Want to win a PS4? Go Premium and enter to win our High-Tech Treats giveaway. Enter to Win

x
?
Solved

Remove an OU from DirSync in the middle of a Staged Migration

Posted on 2015-01-31
11
Medium Priority
?
171 Views
Last Modified: 2015-02-05
I have been successfully DirSync 4 thousand users during a staged migration.
I just realized there is an entire OU filled with 1200 "users" that are simply place holders for wireless users.
I am not a network guy but I recognize this a security mechanism or the like - but it does not need to be synced.

Anyway, my question is how can I exclude this OU now that it is already "Syncing"?

Thank you for your time in advance.
0
Comment
Question by:K B
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 4
  • 4
  • 3
11 Comments
 
LVL 17

Expert Comment

by:Ivan
ID: 40581940
Hi,

I don't think there is a "stop" button for this. After sync is done, you can configure exclusion for OU, export Azure AD (from dyr sync tool) and do a Full Sync Full Import, so that specified OU get's deleted from Office 365.

Regards
0
 
LVL 8

Author Comment

by:K B
ID: 40581942
Will this cause an interruption of service?
0
 
LVL 17

Expert Comment

by:Ivan
ID: 40581950
Well, I have done this few days ago and everything was working. Required users got deleted, I was logged on the entire time on office 365, Lync worked for all users..

I don't think there is any interruption, but I am not 100% sure.
0
What does it mean to be "Always On"?

Is your cloud always on? With an Always On cloud you won't have to worry about downtime for maintenance or software application code updates, ensuring that your bottom line isn't affected.

 
LVL 22

Expert Comment

by:Jakob Digranes
ID: 40582771
@spriggan13 is correct.... as long as you don't remove any users with licenses and mailboxes assigned to them - no probl
0
 
LVL 8

Author Comment

by:K B
ID: 40582818
So I don't stop DirSync in any way?

1. I configure the OU exclusions (where in DirSync)?

   2. Then Remove-MsolUser ...the users I don't want synced (& removefromrecyclebin) ?
      3. Anything else?


Thanks again!
0
 
LVL 22

Expert Comment

by:Jakob Digranes
ID: 40582852
only 1.
http://blogs.msdn.com/b/denotation/archive/2012/11/21/installing-and-configure-dirsync-with-ou-level-filtering-for-office365.aspx 
remove OU here then run full import full sync

no need to delete users from OFfice 365 -- they'll be removed from recycle bin in 30 days
0
 
LVL 17

Assisted Solution

by:Ivan
Ivan earned 1000 total points
ID: 40582873
Hi,

as jakob_si said, you don't delete users that were synced from you AD by going to Office 365 and deleting them there.
When you configure OU or users filtering in DirSync, those OU/users will get deleted from Office 365.

So:
1. Configure DirSync filtering so required OU/users get filtered
2. Run Export Azure AD, from DirSync tool --> this will delete those OU/users after you run command in step 3.
3. Run Full Import Full Sync from DirSync tool
0
 
LVL 8

Author Comment

by:K B
ID: 40582953
Thanks Gents,

So in summary I do not rerun the DirSync setup.. instead I run:

1.      From your DirSync Server navigate to <Drive>\Program Files\Microsoft Online Directory Sync\SYNCBUS\Synchronization Service\UIShell

2.      Double click on miisclient.exe

3.      In Identity Manager, click Management Agents, and then double-click SourceAD.

4.      Click Configure Directory Partitions, and then click Container.

5.      When prompted, enter your domain credentials for the on-premises Active Directory forest.

6.      In the Select Containers dialog box, clear the OUs that you want to skip from syncing to Office365, and then click OK.

7.      Click OK on the SourceAD Properties page.

8.      Perform a full sync: on the Management Agent tab, right-click SourceAD, click Run, click Full Import Full Sync, and then click OK.
0
 
LVL 22

Accepted Solution

by:
Jakob Digranes earned 1000 total points
ID: 40583443
Yes .... and within a couple of hours, users not synced will be removed from O365
0
 
LVL 8

Author Comment

by:K B
ID: 40592319
Close App & restart the FIM service before Step 8?

Does this sound logical?  Heard this from a SME

thoughts?
0
 
LVL 22

Expert Comment

by:Jakob Digranes
ID: 40593041
never done that
0

Featured Post

Has Powershell sent you back into the Stone Age?

If managing Active Directory using Windows Powershell® is making you feel like you stepped back in time, you are not alone.  For nearly 20 years, AD admins around the world have used one tool for day-to-day AD management: Hyena. Discover why.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

With its various features, Office 365 can not only help you with your day-to-day business tasks, it can also do wonders for your marketing campaign.
On September 18, Experts Exchange launched the first installment of the Help Bell, a new feature for Premium Members, Team Accounts, and Qualified Experts. The Help Bell will serve as an additional tool to help teams increase question visibility.
A company’s greatest vulnerability is their email. CEO fraud, ransomware and spear phishing attacks are the no1 threat to a company’s security. Cybercrime is responsible for the largest loss of money to companies today with losses projected to r…
Visualize your data even better in Access queries. Given a date and a value, this lesson shows how to compare that value with the previous value, calculate the difference, and display a circle if the value is the same, an up triangle if it increased…
Suggested Courses

610 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question