09-11-2009 06:17 AM - edited 03-15-2019 07:42 PM
Hi, I have CCM 7.0.2 with AD 2008.
CCM can'T get users for default OU created by AD. I have to create other OU to fix that. Is there anything I can change in AD to let the user on ccm getting the info on ou=Users.
thanks
Solved! Go to Solution.
09-11-2009 10:28 AM
The default is NOT "ou=Users". The default is "cn=Users" (cn stands for "container" here).
Michael
09-11-2009 06:22 AM
Have you confirmed the user you used for the integration has read rights over the OUs you want to sync??
HTH
java
if this helps, please rate
09-11-2009 06:24 AM
No, where do we have to do that :)
any documentation that explain that ?
thanks
09-11-2009 06:37 AM
That's an AD procedure
HTH
java
if this helps, please rate
09-11-2009 06:53 AM
Yep, this is the procedure that I am looking for
09-11-2009 09:31 AM
I might be mistaken, but I believe that all AD accounts have LDAP read permissions by default.
1. Can you see any User accounts that you know came from AD (not pre-existing accounts)?
2. If yes, try restarting the DirSync service on the Publisher.
3. If none show up, recheck the LDAP config on the Publisher. Does it save with no error messages? Is the LDAP User Search Base correct?
I've built a half-dozen UCM clusters that were synced and authenticated with AD. I have yet to figure out a way to filter users via AD permissions. If anyone know how to do this (AD 2003), please let me know.
I usually wind up syncing to the root domain and editing the LDAP filter string in CallManager to restrict which user account show up in CallManager.
Randy
09-11-2009 10:28 AM
The default is NOT "ou=Users". The default is "cn=Users" (cn stands for "container" here).
Michael
Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: