Jump to content

Checking GADS settings for custom OUs \ Search Rules


Recommended Posts

Posted (edited)

Hi all, just set up GADS today to populate our Google Apps domain, would anyone be able to spare a few minutes to sanity check my config?

 

Been using this as reference along with the Google documentation (which isn't that great and has dead links)

 

Gappsconnect Blog. : Introduction to Google Apps Directory Sync (GADS) by example - a beginners guide

 

I have 3 OUs I want to sync within my specified base DN (there's 5 OUs in there I don't want).

The structure is as below (using different names to my live environment)

 

I want to sync FIRSTOU, SECONDOU, THIRDOU but not any of the others.

 

USERS

- FIRSTOU

- SECONDOU

- THIRDOU

- UNWANTEDOU

- UNWANTEDOU2

 

Org Units

 

  • Set up 3 mappings in LDAP Org Unit Mappings so the long LDAP DN maps to a simpler Google Org Unit Name
  • Set up 3 search rules using LDAP query (&(objectCategory=organizationalUnit)(Name=FIRSTOU)) to specifically pick the OUs to sync
  • No Exclusion rules

User Accounts

 

  • Unique Identifier Attribute set to objectGUID
  • Don't suspend existing users not found in LDAP (I have a couple of manual users in GAfE I don't want to remove)
  • Create two search rules for each OU using Base DN to specify the location each time: one rule to sync active users and the other to suspend those with the Account Disabled checkbox set in AD as per article above
  • "Do not sync if the suspensions would exceed..." exclusion rules will need to be temporarily increased on initial sync

I'm not syncing groups (yet) but if I do it'll be via the same Search Rules method to specify the exact groups I want to sync into GAfE, or an OU if it comes to needing that many.

 

It seems to be working fine using the simulation and log file, users going into the correct Org and disabled accounts being marked as suspended.

Anything else to watch out for before I hit the trigger? Passwords will be using GAPS but for the time being we're piloting so will just reset users as we go along to get it going.

 

Manual account exclusions

 

Looks like I may need one more Org unit manually created in GAfE for any non-LDAP accounts we want to use, then add that as an Exclusion Rule in Google Apps Configuration as well?

Edited by gshaw

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...