<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic AD user status Sync in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/ad-user-status-sync/m-p/44538#M18114</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;we have alfresco 5.2 in our environment. we have a couple of active directory domain and which is mapped in alfresco. previously we have all the users (including disabled and active users) in the alfresco.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;issue&amp;nbsp;1: &lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;we have modified the person query and enabled "synchronization.allowDeletions" in ldap-ad-authentication.properties to perform a full sync with the AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;ldap.synchronization.personQuery=(&amp;amp;(objectclass\=user)(userAccountControl\:1.2.840.113556.1.4.803\:\=512))&lt;BR /&gt;ldap.synchronization.personDifferentialQuery=(&amp;amp;(objectclass\=user)(userAccountControl\:1.2.840.113556.1.4.803\:\=512)(!(modifyTimestamp&amp;lt;\={0})))&lt;/P&gt;&lt;P&gt;synchronization.synchronizeChangesOnly=false&lt;BR /&gt;synchronization.allowDeletions=true&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;After we restarted the service with the above configuration, we still can see the users in alfresco which are already got deleted in AD.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;issue 2:&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;we also configured the user status to be reflected in the alfresco, hence we modified the alfresco-global.properties with the below parameters.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;BLOCKQUOTE class="jive_macro_quote jive-quote jive_text_macro"&gt;&lt;P&gt;authentication.chain=alfinst:alfrescoNtlm,passthru1&lt;img id="smileytongue" class="emoticon emoticon-smileytongue" src="https://connect.hyland.com/i/smilies/16x16_smiley-tongue.png" alt="Smiley Tongue" title="Smiley Tongue" /&gt;assthru,ad1:ldap-ad,ad2:ldap-ad,ad3:ldap-ad,ad4:ldap-ad&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;### user account status syncronization ###&lt;BR /&gt;synchronization.externalUserControl=true&lt;BR /&gt;synchronization.externalUserControlSubsystemName=ad1,ad2,ad3,ad4&lt;BR /&gt;ldap.synchronization.userAccountStatusProperty=userAccountControl&lt;BR /&gt;ldap.synchronization.disabledAccountPropertyValue=514&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after we restarted the alfresco service, we still see that user status (enabled/disabled) is not reflected in alfresco. users which are disabled in AD is still active in alfresco.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;let me know what could be the issue here. our final goal is to do a full sync with active users in alfresco. if the user is disabled, the same should be reflected in alfresco as well.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Appreciate your help!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Thu, 02 Aug 2018 06:48:35 GMT</pubDate>
    <dc:creator>muthu_domain</dc:creator>
    <dc:date>2018-08-02T06:48:35Z</dc:date>
    <item>
      <title>AD user status Sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/ad-user-status-sync/m-p/44538#M18114</link>
      <description>Hi,we have alfresco 5.2 in our environment. we have a couple of active directory domain and which is mapped in alfresco. previously we have all the users (including disabled and active users) in the alfresco.issue&amp;nbsp;1: we have modified the person query and enabled "synchronization.allowDeletions" in l</description>
      <pubDate>Thu, 02 Aug 2018 06:48:35 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/ad-user-status-sync/m-p/44538#M18114</guid>
      <dc:creator>muthu_domain</dc:creator>
      <dc:date>2018-08-02T06:48:35Z</dc:date>
    </item>
    <item>
      <title>Re: AD user status Sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/ad-user-status-sync/m-p/44539#M18115</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&lt;SPAN style="color: #58595b; background-color: #ffffff; font-weight: bold;"&gt;Changing synchronization.synchronizeChangesOnly to false means the scheduled job for synchronization runs in Full Mode. Not sure that full mode is triggered in server startup as well.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #58595b; background-color: #ffffff; font-weight: bold;"&gt;You can try running the job by either changing the cron or using jconsole.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2018 10:39:57 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/ad-user-status-sync/m-p/44539#M18115</guid>
      <dc:creator>hardik1512</dc:creator>
      <dc:date>2018-08-02T10:39:57Z</dc:date>
    </item>
    <item>
      <title>Re: AD user status Sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/ad-user-status-sync/m-p/44540#M18116</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;In fact, it is not. Full mode is not triggered in startup. A trick for doing this&amp;nbsp;in the startup&amp;nbsp;is doing &amp;nbsp;&lt;SPAN style="color: #58595b; background-color: #ffffff; font-weight: bold;"&gt;ldap.synchronization.personQuery the same as ldap.synchronization.personDifferentialQuery&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #58595b; background-color: #ffffff; font-weight: bold;"&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #58595b; background-color: #ffffff;"&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN style="color: #58595b; background-color: #ffffff;"&gt;--C.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 02 Aug 2018 16:19:37 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/ad-user-status-sync/m-p/44540#M18116</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2018-08-02T16:19:37Z</dc:date>
    </item>
    <item>
      <title>Re: AD user status Sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/ad-user-status-sync/m-p/44541#M18117</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi Cesar,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;still the issue is not resolved. even i have made changes in alfresco-global.properties and ldap-ad subsystem properties with below values:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;on both alfresco-global.properties and ldap-ad.properties:&lt;/P&gt;&lt;P&gt;synchronization.synchronizeChangesOnly=false&lt;BR /&gt;synchronization.allowDeletions=true&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;On alfresco-global.properties:&lt;/P&gt;&lt;P&gt;synchronization.syncWhenMissingPeopleLogIn=true&lt;BR /&gt;synchronization.syncOnStartup=false&lt;BR /&gt;#synchronization.import.cron=* * * * * ?&lt;BR /&gt;synchronization.import.cron=* 0/10 * * * ?&lt;BR /&gt;ldap.synchronization.enableProgressEstimation=true&lt;/P&gt;&lt;P&gt;ldap.synchronization.userAccountStatusInterpreter=ldapadUserAccountStatusInterpreter&lt;/P&gt;&lt;P&gt;### user account status syncronization ###&lt;BR /&gt;synchronization.externalUserControl=true&lt;BR /&gt;synchronization.externalUserControlSubsystemName=ad2,ad4&lt;BR /&gt;ldap.synchronization.userAccountStatusProperty=userAccountControl&lt;BR /&gt;ldap.synchronization.disabledAccountPropertyValue=514&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;after i restarted alfresco service, still i can see old users in alfresco and their user status also NOT synced. let me know is this functionality will work with alfresco with AD configuration or is there something which i'm missing.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 07 Aug 2018 17:12:52 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/ad-user-status-sync/m-p/44541#M18117</guid>
      <dc:creator>muthu_domain</dc:creator>
      <dc:date>2018-08-07T17:12:52Z</dc:date>
    </item>
    <item>
      <title>Re: AD user status Sync</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/ad-user-status-sync/m-p/44542#M18118</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Try with this aprox:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="link-titled" href="http://formtektips.blogspot.com/2018/02/best-practices-for-managing-user-import.html" title="http://formtektips.blogspot.com/2018/02/best-practices-for-managing-user-import.html" rel="nofollow noopener noreferrer"&gt;Technical Tips &amp;amp; Tricks: Best Practices for Managing User Import into Alfresco from Active Directory&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Regards.&lt;/P&gt;&lt;P&gt;--C.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 09 Aug 2018 18:50:46 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/ad-user-status-sync/m-p/44542#M18118</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2018-08-09T18:50:46Z</dc:date>
    </item>
  </channel>
</rss>

