Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

Howdy, I think I'm being a duh-duh kind of idiot here

 

We have an OU structure like this

 

OU=KS-Users,DC=camelot,DC=local

 

Within KS-Users we have KS-Administrators, KS-Staff, KS-Pupils blahblahblah. We have a KS-Parents one in there that we really don't need to sync. I've setup (or at least think I have) an exclusion rule in the 'Org Units' tab then all the parents (about 500 of them) are syncing to the root OU instead.

 

Again I'm sure I'm being stupid, but what on Earth am I doing wrong?

Posted (edited)

Do you have Exclusion Type ORGUNIT_DN Match type EXACT and the Rule is your OU path ?

 

*edit*

 

you can get the proper path by right clicking the OU container in AD users and computers, attribute editor and use the distinguishedName attribute (just click edit then copy and paste into GADS)

Edited by caffrey
Posted
Just checked and yup, path is definitely correct! But like I say instead of excluding the OU altogether it puts them all in our GAPPS root OU. Have I got to add an exclusion rule alongside each tab ie GAPPS Configurarion/Org Units/User Accounts/Groups/User Profiles etc?
Posted

No, it should be just the Org units - typical exclusion rules looks like this :-

 

rules.jpg

 

Example here excludes the movie OU we have

 

You can also have exclusion rules inder the google apps configuration, this excludes OUs that are created in the GAFE admin panel that aren't related to your local domain.

 

Other than that - it should work - nothing in the logs ?

rules.png

Posted
Odd, I think I had similar issues until I got the LDAP path correct, is your base DN set correctly under LDAP Configuration ? e.g. ours is "OU=Network Users,OU="your ou" Top Level OU,DC="your DC"
Posted (edited)

Strange then, I remember having similar issues back in the day when I first set it up about 2 years ago, now it's set up I'm scared to touch it!

 

Seems odd that your's just says "KS-Parents" whereas ours says "Delete Organization(s) - 1 total "***/*** Top Level OU/Network Users/Staff Users/Test Staff OU" eg has the OU path

 

*edit*

 

Do you have the LDAP org unit mappings set ? and the search rules ?

Edited by caffrey
Posted
That's not how ours is set up, the org unit description attribute is "description" not "name" BaseDN like yours is blank, in the mappings I don't use "" I use different google apps names (e.g. Student users) to keep staff and students apart e.g LDAP DN :OU=Student Users,OU=Network Users,OU=*** Top Level OU,DC=*** Google apps name - Student Users
Posted

You can exclude the OU from being created, you cannot exclude the users within being created with this rule

 

User Search Rules

 

"

Note: You cannot create an LDAP rule to exclude a specific OU in your LDAP directory. Instead, limit the LDAP administrator authority on your LDAP directory server, removing access to any OUs on your LDAP directory server that you do not want to synchronize."

Posted

You can, and it will exclude the OU object. The user accounts are created with user search, which selects all users that can be seen from the search root with the specified filter. It does not use the OU criteria for this.

 

OUs creates OUs based on the filter

Users on User filter

Groups on groups filter.

 

The processes aren't linked in any way, because Google are Google and management tools aren't exciting to make. I've spent some time on this before I found the note, and the only way to stop the user creation from an OU below the root of the search is to deny access to the objects in AD from the GADS user.

Posted (edited)

The parents mail attribute is their own personal email address, the whole reason we have KS-Parents really is to do with our VLE. Just totally forgotten now it might be a Groups thing, we have a KS-Sec-Parents security group along with the others.

 

edit: actually no thats fine, that security group doesn't have a mail attribute

Edited by rickjames
Posted

CRACKED IT, or so I think. Had to sort the search rules out in user accounts so its only allows users with our email address, so (&(objectCategory=person)(objectClass=user)(mail=*knightsbridgeschool.com*))

 

Run a simulated sync and it deletes all the users ie parents without it, so happy days (maybe)

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...