When you migrate from Active Directory to the Identity Vault, you need to be concerned about object containment, DN references, and search limits on the Active Directory server. The general strategy for dealing with containment is to migrate containers first, objects that might be members of groups (including user objects) second, and groups last. If you have a moderately large number of objects to migrate, you need to adjust your strategy to handle the LDAP search constraints configured on the Active Directory server. You can change the constraints on the LDAP server or adjust your migration to get only a subset of objects each time (for instance, migrating container by container or migrating objects starting with A, B, etc.).