number of Cache Credentials jobs that were successfully assigned to workstation(s).
- Migration Completed - number of servers that have been successfully migrated.
- Migration Failed - number of servers that could not be migrated.
- File Shares - presents a summary of the ReACL status of file shares in the source tenant. Click View All to open the File Shares tab pre-filtered to display more information about workstations. The status values are as follows:
- ReACL In Progress - number of ReACL processes attempting to update the file share’s domain user security ACL with the matching target user ObjectSID.
- ReACL Failed - number of ReACL processes that failed to update the file share’s domain user security ACL with the matching target user ObjectSID.
- ReACL Completed - number of ReACL processes that successfully updated the file share’s domain user security ACL with the matching target user ObjectSID.
- Agent Last Contact - Indicates when the agent last communicated with the service. It is categorized as Today, Within Last 7 Days, Within Last 14 Days, and More Than 14 Days.
In Active Directory the Agent Last Contact time is updated based on the TCP connection with the back end. This will occur if a job is retrieved or every 4 hours as a fall back. It is not expected that the Agent Last Contact time will update every two minutes even if the UDP requests to the job availability cache are functioning. correctly.
Click View All to open the Ready Devices tab. The Agent Last Contact column indicates the last time a management agent or client device communicated with a server or management system.
Filtering the Dashboard
The Dashboard displays a summary of devices across all environments by default. You can filter the information for a specific environment as described below
To filter the Dashboard:
- Click Filter to open the filter menu.
- Click Source Environment dropdown and select an environment. The Dashboard displays a summary of the selected environment.
- If multiple environments are selected, the Dashboard displays the combined summary of the selected environments. The Filter action link displays the number of filters applied.
- Click ✕to remove an applied filter or Clear All to reset the filter.
- If the filter menu is open, you can hide the filter menu by clicking the Filter action link again.
You can also select a collection from the dropdown at the upper-right corner of the workspace. Collections can be used with the Source Environment filter. See Collections for more information.