?
Solved

Virtual OU/Query-Based OU/Active Directory View possible?

Posted on 2006-07-24
9
Medium Priority
?
1,570 Views
Last Modified: 2008-05-30
We have an Active Directory setup in which we use OUs to seperate our hundreds of users by department in a heirarchial structure. This works great for most applications, but we have a new one coming down the pike called Powerschool which, while it knows how to look up auth info from AD, doesn't know how to do it with search scope=sub, so it seems to require all of our users to be in the same OU. Because we actually use our AD in a specific structure for OU-based policies and that sort of thing, it's not possible for us to move the user accounts into a single OU.

Is it possible to have a single OU whose contents are dynamically updated by an LDAP query?  I'm thinking along the lines of a database view, or even to give a simpler example, the "Search Folders" found in recent versions of Outlook, Thunderbird, Mail.app, and Evolution.

If I could have all of my users in a single OU, at least for query purposes, it would be a huge step forward for us with this Powerschool project.

Thanks.
(Don't hesitate to ask for clarification, I'll be watching this entry closely all day)

--
Sam Powers (sam@rm-r.net)
Database Administrator
Jackson County SD #6, Central Point, OR
0
Comment
Question by:sd6tss
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
9 Comments
 

Author Comment

by:sd6tss
ID: 17168720
I'd like to use built in tools if possible. I understand that a "Virtual Directory Server" (External LDAP aggregator) may be one option, but that'd be my #2 choice.
0
 

Author Comment

by:sd6tss
ID: 17168854
(that is to say that if there were a virtual directory server built into AD, I'd just go ahead and use that instead of getting some other piece of software, but the more i look into it the more it seems like a virtual directory server is what i need)
0
 
LVL 4

Expert Comment

by:pmarquardt
ID: 17179154
Can you use a distribution/security group instead of an OU container for application mgt? I don't see the reason you are locked into using an OU container for this application. There are also tools available that allow you to custom create schema changes for containers to allow finite control levels on object. I am aware of Quest's tool, but I am certain others are available. Of course you already know about the external LDAP aggregator, so I guess that's a moot subject.
0
Does Powershell have you tied up in knots?

Managing Active Directory does not always have to be complicated.  If you are spending more time trying instead of doing, then it's time to look at something else. For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why

 

Author Comment

by:sd6tss
ID: 17180326
No, I can't use an exchange distribution group or an AD security group. Powerschool wants to look in a specific LDAP context for objects with a specific attribute filled out (Usually this would be uid or userPrincipalName.)

Because distribution groups and security groups contain their member users as attribute values rather than objects with subordinate DNs, you can't perform a query with your base as the security group, because no data would be returned. Sorry.

I'm working on configuring oracle virtual directory right now, I hope it works out.

(Can I give myself the points for answering the question?)
0
 
LVL 4

Expert Comment

by:pmarquardt
ID: 17184126
I think the idea is you get to keep your points.... :-)

I wish I could have been of more help to you, but I believe you are on the narrow path with this issue.

Please let me know if I can be of any help to you. I realize how frustrating it can be...
0
 

Accepted Solution

by:
ee_ai_construct earned 0 total points
ID: 17399710
Closed, 500 points refunded.
ee ai construct
Community Support Moderator
replacement part #xm34
0
 

Expert Comment

by:Hellbentmaster
ID: 33634939
In case this question is open to somebody, I've found the solution:

Now there's a tool that helps view and manage Active Directory objects collectively.
http://www.adaxes.com/tutorials_ActiveDirectoryManagement_ViewAndManageADObjectsCollectively.htm

Thanks.
0

Featured Post

Concerto's Cloud Advisory Services

Want to avoid the missteps to gaining all the benefits of the cloud? Learn more about the different assessment options from our Cloud Advisory team.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Let's recap what we learned from yesterday's Skyport Systems webinar.
Active Directory can easily get cluttered with unused service, user and computer accounts. In this article, I will show you the way I like to implement ADCleanup..
This Micro Tutorial hows how you can integrate  Mac OSX to a Windows Active Directory Domain. Apple has made it easy to allow users to bind their macs to a windows domain with relative ease. The following video show how to bind OSX Mavericks to …
Attackers love to prey on accounts that have privileges. Reducing privileged accounts and protecting privileged accounts therefore is paramount. Users, groups, and service accounts need to be protected to help protect the entire Active Directory …

719 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question