<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Local User / AD user sync deletion. in Alfresco Forum</title>
    <link>https://connect.hyland.com/t5/alfresco-forum/local-user-ad-user-sync-deletion/m-p/78055#M24463</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp; Thanks for the clarification. It is helpful!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Tue, 31 Jul 2018 14:27:14 GMT</pubDate>
    <dc:creator>muthu_domain</dc:creator>
    <dc:date>2018-07-31T14:27:14Z</dc:date>
    <item>
      <title>Local User / AD user sync deletion.</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/local-user-ad-user-sync-deletion/m-p/78053#M24461</link>
      <description>Hi,we have few users in alfresco local database and we have migrated some of the users to AD. my question is:1. if we do full sync with AD and enabling&amp;nbsp;synchronization.allowDeletions&amp;nbsp;will affect local users in alfresco ?. because our existing user query in ldap-ad chain brought up all the computer a</description>
      <pubDate>Tue, 31 Jul 2018 07:10:26 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/local-user-ad-user-sync-deletion/m-p/78053#M24461</guid>
      <dc:creator>muthu_domain</dc:creator>
      <dc:date>2018-07-31T07:10:26Z</dc:date>
    </item>
    <item>
      <title>Re: Local User / AD user sync deletion.</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/local-user-ad-user-sync-deletion/m-p/78054#M24462</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;Hi:&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;1. if we do full sync with AD and enabling&amp;nbsp;synchronization.allowDeletions&amp;nbsp;will affect local users in alfresco ?.&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;gt; Do you mean if some username collides ? I would say that it affects in terms on chain authentication only (you may login with two passwords in general) , but the user in Alfresco belongs to two&amp;nbsp;authentication zones, so I think it won't be deleted.&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;because our existing user query in ldap-ad chain brought up all the computer and service accounts into alfresco. existing person query in ldap-ad chain is (&amp;amp;(objectclass=user)).&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;gt; For&amp;nbsp;avoiding this&amp;nbsp;you should define a more precise query or to make&amp;nbsp;an&amp;nbsp;aproximation like this:&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;A class="link-titled" href="http://formtektips.blogspot.com/2018/02/best-practices-for-managing-user-import.html" title="http://formtektips.blogspot.com/2018/02/best-practices-for-managing-user-import.html" rel="nofollow noopener noreferrer"&gt;Technical Tips &amp;amp; Tricks: Best Practices for Managing User Import into Alfresco from Active Directory&lt;/A&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;2. if i modify the user query to (&amp;amp;(objectclass=user)(userAccountControl=512)), it will bring only active users from AD. does all junk users will gets cleanup if i only modified the query alone or do i need to do a full with AD anyways.&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&amp;gt; For cleaning your computer and service accounts, you will need a full sync with deletions on a newer user query that exclude all those&amp;nbsp;&lt;SPAN&gt;computer and service accounts. The above link probably do the right&amp;nbsp;sync. Another simple&amp;nbsp;trick for starting from zero point (without ldap users) is to change to a virtual&amp;nbsp;&lt;SPAN style="color: #505050; background-color: #ffffff;"&gt;userSearchBase so the resulting query gives zero users and do full sync. And later just put the correct user query. You can check the querys with Apache Directory Studio for example.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;SPAN style="background-color: #ffffff; color: #505050;"&gt;Regards.&lt;/SPAN&gt;&lt;/P&gt;&lt;P style="color: #727174; background-color: #ffffff; border: 0px;"&gt;&lt;SPAN style="background-color: #ffffff; color: #505050;"&gt;--C.&lt;/SPAN&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2018 11:35:24 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/local-user-ad-user-sync-deletion/m-p/78054#M24462</guid>
      <dc:creator>cesarista</dc:creator>
      <dc:date>2018-07-31T11:35:24Z</dc:date>
    </item>
    <item>
      <title>Re: Local User / AD user sync deletion.</title>
      <link>https://connect.hyland.com/t5/alfresco-forum/local-user-ad-user-sync-deletion/m-p/78055#M24463</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;&amp;nbsp; Thanks for the clarification. It is helpful!&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 31 Jul 2018 14:27:14 GMT</pubDate>
      <guid>https://connect.hyland.com/t5/alfresco-forum/local-user-ad-user-sync-deletion/m-p/78055#M24463</guid>
      <dc:creator>muthu_domain</dc:creator>
      <dc:date>2018-07-31T14:27:14Z</dc:date>
    </item>
  </channel>
</rss>

