Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×
  • entries
    60
  • comments
    63
  • views
    837

Matching sims to active directory


Although it's been on my mind for years, there was no outside pressure to match sims users to active directory, so I never got round to it. Even though most users were created from sims, there's tonnes of inconsistencies due to altering the creation process in past years, kids that turn up without accounts, kids that have left the school etc.

 

The most recent moodle coordinator is much more IT literate than past ones and there's pressure from above to be able to do something that requires connections. They want to be able to match user accounts to moodle reports to free school meals type data. I think they need the user data to be able to identify moodle users. I don't entirely understand it. I don't need to know that bit. All I have to do is make users matchable to sims.

 

The easiest way to do this foolproof is to insert the admission numbers into the office field of active directory. Then I can just export a csv file from ad and the moodle guy will use it as a lookup table in his access database.

 

to insert data get a csv from sims containing name, admission number

 

for /f "delims=, tokens=1,2" %%a in ('type admission_numbers.csv') do dsmod user "cn=%%a,ou=pupils,dc=school,dc=county,dc=sch,dc=uk" -office "%%b"  

 

this will match the user by name, overwrite the office field and wont error quit if you run it multiple times.

 

However there's another problem.

The container (CN) is the field "disguished name" or the name column in active directory users and computers. Many older users have their username in this field not their name.

 

So now I need to rewrite dn field with their full names.

Enter a program called "ldifde" that does that kind of thing.

But its not command line orientated. It uses a data file called something.ldf

So I have to write a script to write the data file

 

Export a csv from active directory users and computers that contains name,username

 

const ForReading = 1
const ForAppending = 8
const ForWriting = 2


inputfile="addn.csv"
outputfile="import.ldf"

'open data .csv file
set fso = CreateObject("Scripting.FIleSystemObject")
set ts = fso.OpenTextFile(inputfile, ForReading)

set rs = fso.opentextfile(outputfile, ForWriting,true)

'while not end of file read a line
Do While ts.AtEndOfStream <> True
sstring=ts.readline
pupilrec=split(sstring,",")
fullname = pupilrec(0)
currentdn = pupilrec(1)

rs.writeline "dn: CN=" & currentdn & ",ou=pupils,dc=school,dc=county,dc=sch,dc=uk"
rs.writeline "changeType: modrdn"
rs.writeline "newrdn: cn=" & fullname & ",ou=pupils,dc=school,dc=county,dc=sch,dc=uk"
rs.writeline "deleteOldRdn: 1"
rs.writeline 


loop

 

That gives me a massive file of change orders. Running it a bit at a time. Scared of the law of unexpected consequences breaking all the users.

 

c:\>ldifde -i -f part1.ldf -j log -k

 

-k to ignore errors (or it will error quit)

 

then rerunning the dsmod batch file. Will be done tomorrow. Then I can start thinking up ways where being able to identify sets of students might be useful.

 

Turns out I needed to have the moodle logins in the csv file too. Typically the moodle logins are not consistent with network logins. Year 7 and Year 8 are but not the rest. They're how we aspire to have all our logins. Fortunately it's not too hard to construct moodle logins from existing data. So I made another csv with the moodle usernames and used dsmod as above to insert them into the "business phone" field.

 

Then set up all the necessary columns in active directory users and computers and export the perfect CSV file.

Edited by browolf

0 Comments


Recommended Comments

There are no comments to display.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...