fiza Posted May 5, 2015 Posted May 5, 2015 We have got a Google Apps domain where we originally created users with CSV files. For next year we want to utilise GADS so that any changes in Active Directory are reflected in GAFE. I have played a little with gads with a test domain but I don't know what effect it would have on an already populated Google domain. If the email addresses in AD match those in Google will it then match those accounts or try to create new ones?
robjduk Posted May 5, 2015 Posted May 5, 2015 Only a guess but I would imagine it would error out and not create the AD user's account. You should be able to test this if you point GADS towards a test OU.
caffrey Posted May 5, 2015 Posted May 5, 2015 You can always simulate sync to test, it should come back with errors etc.
robjduk Posted May 5, 2015 Posted May 5, 2015 You can always simulate sync to test, it should come back with errors etc. or you could just do that......
InterwebsGuy Posted May 6, 2015 Posted May 6, 2015 (edited) It doesn't error out. It updates existing accounts with some kind of identifier, presumably so it can easily identify it in GADS' local records for sync purposes. If the user's name or other parameters that you have populated in Google Apps have changed, and you set GADS to populate these parameters in Google Apps from AD records, it will update them to reflect the AD accounts. Just be cautions with GADS and exclude any accounts you may not want to sync to Google Apps, and perhaps more importantly, exclude any Google accounts that may exist in Google Apps that don't exist in AD that you want to keep. If you don't exclude them, in the case of the latter, GADS will delete them! Edited May 6, 2015 by InterwebsGuy 1
fiza Posted May 6, 2015 Author Posted May 6, 2015 (edited) It doesn't error out. It updates existing accounts with some kind of identifier, presumably so it can easily identify it in GADS' local records for sync purposes. If the user's name or other parameters that you have populated in Google Apps have changed, and you set GADS to populate these parameters in Google Apps from AD records, it will update them to reflect the AD accounts. Just be cautions with GADS and exclude any accounts you may not want to sync to Google Apps, and perhaps more importantly, exclude any Google accounts that may exist in Google Apps that don't exist in AD that you want to keep. If you don't exclude them, in the case of the latter, GADS will delete them! I am trying to exclude certain OUs and users within from syncing but the OUs still get created. I want certain ones created but others ignored. I have put an exclusion in "Org Units" as ; Exclude Type : Org Unit DN Match Type : Exact Match Exclusion Rule : OU=Staff,OU=school users,DC=domain,DC=school,DC=borough,DC=sch,DC=uk Edited May 6, 2015 by fiza
InterwebsGuy Posted May 6, 2015 Posted May 6, 2015 I am trying to exclude certain OUs and users within from syncing but the OUs still get created. I want certain ones created but others ignored. I have put an exclusion in "Org Units" as ; Exclude Type : Org Unit DN Match Type : Exact Match Exclusion Rule : OU=Staff,OU=school users,DC=domain,DC=school,DC=borough,DC=sch,DC=uk I assume you've put this exclusion in the Org Units section of GADS? If so, I think you will probably have to do an exclusion of some kind in the User Accounts section too. I never tried to exclude an OU per se, as the way you are trying to do, we were just very explicit in which OUs and users we synced (based on a security group membership), so that's a little guess work on my part from what I know about GADS.
fiza Posted May 6, 2015 Author Posted May 6, 2015 The exclusion is in the Org Units section. I haven't put anything in the Users exclusion as what I am doing is ; any users I don't want synced I am making sure they don't have an email address assigned in AD and that way GADS ignores them. Its the OUs that get created in Google that I don't want. My AD structure is; Users ....staff ....students ........year7 ........year8 ........ year9 ........ year10 ........ year11 ........year12 ........year13 ........test ........staleACs I want to ignore test and staleACs by putting them in as exclusions in GADs but they still get created.
InterwebsGuy Posted May 6, 2015 Posted May 6, 2015 The exclusion is in the Org Units section. I haven't put anything in the Users exclusion as what I am doing is ; any users I don't want synced I am making sure they don't have an email address assigned in AD and that way GADS ignores them. Its the OUs that get created in Google that I don't want. My AD structure is; Users ....staff ....students ........year7 ........year8 ........ year9 ........ year10 ........ year11 ........year12 ........year13 ........test ........staleACs I want to ignore test and staleACs by putting them in as exclusions in GADs but they still get created. Well, that's one way to stop an account being synced! I can't imagine why it would be syncing all your OUs automatically, I remember having to state each OU manually. Are you trying to sync the root Users OU? Either way, I'd expect you should be able to exclude any sub-OUs in Users by the way you are doing it. I'm not sure I can help much more, as it's not something I've tried. :-) 1
fiza Posted May 6, 2015 Author Posted May 6, 2015 @enjay @caffery - as users of GADS (I gleaned this from some other threads) do either of you know why my Org Unit exclusions aren't working ? any pointers would be appreciated.
fiza Posted May 6, 2015 Author Posted May 6, 2015 I think my issue may be that the OU I want to exclude has sub-OUs inside it. GADS doesn't seem to like that. I can exclude one of the sub OUs and that seems to work.
InterwebsGuy Posted May 6, 2015 Posted May 6, 2015 I think my issue may be that the OU I want to exclude has sub-OUs inside it. GADS doesn't seem to like that. I can exclude one of the sub OUs and that seems to work. It could be. I've noticed it doesn't like nested security groups (much to my frustration), so it stands to reason it might not like sub-OUs.
fiza Posted May 6, 2015 Author Posted May 6, 2015 It could be. I've noticed it doesn't like nested security groups (much to my frustration), so it stands to reason it might not like sub-OUs. Just added all the Sub OUs into the exclusions and now its working!!!
InterwebsGuy Posted May 6, 2015 Posted May 6, 2015 Just added all the Sub OUs into the exclusions and now its working!!! Good to hear!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now