Jump to content

Recommended Posts

Posted

Hi,

 

I have started using the Azure connector with Office 365 which works pretty well (almost there M$... just copy Google a bit more) but for some reason the syncing is doing all the Ou's to the cloud and I really don't want all my controlled assessment accounts up there.

 

I have found an article which I think was for the previous version and changed the settings using the MIISCLIENT.EXE program in management agent > AD Connector > Configure Directory Partitions > Containers and just selected the staff OU to start with but its still syncing all the accounts and I am getting errors sent to m about the sync not working properly for these kids accounts.

 

I went in and disabled the AD connector online and deleted all the kids accounts and tried again but they uploaded the kids accounts again.

 

Is this the correct way to sync certain OU's? I have read somewhere that they want you to sync your whole org but that's a bit useless unless they start allowing us to create nice groups online to sort them out (Google again)

Posted

That's exactly how I followed my setup but its still syncing other OU's that I told it not to.

 

If the account is not in the OU anymore that gets synced should it get put in the deleted users bit?

 

The results of the upload are a bit confusing

 

Synchronization Satitics

Unchanged 165 (staff I believe)

Add 0

Updates 0

Renames 0

Deletes 1844

 

Its just a bit confusing as I deleted everyone other than staff off the cloud last night and the first sync they have come back… but this is now saying its deleting them. I wonder if it took them out of deleted users and put them back in the main bit as the users are set for deleting after 30 days??

Posted
(almost there M$... just copy Google a bit more)

 

:nono:

 

Is this the correct way to sync certain OU's? I have read somewhere that they want you to sync your whole org but that's a bit useless unless they start allowing us to create nice groups online to sort them out (Google again)

 

Did you perform a full sync afterwards? Take a look at this post: Installing and Configure DirSync with OU level filtering for Office365 - Denotation - Site Home - MSDN Blogs

Posted (edited)
:nono:

 

Copying it the wrong word sorry, but you are playing catchup. It would be nice to be able to put the uploaded users into groups for easy filtering, only allowing 20 users per page is a pain as it took me ages to delete them yesterday.

 

As for the DIRSYNC, I have doen a full sync and here is a screenie of my filtering. I must be missing something obvious here.

 

azure.jpg

Edited by Simcfc73
Posted
It would be nice to be able to put the uploaded users into groups for easy filtering, only allowing 20 users per page is a pain as it took me ages to delete them yesterday.

 

The GUI is great for so, so many things. However, it's not particularly efficient for doing things for large numbers of users, or a large number of times in repetition. Windows Remote PowerShell is a much, much better method of managing more than a handful of users; offering you the ability to make far-reaching config changes in literally one or two lines of cmdlets.

 

Google's approach might be more browser-based, and that's fine, but I don't think they have anything that even comes within a country mile of PowerShell. :)

 

As for the DIRSYNC, I have doen a full sync and here is a screenie of my filtering. I must be missing something obvious here.

 

[ATTACH=CONFIG]21947[/ATTACH]

 

You've got a couple of options. Start again by reinstalling DirSync. Phone support. Or lastly, get a partner to help you.

 

How did you trigger a full sync?

Posted

It a new install on a different server, I had ADFS on a different one and it went belly up when I changed password so I reinstalled it fresh. I did a full sync with the right click run now, I will try with the powershell command next.

 

I just added a attribute field now so will see if that works.

Posted

Boooo and as if by magic its done it and I don't know what I did wrong/right.

 

Looking at the operations log the Windows Azure Active Directory export Export hadn't run since 8.30 even though I thought I was forcing it to which is weird.

 

So my question is, when you right click on the AD connector and do a Full Import Full Sync is doesn't do a upload to the cloud, you have to do a right click Azure then Export.... is this right as its the way its forcing a sync on mine but there's no documentation saying this.

Posted
So my question is, when you right click on the AD connector and do a Full Import Full Sync is doesn't do a upload to the cloud, you have to do a right click Azure then Export.... is this right as its the way its forcing a sync on mine but there's no documentation saying this.

 

No, you should not run them one by one like that. Use the PowerShell script.

 

Synchronize your directories

Posted

Okay thanks for the help, just going through and adding the attribute so it doesn't sync everyone.

 

Don't mean to be overly negative and pro google.. I don't particularly like there stuff either it just some of there features are really good.. and I despair at having to use Powershell scripts to accomplish simple tasks, I have enough swimming in my head without having to remember strings of code.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...