Solved

Sharepoint Import User & Profiles

Posted on 2011-03-02
5
471 Views
Last Modified: 2012-05-11
Hi guys,

I would like to know if correctly. I'm trying to correct my connection with AD.  I already have the connection to AD but in the "User filter:" I would like to know if it's ok this query to exclude all disabled accounts and users start with "s-" because all users started with "s-" is a Service Accounts.

Exclude accounts that start with s-
(&(objectCategory=Person)(objectClass=User)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(!(!givenName=s-*)))

Also I would like to know a best practice to syncronize the import schedule (Full & Incremental) for a Big Farm.

I supose this:
1- Full Every 1 Month
1- Incremental Every 1 Week.

It's OK?.

Is Sharepoint 2007.

Thanks in advance,
0
Comment
Question by:Gonzalo Becerra
  • 2
  • 2
5 Comments
 
LVL 9

Assisted Solution

by:Ivan Padabed
Ivan Padabed earned 200 total points
ID: 35023350
generally OK. although I would do incremental sync once a day (night). But it depends on farm load and operation time for your particular environment
0
 
LVL 1

Author Comment

by:Gonzalo Becerra
ID: 35025671
My query to import enabled account and exclude all account starting with s- it's ok?

0
 
LVL 38

Accepted Solution

by:
Justin Smith earned 300 total points
ID: 35025989
I'm thinking it should be:

(&(objectCategory=Person)(objectClass=User)(!userAccountControl:1.2.840.113556.1.4.803:=2)(!givenName=s-*))


I'll agree with Ivan about daily imports.....but yes it does really depened on your environment.  My current client is modifying AD users daily, so that needs to be reflected in SP daily.
0
 
LVL 1

Author Comment

by:Gonzalo Becerra
ID: 35026375
We need syncrinize about 190000 users. I think one increment per week and 1 full per month.

Actually we don't have configured incremental or full is not sincronizing now.

Which is the correct?.

(&(objectCategory=Person)(objectClass=User)(!userAccountControl:1.2.840.113556.1.4.803:=2)(!givenName=s-*))

This correct?
(&(objectCategory=Person)(objectClass=User)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(!(!givenName=s-*)))
0
 
LVL 38

Expert Comment

by:Justin Smith
ID: 35026479
You could try both, and see if either work.
0

Featured Post

Networking for the Cloud Era

Join Microsoft and Riverbed for a discussion and demonstration of enhancements to SteelConnect:
-One-click orchestration and cloud connectivity in Azure environments
-Tight integration of SD-WAN and WAN optimization capabilities
-Scalability and resiliency equal to a data center

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

A phishing scam that claims a recipient’s credit card details have been “suspended” is the latest trend in spoof emails.
In-place Upgrading Dirsync to Azure AD Connect
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
Microsoft Active Directory, the widely used IT infrastructure, is known for its high risk of credential theft. The best way to test your Active Directory’s vulnerabilities to pass-the-ticket, pass-the-hash, privilege escalation, and malware attacks …

839 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question