Solved

Sharepoint Import User & Profiles

Posted on 2011-03-02
5
464 Views
Last Modified: 2012-05-11
Hi guys,

I would like to know if correctly. I'm trying to correct my connection with AD.  I already have the connection to AD but in the "User filter:" I would like to know if it's ok this query to exclude all disabled accounts and users start with "s-" because all users started with "s-" is a Service Accounts.

Exclude accounts that start with s-
(&(objectCategory=Person)(objectClass=User)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(!(!givenName=s-*)))

Also I would like to know a best practice to syncronize the import schedule (Full & Incremental) for a Big Farm.

I supose this:
1- Full Every 1 Month
1- Incremental Every 1 Week.

It's OK?.

Is Sharepoint 2007.

Thanks in advance,
0
Comment
Question by:Gonzalo Becerra
  • 2
  • 2
5 Comments
 
LVL 9

Assisted Solution

by:Ivan Padabed
Ivan Padabed earned 200 total points
Comment Utility
generally OK. although I would do incremental sync once a day (night). But it depends on farm load and operation time for your particular environment
0
 
LVL 1

Author Comment

by:Gonzalo Becerra
Comment Utility
My query to import enabled account and exclude all account starting with s- it's ok?

0
 
LVL 38

Accepted Solution

by:
Justin Smith earned 300 total points
Comment Utility
I'm thinking it should be:

(&(objectCategory=Person)(objectClass=User)(!userAccountControl:1.2.840.113556.1.4.803:=2)(!givenName=s-*))


I'll agree with Ivan about daily imports.....but yes it does really depened on your environment.  My current client is modifying AD users daily, so that needs to be reflected in SP daily.
0
 
LVL 1

Author Comment

by:Gonzalo Becerra
Comment Utility
We need syncrinize about 190000 users. I think one increment per week and 1 full per month.

Actually we don't have configured incremental or full is not sincronizing now.

Which is the correct?.

(&(objectCategory=Person)(objectClass=User)(!userAccountControl:1.2.840.113556.1.4.803:=2)(!givenName=s-*))

This correct?
(&(objectCategory=Person)(objectClass=User)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(!(!givenName=s-*)))
0
 
LVL 38

Expert Comment

by:Justin Smith
Comment Utility
You could try both, and see if either work.
0

Featured Post

Free Trending Threat Insights Every Day

Enhance your security with threat intelligence from the web. Get trending threat insights on hackers, exploits, and suspicious IP addresses delivered to your inbox with our free Cyber Daily.

Join & Write a Comment

Resolve DNS query failed errors for Exchange
Disabling the Directory Sync Service Account in Office 365 will stop directory synchronization from working.
This tutorial will walk an individual through the process of transferring the five major, necessary Active Directory Roles, commonly referred to as the FSMO roles from a Windows Server 2008 domain controller to a Windows Server 2012 domain controlle…
This tutorial will walk an individual through the process of configuring their Windows Server 2012 domain controller to synchronize its time with a trusted, external resource. Use Google, Bing, or other preferred search engine to locate trusted NTP …

763 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

6 Experts available now in Live!

Get 1:1 Help Now