This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

Synchronization of AD User and AD Groups

Hi,

 

i got a problem while synchronizing from OIM into Active Directory.

We have Domain with different Customers in it. We only manage at this time one customer with OIM.

There are some Active Directory Groups which are shared between the Customers.

 

In the Manager Application i can see that in some of those AD-Groups "Active Directory SIDs" and the Identites from OIM are displayed.

 

Everytime I synchronize from OIM to AD, the OIM Jobserver tries to add this "Active Directory SIDs" again as an Member of the group, although they are in it right now.

 

Is there any Way that there  unmanaged AD-Accounts are ignoriered by Synchronizing?

 

Thanks for your Help

Parents
  • Hi Trevor,

    I am filtering in the Synchronization Job only users with the AD-Attribute "Employeeid" filled with "OI%". All the SID-Objects doesnt have this Attribute filled.

    We are tracking changes in Active Directory with "ChangeAuditor" and we can see on every Sync that the Domain Controllers get flooded with failed actions. Thats because the Assignment from SID-Objects to 1IM Groups is already exisiting in AD.

    I have no idea why 1IM want to add these SID-Objects again to this groups.

    Anyone else an idea?

    best Regards

    Marcel

Reply
  • Hi Trevor,

    I am filtering in the Synchronization Job only users with the AD-Attribute "Employeeid" filled with "OI%". All the SID-Objects doesnt have this Attribute filled.

    We are tracking changes in Active Directory with "ChangeAuditor" and we can see on every Sync that the Domain Controllers get flooded with failed actions. Thats because the Assignment from SID-Objects to 1IM Groups is already exisiting in AD.

    I have no idea why 1IM want to add these SID-Objects again to this groups.

    Anyone else an idea?

    best Regards

    Marcel

Children
No Data