Endpoint Protection

 View Only
  • 1.  Can't get Active Directory Client Synchronization to Work After Upgrade to SEPM MR4 MP2

    Posted Jun 26, 2009 01:08 PM
    Synchronization had been working mostly fine until the latest upgrade.
    Active Directory integration works partially because we can use our domain accounts to authenticate into the SEPM console.
    However, the scheduled synchronizations and manual synchronizations for clients started failing after upgrade.

    Since we started having this problem we have been experimenting with different formats and different syntax of typing in the Directory Server info into the SEPM console.  The user account is still active and has a non-expiring password.
    The Help file on this is too vague so I am going to ask here for very specific answers.
    We have only have one SEPM server so there is no replication involved.

    Under "Edit Directory Server" what is typed into each field?

    Name:  Is this just a label or is it suppposed to be your domain name or the host name of the domain controller you want to use?
    Server type:  Should the Active Directory ot LDAP radio button be selected (what are pos and cons of each)?
    Server IP address or name:  Should IP address or hostname be used or does it matter?
    LDAP port:  389 is default
    LDAP BaseDN:  I can't find an example anywhere that shows how to type the syntax of an OU structure more than 1 level deep, so we don't know what order/syntax to type in the OUs to get the entire path.
    User Name: do you type domain\user name or just user name?
    Password:  of course this is the user password


  • 2.  RE: Can't get Active Directory Client Synchronization to Work After Upgrade to SEPM MR4 MP2

    Posted Jun 26, 2009 07:14 PM
    Name: Is this just a label or is it suppposed to be your domain name or the host name of the domain controller you want to use?
    Just a label

    Server type: Should the Active Directory ot LDAP radio button be selected (what are pos and cons of each)?
    If you are only interested in the computer names, Use Active Directory.

    Server IP address or name: Should IP address or hostname be used or does it matter?
    I use server name, but I'm sure IP should work

    LDAP port: 389 is default
    yes.

    LDAP BaseDN: I can't find an example anywhere that shows how to type the syntax of an OU structure more than 1 level deep, so we don't know what order/syntax to type in the OUs to get the entire path.
    Shouldn't matter if you use choose Active Directory.

    User Name: do you type domain\user name or just user name?
    Mine is listed without the domain\

    Maybe if you list the errors that the synch process gives, someone here can troubleshoot the issue.



  • 3.  RE: Can't get Active Directory Client Synchronization to Work After Upgrade to SEPM MR4 MP2
    Best Answer

    Posted Jun 30, 2009 11:43 AM
    Nothing would fix it no matter what was entered as server or LDAP settings. I finally had to delete all of the computer OUs imported into SEPM and reimport them and it started working again.