AD sync without importing groups
Updated: 29 Oct 2010 | 7 comments
Does anyone know how to setup the AD sync/import so that users will be imported but not groups? We'd prefer to manage groups manually but still need users imported upon creation.
Discussion Filed Under:
Comments
I like to know about this as
I like to know about this as well........
USe the MR1 release of Service Desk
We have this working but there are a number of steps:
It is best to try this with one or two OUs at the lowest level of your AD and then add others when you are happy.
I adjusted my config to the
I adjusted my config to the OUs that I want. Now, how do you remove all of the old users and groups that you don't want in the system?
Deleting users and groups
Groups are easy to delete. Go to Admin/Users/Accounts/List Groups. You can delete any group from the action selection on the RHS of each group.
There is no easy way to delete users although this feature has been requested, see the request on the Altiris Knowledgebase site, https://kb.altiris.com/display/1/index.asp?c=&cpc=&cid=&cat=&catURL=&r=0.3393213 , and subscribe to be kept up to date.
The way I have removed users, which only works for a small number and they have no tickets against them, is to create a dummy user, which I call 'deleted.user', in SD. I then use the merge action to merge the user with my 'deleted.user'. This gives you a warning message that the user will be deleted and removes them from SD.
Groups and Users in same OU
Hi!
We have groups and users and the same OU and cannot change that.
I would love to have a option to Disable groups when importing!
Thanks!
Robert Lundsten
Consultant / Founder : Asterio
Homepage | http://www.asterio.se
Blog | http://www.asterio.se/blogg
Twitter | http://twitter.com/asterioan
AD sync without importing groups
Is there anyway to NOT import groups? I see some workarounds here but nothing that says 'do not import groups'.
I have so many groups that when I try to assign permissions, I don't have any of teh built in groups in the selction list. All i have are the top 2000 imported groups from AD.
After all the talking stops 1 simple fact remains.
It is what we, collectively, have allowed it to become.
AD sync without importing groups
Hi All,
No theres is no wqy no filter group import.
I asked today to one of my customer to create SD groups in a dedicated OU: I do not think it's a problem. You create dedicated groups for SD and put them in a dedicated OU.
Next, you can use the tools I made to copy permissions and so on from on group to others:
AD sync without importing groups
Best regards,
Fabrice B M
FABEMARA Consulting the main Symantec Altiris Partner in Spain
http://www.fabemara.es
http://assistance.fabemara.com
Would you like to reply?
Login or Register to post your comment.