Applications Server
 

Sharepoint 2013 : Managing and Configuring Profile Synchronization (part 2) - Active Directory Import

11/20/2013 6:55:06 PM

3. Active Directory Import

The Active Directory Import (ADI) synchronization method provides administrators with a new option for syncing profiles. One of the benefits of choosing this method is that you don’t have to provision the User Profile Synchronization Service. No, this is not a joke. Recall reading that ADI is much easier to configure. This synchronization process runs entirely in the context of the User Profile Service Application. In general, ADI is configured in three steps: selecting ADI as the sync option, as covered in the previous section; creating a connection; and mapping user profile properties. The following steps provide the details for creating a connection:

1. In the Synchronization section of the Manage Profile Service page, click Configure Synchronization Connections.

2. Click Create New Connection.

3. Enter a name in the Connection Name box.

4. Enter the fully qualified domain name of the domain you wish to sync.

5. Select the Authentication Provider type. Most administrators will use Windows Authentication. Click the Authentication Provider Type drop-down menu to familiarize yourself with the options available.

6. Enter the account name and password of the Active Directory account you configured to do the import. Figure 3 shows an example of a completed connection.

FIGURE 3

image

7. Make sure the default port is correct and check whether your domain uses SSL.

8. Optionally, check the box to filter disabled users from the import.

9. Add any LDAP filters that you want to use to filter users from the synchronization process. Here’s a common filter that includes accounts that are not disabled:
(&(objectCategory=person)(objectClass=user) 
( !(userAccountControl:1.2.840.113556.1.4.803:=2))).

NOTE The LDAP filters used here are inclusion filters; they tell the sync process what to include, not what to exclude. This is different from the User Profile Synchronization process, where the filters are exclusion filters. Also, since there is a check box for excluding disabled users, you could use the following filter as another example for users with an e-mail address: (&(objectCategory=Person)(objectClass=User)(!(userAccountControl:1.2.840.113556.1.4.803:=2))(mail=*)).

10. Click Populate Containers to load the tree view.
11. Select the objects that you want included in the import.
12. Click OK. The connection information is stored in the profile database.

As you can see, this is much easier and faster to configure compared to configuring the SharePoint Profile Synchronization process. However, administrators need to be aware of the limitations:

  • This is a single Active Directory forest sync.
  • Mapping to SharePoint system properties that begin with “SPS-” is not allowed.
  • Mapping multi-value data types to single-value data types and vice versa is not supported.
  • Mapping two different attributes to the same property is not supported.
  • Augmenting profile information using the BCS is not supported.

By default, the import process runs every five minutes. Either you can wait for the job to run or you can manually start a full synchronization from the Manage Profile Service page. To change the schedule of the job, click Configure Synchronization Timer Job under the Synchronization heading on the Manage Profile Service page. Note that a full import is required whenever a configuration change occurs. A configuration change includes one of the following:

  • Adding or removing organizational units (OUs)
  • Changing the filter properties
  • Adding or changing property mappings

It’s a good idea to purge the profile database after a full import has been completed. You can do that using the following PowerShell cmdle:

Set-SPProfileServiceApplication - Identity $UPS_to_Update
-PurgeNonImportedObjects $true

The final configuration step involves mapping user properties in the user directory to SharePoint properties. This is discussed in the next section, but keep in mind that it also applies here. To summarize the preceding, the ADI process requires selecting the ADI option, creating a new connection, and mapping user attributes. Once completed, the farm administrator can initiate an incremental or full sync from the Start Profile Synchronization page. This page is accessed using the Start Profile Synchronization link in the Synchronization section of the Manage Profile Service page. The sync is initiated by choosing one of the following:

  • Start Full Synchronization — Use this if syncing for the first time or if connections have been added or modified since the last sync.
  • Start Incremental Synchronization — Use this to synchronize only information that has changed since the last sync.
 
Others
 
- Sharepoint 2013 : Managing and Configuring Profile Synchronization (part 1) - Choosing a Synchronization Method
- Sharepoint 2013 : Configuring User Profiles and Social Computing - What’s New in Enterprise Social?
- Exchange Server 2013 : Defining a Highly Available Messaging Solution - Achieving High Availability
- Exchange Server 2013 : Defining a Highly Available Messaging Solution - Defining Terms for Availability
- Exchange Server 2013 : Defining a Highly Available Messaging Solution - Defining the Cost of Downtime, Planning for Failure
- Exchange Server 2013 : Defining a Highly Available Messaging Solution - Defining Availability
- About Microsoft SharePoint 2013 : What Is a Workflow?
- About Microsoft SharePoint 2013 : What Is Tagging?
- About Microsoft SharePoint 2013 : What Is a Content Type?
- About Microsoft SharePoint 2013 : What Are Web Parts?
- About Microsoft SharePoint 2013 : What Is a View?
- Feature Overview and Benefits of Microsoft Lync Server 2013 : Remote Access
- Feature Overview and Benefits of Microsoft Lync Server 2013 : Enterprise Voice
- Feature Overview and Benefits of Microsoft Lync Server 2013 : Dial-In Conferencing
- Feature Overview and Benefits of Microsoft Lync Server 2013 : Presence (part 3)
- Feature Overview and Benefits of Microsoft Lync Server 2013 : Presence (part 2)
- Feature Overview and Benefits of Microsoft Lync Server 2013 : Presence (part 1) - Presence States , Access Levels and Privacy Relationships
- About Microsoft SharePoint 2013 : What Is a Document Library?
- About Microsoft SharePoint 2013 : What Is a Personal Site?
- About Microsoft SharePoint 2013 : What Is a Site?
 
 
Most View
 
- Windows 8 : Sharing Settings (part 1) - To access sharing settings
- Developing, Integrating, and Building Applications in Sharepoint 2013 (part 5) - Data Integration
- Windows 7 : Windows Media Player - Taking Your Music and Video on the Go (part 1) - Burning Customized CDs
- Microsoft OneNore 2010 : Distributing Your Notes - Emailing a Page
- Windows Server 2012 : Understanding Internet Information Services 8 (part 2) - Exploring the IIS Manager Administration Panes
- Microsoft Word 2010 : Employing Tools for Quality - Using Find and Replace (part 1) - Extending Search Options
- Microsoft PowerPoint 2010 : Preparing a Slide Show - Creating a Custom Slide Show
- Windows 7 : Using BitLocker Drive Encryption
- Microsoft Exchange Server 2013 : Designing a Successful Exchange Storage Solution - Storage Changes in Exchange 2013
- Packaging and Deploying Sharepoint 2013 Apps : Deploying an App (part 2) - Provider-Hosted App Deployment
 
 
Top 10
 
- Microsoft Visio 2013 : Adding Sophistication to Your Drawings - Understanding and using layers
- Microsoft Visio 2013 : Adding Sophistication to Your Drawings - Inserting pictures
- Microsoft Excel 2010 : Filtering Options (part 3) - Using the Search Function for Grouped Dates, Using Text, Number and Date Special Filters
- Microsoft Excel 2010 : Filtering Options (part 2) - Searching Functions for Listed Items
- Microsoft Excel 2010 : Filtering Options (part 1) - Filter Listing for Listed Items, Grouped Dates Filter Listing
- Microsoft Excel 2010 : Filtering and Consolidating Data - Preparing Data, Applying a Filter to a Dataset
- Microsoft PowerPoint 2010 : Inserting Charts and Related Material - Formatting a SmartArt Graphic
- Microsoft PowerPoint 2010 : Inserting Charts and Related Material - Resizing a SmartArt Graphic
- Microsoft PowerPoint 2010 : Inserting Charts and Related Material - Modifying a SmartArt Graphic
- Microsoft PowerPoint 2010 : Inserting Charts and Related Material - Using the Text Pane with SmartArt Graphics