Jump to content

Recommended Posts

Posted

Finally getting around to syncing groups with GCDS. All great.

But a limitation is if you have created a manual group in Google. It won't remove users that are in the group but not in your AD.

 

For groups that users or administrators created using the Google Groups app, it doesn’t delete:

 

These groups, if they don’t exist on your LDAP server

Members that exist in the group, but not on your LDAP server

 

 

Anyone know of a way to make GCDS think it created the Google groups. How does GCDS store that it created the group.

Can't recreate all groups as they are already in use on different things. Anyone any ideas?

Posted

Don't know of any way for GCDS to 'adopt' groups like that. I suspect there'll be some group IDs tucked away in whatever local database GCDS utilises.

 

Does GCDS add new members to those groups? If so, you can empty them and let GCDS go from there.

 

If it doesn't do anything with them at all, I suppose you could rename the existing groups with suffix of ".legacy" or something, create new versions of them via GCDS and manually add the new groups into their respective legacy groups (removing any existing manually added members, so that the legacy groups only contain their corresponding new groups).

 

You can then use gam to hide the legacy groups from the directory, which will help you to phase them out. Also, you'd want to prevent anyone from adding members to the legacy groups.

  • Thanks 1
Posted

Yeah it adds staff fine. Just never removes. Even if GCDS has added the group member during a sync.

Yeah I wondered where it stored the information. If we moved GCDS to another server. I guess that would need migrating or all groups would be one way sync again. Wasn't sure if there was a flag within the google group that was set. I've looked with GAM and can't find anything though.

Group within a group isn't a bad idea to begin with though.

Posted

That's weird. I would expect it to manage the group okay, assuming that the group address matches. In the past, when I've changed a group address in AD, GCDS has created a new group rather than updating the address of the original group.

 

With users, GCDS makes use of GUIDs to link LDAP users to Google users (so that changing someone's address doesn't result in a new account being created), but that doesn't appear to be the case with groups, which is why I'd expect it to manage the group okay if the address matches exactly.

  • 2 weeks later...
Posted (edited)

Came here to post this same issue, driving me mad. Used https://toolbox.googleapps.com/apps/loganalyzer/ and everything checks out fine. Ad used, matched by mail, is added to Google Group, but remove them from AD and run the sync, they're never removed.

 

I'll try removing this group in Google and letting GCDS recreate it. I suspect doing so is going to cause email issues with people's directory results though?

 

EDIT: after more testing, this issue is limited to some groups, and not others. Need to look at group permissions, however I was pretty thorough with keeping them consistent...

Edited by Planehazza
Posted
It does tell you that it only syncs if GCDS creates the groups. Was just hoping there was a way around it as already setup all my groups. I’m using groups for shared drive permissions too so a pain to recreate
  • 1 year later...
Posted (edited)

Slight change of subject, and bit of a thread necro...

 

Anyone know how to make GCDS honour group email changes? I want to change email group OLD-AllStaff to NEW-AllStaff, and have I updated the LDAP group search rules, but instead of amending the existing group in Google (like it would a user object) it's just treating NEW-AllStaff as new group and creating it.

 

It doesn't seem to link groups with immutable IDs like it does users, so I'm fearing the answer is "you can't". 

 

I can just use GAM to rename them all in Google and then make the same changes in Google with sync temporarily disabled, but I was hoping for a more standard GCDS approach.

Edited by Planehazza
Posted

I think that used to be the case, but GCDS was updated recently to make this a bit easier. It still doesn't used a GUID to link AD groups to Google groups (as it does for users).

 

If you update the AD group's mail attribute, and then manually update the Google group's email attribute (either in Google Admin or in Google Groups) to match exactly, and then run GCDS with the flush cache option, it should behave and sync the group as required, without creating a new one.

 

When you change the group address in Google Admin/Groups, the old address is added as an alias (similar to how it would when changing a user's primary email address), so if you definitely don't want the old group address to hang around you'll want to remove it from there as well.

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...