Jump to content

Recommended Posts

Posted

We currently have GAFE with a VLE plonked on top - the VLE uses its own synch tools to pull data from our MIS to create/synch users etc.

 

However we wish to change this, to seperate the VLE and use GADS to pull data straight from our AD servers - all good in theory but I'm wondering if it will cope with the existing users in GAFE, as the usernames (i.e AD logins) are the same. So anyone whose account was created using the prior VLE synch should keep their same account, but the password would synch with their AD account rather than the vle generated one.

 

With me not being very familiar with GADS, does that sound feasible to anyone who has done anything like this?

Posted
Personally not done it, but I believe it syncs using the e-mail attribute in AD, so I guess if the email addresses in AD match the GAPPS account it should be fine
  • Thanks 1
Posted

I have done this twice recently, one with RealSmart, if you're using this :).

 

Any accounts where the username on AD machines on Google Apps it will simply update the account with the AD details. Any accounts not found in AD where put into a suspended state. They can be easy restored. If the usernames in AD don't match Google apps they are put into a suspended state and a new account is created with the usernames from AD. They can be easy restored by deleting the new account, renaming the username on the old to match AD and re-syncing. This will match it up with the AD user.

 

Delete all your old groups first before you sync with your AD groups. I suggest you use GAM to do this. Also When you sync all these groups again they will take a while for them to appear for the end user.

 

Thanks

  • Thanks 2
Posted

This answers some questions I had so thanks!

If their Google account is synced with AD, does this mean that any password resets will have to be done in AD as well or can it still be changed through Google Admin?

Posted
You can just use google apps password sync for that, just run on each DC and it will sync the passwords with the google accounts

 

Alternatively you can setup some find of SAML SSO like Active Directory Federated Services. We do it this way so we have SSO between a range of products. Once you are signed into one service you do not need to sign into the others.

Posted
I have done this twice recently, one with RealSmart, if you're using this :).

 

Any accounts where the username on AD machines on Google Apps it will simply update the account with the AD details. Any accounts not found in AD where put into a suspended state. They can be easy restored. If the usernames in AD don't match Google apps they are put into a suspended state and a new account is created with the usernames from AD. They can be easy restored by deleting the new account, renaming the username on the old to match AD and re-syncing. This will match it up with the AD user.

 

Delete all your old groups first before you sync with your AD groups. I suggest you use GAM to do this. Also When you sync all these groups again they will take a while for them to appear for the end user.

 

Thanks

 

Perfect, that's what I was hoping someone would say!:)

Posted

Has anyone got a recent guide on how they set this up?

 

One thing I've noticed is that GADS seems to use the AD mail attribute which we don't have set at the moment. Basically I want a very simple synch of all user login's and all groups from two OU's!

Posted
Has anyone got a recent guide on how they set this up?

 

One thing I've noticed is that GADS seems to use the AD mail attribute which we don't have set at the moment. Basically I want a very simple synch of all user login's and all groups from two OU's!

 

Whilst this isn't recent it still applies, tried and tested recently -

 

Do you have your full UPN matching your users email address?

 

Also if you have Salamander they will be able to populate the email field for you.

Posted (edited)

We have the UPN set to our original domain name, the GAFE is our new domain name - just to complicate things!

 

I guess if I can sort out a script I could set the users mail attribute to the userlogin@newdomainname format and then GADS would work as normal.

 

Actually, I wonder if you can enter a custom entry in the Email Address Attribute in GADS? something like sAMAccountName & "@newdomain.com"

Edited by Sheridan
Posted

I've managed to change the mail attribute for everyone now so I get a good synch test result!

 

Only couple of issues I know will crop up are:

 

1) User title isn't in AD, so Mrs Smith will appear as Julie Smith etc - some might not like that!

2) We will lose the class sets groups from our current MIS, as the AD groups are manually created and don't pull from it. I know theres a Schools version of GADS, but that seems to involved exporting csvs and I want to make this as simple as possible!

 

Other than that, so far so good!

Posted

1) Staff use full names here. If you have Salamader you might be able to populate that if you have it. If not might be a manual job.

2) Again Salamander will solve this issue and can create the AD groups automatically and then GADS will sync them.

  • Thanks 1
Posted

Ditto, ditto and ditto. :)

 

Using FN-GM's advice earlier in the year, we moved away from Realsmart this summer, and now use a combination of GADS, GAPS and SalamanderSoft.

 

Peter

Posted
Same here but we don't use password sync, we use ADFS instead.

 

Should have said, we also implemented ADFS (with your guidance) - but it doesn't cover all scenarios.

 

If users just browse to drive.google.com it doesn't SSO them, so they still need their Google password to be set.

 

Peter

Posted
If users just browse to drive.google.com it doesn't SSO them, so they still need their Google password to be set.

 

If someone goes to drive.google.com/a/domain.com - it signs them in automatically

If you go to drive.google.com then type the email in it will redirect to ADFS and automatically sign in.

 

Sounds like something isn't configured correct on your setup.

Posted
If you go to drive.google.com then type the email in it will redirect to ADFS and automatically sign in.

Mine doesn't - but I now suspect that's because I'm super-admin on GAFE.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...