User Account Issue
I have a very strange one that I am struggling to get my head around. We are using PaperCut to monitor printing and pick all users up from a group, nothing strange here, all working ok.
However, just recently we have been having some users being “removed” from PaperCut even though they have not been removed from AD. After a bit of digging and working with PaperCut, we have found the following:
When a user has been “removed” from PaperCut, if we looked at the group membership in AD, the user was still in there, however if we looked at the group membership in LDAP, the user had been removed. Re-adding the user and re-syncing in PaperCut put the user back in.
Has anyone else seen this or something similar where a user is in a group in AD but not in LDAP?
I have posted some pictures as well that show this better:
LDAP shows that the user, Andrew Davies in this case, is not showing in the group: SIMSGroup
AD shows that Andrew Davies is in the group.
LDAP2 shows that he is back in the group again, but this was after removing him from the group via AD and re-adding him.
I hope someone with a bit more knowledge of AD than me can help on this as I, and PaperCut, are stumped!
Attachment 20583Attachment 20584Attachment 20585
To me there are to possibilities -
Either your servers aren't replicating properly, hence that's why users appear to be disappearing. I presume Papercut regularly 'checks in' to one or more of your servers for updated user info. Secondly, are you using a strong password to login to Papercut itself? The built in user account which isn't linked to AD.
I have just tested the replication and all is running as expected. We have 1 PDC and 4 other DCs in the forest and communications are all fine.
I dont think the issue is with the password as we have not had any issues for over 12 months and not changed anything on the forest and everything has worked fine up to this point.
Unless your users are changing regularly, is there any way to stop Papercut using LDAP to obtain new users temporarily?
My PaperCut is set to use Windows AD and not PaperCut..... thats the confusing thing!
Sorry if I'm not being clear - Papercut uses LDAP to read users from Active Directory, so I can only presume this is automated/scheduled once every few hours or 24 hours etc... there must be a way to temporarily disable this in Papercut. This'll allow you to determine if the problem is with Papercut itself or AD.
Thats what I am say, my PaperCut is set to take its information from Windows Active Directory not LDAP. Windows Active Directory is the selected method of adding users in.
PaperCut wouldn't remove a user from its Users tab unless you manually tell it to, seems odd they are being automatically removed.