<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic User changes domains help in Alfresco Archive</title>
    <link>https://connect.hyland.com/t5/alfresco-archive/user-changes-domains-help/m-p/271994#M225124</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;I have a bunch of users that are in Active Directory groups and being added automatically to Alfresco.&amp;nbsp; The way it works:&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;DomainA group with username jriker DISABLED&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;DomainB group with username jriker ACTIVE&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt; &lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Both DomainA and DomainB has the same named AD groups and they all are stored in another meta group that I directly reference.&amp;nbsp; Problem I'm having now is when people are moved to DomainB they are able to login still but none of their data is associated with them.&amp;nbsp; How do I tell Alfresco these are the same users or is the problem that the system has not resync'd yet?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;JR&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 13 Sep 2011 16:56:14 GMT</pubDate>
    <dc:creator>jriker1</dc:creator>
    <dc:date>2011-09-13T16:56:14Z</dc:date>
    <item>
      <title>User changes domains help</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/user-changes-domains-help/m-p/271994#M225124</link>
      <description>I have a bunch of users that are in Active Directory groups and being added automatically to Alfresco.&amp;nbsp; The way it works&lt;IMG id="smileyvery-happy" class="emoticon emoticon-smileyvery-happy" src="https://migration33.stage.lithium.com/i/smilies/16x16_smiley-very-happy.png" alt="Smiley Very Happy" title="Smiley Very Happy" /&gt;omainA group with username jriker DISABLEDDomainB group with username jriker ACTIVE Both DomainA and DomainB has the same named AD groups and they all are stored in another meta</description>
      <pubDate>Tue, 13 Sep 2011 16:56:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/user-changes-domains-help/m-p/271994#M225124</guid>
      <dc:creator>jriker1</dc:creator>
      <dc:date>2011-09-13T16:56:14Z</dc:date>
    </item>
    <item>
      <title>Re: User changes domains help</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/user-changes-domains-help/m-p/271995#M225125</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Thought I would revive this as I can't imagine an enterprise application would not be able to accommodate someone switching domains in an organization.&amp;nbsp; Even if it was manually editing the database and updating some UUID or something.&amp;nbsp; Anyone?&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Thanks.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;JR&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2011 13:31:33 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/user-changes-domains-help/m-p/271995#M225125</guid>
      <dc:creator>jriker1</dc:creator>
      <dc:date>2011-10-14T13:31:33Z</dc:date>
    </item>
    <item>
      <title>Re: User changes domains help</title>
      <link>https://connect.hyland.com/t5/alfresco-archive/user-changes-domains-help/m-p/271996#M225126</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;SPAN&gt;Hello,&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;it all depends on how your authentication subsystem is set up with regards to the synchronization, and how you manage the identities in your LDAP/AD. We have a customer whose LDAP simply contains all trees of their domains and we have set up one authentication subsystem against this aggregated LDAP - when users change domains and their active flag is updated, the currently active account is considered for synchronisation with Alfresco. As long as the identifying property has the same value, the user is unaltered in Alfresco.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;But when you have two or more subsystems configured (one for each domain) you actually cause Alfresco to delete and recreate users when they move, as two users from different subsystems are not considered to be the same individual as long as both subsystems are active.&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;So:&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- ensure users move only between the domains covered by a single subsystem&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- ensure user moves are atomic operations (if one account is deactivated and the new one will only be available two days later, you run the risk of the user being deleted in the meantime depending on your synchronisation interval / triggers)&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;- ensure the identifying property remains exactly the same (although case is probably irrelevant at least for 3.4 and lower)&lt;/SPAN&gt;&lt;BR /&gt;&lt;BR /&gt;&lt;SPAN&gt;Regards&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;Axel&lt;/SPAN&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 14 Oct 2011 14:12:04 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-archive/user-changes-domains-help/m-p/271996#M225126</guid>
      <dc:creator>afaust</dc:creator>
      <dc:date>2011-10-14T14:12:04Z</dc:date>
    </item>
  </channel>
</rss>

