Solved

Duplicate 'name' attribute in Active Directory

Posted on 2009-07-08
1
2,209 Views
Last Modified: 2012-05-07
We have run into an issue where multiple names (e.g., John Smith) appear in the same Organizational Unit in Active Directory.  While other attributes like samaccountname, employeeid and others are unique, we find that Active Directory will not allow for a duplicate 'name' attribute.  Is this because CN derives by name by default?  Or, is there a workaround?

We ponder appending some unique value to the end of name (e.g., John Smith [jsmith01]).  However, I wanted to throw this question out there to see what other feedback I can get.  From what I have read, it seems like while you cannot have duplicate 'name' attribute values in the same Organizational Unit, you can have the same name in Active Directory in another OU.  Mainly, I was just wondering what others have done because I suspect it must be common for large directories with many users in OUs to have similar run ins with multiple John Smith names (or other common names).
0
Comment
Question by:CecilAdmin
1 Comment
 
LVL 70

Accepted Solution

by:
Chris Dent earned 500 total points
ID: 24803364
>  Is this because CN derives by name by default?

Yes. Every CN must be unique within the same container to meet the constraint that every Distinguished Name (DN) must be unique.

I'm afraid there's no way around that aside from changing the value for CN (also known as the Relative DN, RDN).

This is a limitation of LDAP rather than something unique to AD.

Whenever I've bumped into this in the past either the givenName is changed to a short version, if applicable. Or a middle initial is inserted, again if applicable.

Chris
0

Join & Write a Comment

Do you have users whose passwords are expiring and they are constantly calling you?  Well I sure did and needed a way to put an end to this.  We have a lot of remote users which would not be notified that their passwords were expiring since they wer…
Is your Office 365 signature not working the way you want it to? Are signature updates taking up too much of your time? Let's run through the most common problems that an IT administrator can encounter when dealing with Office 365 email signatures.
This tutorial will walk an individual through the steps necessary to join and promote the first Windows Server 2012 domain controller into an Active Directory environment running on Windows Server 2008. Determine the location of the FSMO roles by lo…
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles to another domain controller. Log onto the new domain controller with a user account t…

759 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

20 Experts available now in Live!

Get 1:1 Help Now