Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

LDAP Filter to exclude a sub OU?

I have a need to exclude a sub OU from a search base.  CUCM is LDAP integrated to Active Directory.  The directory search basically OU=Users, DC=company,DC=local.  There is a couple of OU's located under the Users container (OU=service, OU=special).  A third party manages this companies AD and is not willing to make any changes to the structure.  Does anyone have a suggestion for a filter that will work to filter out the users in the OU=special?  I have tried several things but the ones i thought would work are:

1. (&(objectClass=user)(!(OU=special)))  have tried this with the full search base as well

2. (!(&(objectClass=user)(OU=special)))

Any help would be appreciated.

 

Everyone's tags (2)
2 REPLIES
Cisco Employee

Simply remove read

Simply remove read permissions over that OU from the user you're using for the integration.

HTH

java

if this helps, please rate

www.cisco.com/go/pdi
New Member

Hi gpword,I dont think you

Hi gpword,

I dont think you can exlcude a sub OU, at least I could never get it working.

A few options you can use.

1. Add all the users in the "Special" OU to a group and then exclude that group - I use this option and it works

(&(ipPhone=*)(objectclass=user)(!(objectclass=Computer))(!(UserAccountControl:1.2.840.113556.1.4.803:=2))(!(memberOf=cn=GrouptoExclude,ou=XXXX,ou=XXXXX,DC=domain,DC=local)))

2. As above you could utilise the ipPhone field and only sync users who have this set or only sync users who are a member of a particular group below

(&(ipPhone=*)(objectclass=user)(memberOf=cn=USERStoSYNC,ou=XXXX,ou=XXXX,DC=domain,DC=local)(!(objectclass=Computer))(!(UserAccountControl:1.2.840.113556.1.4.803:=2)))

The above examples also exclude disabled accounts, computer objects and inlcude only users with the ipPhone field set.

 

Thanks,

7887
Views
20
Helpful
2
Replies
CreatePlease login to create content