Quantcast
Channel: Forum Microsoft Identity Manager
Viewing all articles
Browse latest Browse all 1783

How to move AD user from one OU to another

$
0
0

Hi,

Users should reside in different Organizational Units (OUs) in AD, based on their department(as in lab 4c, exercise 1 in the FIM A515 Basic course). The flow from MV to AD CS is as following for the “dn” attribute:

 

·         distinguishedName ->dn (initial flow only)

·         distinguishedName ->dn

 

distinguishedName is a custom attribute on the form “CN= JACK JOHNSON,OU=Users1,DC=TEST,DC=COM”, generated in a custom workflow. Always pointing to an existing OU.

 

When distinguishedName change from e.g. “CN= JACK JOHNSON,OU=Users1,DC=TEST,DC=COM” to “CN= JACK JOHNSON,OU=Users2,DC=TEST,DC=COM” the user should be moved from OU Users1 to OU Users2. The new dn value flow to the AD CS as it should. However, after an export run on the ADMA(without any errors), an delta import run on the ADMA gives an “exported-change-not-reimportet”, pointing to the dn attribute, and the user has not changed OU in AD.

 

I understand the “exported-change-not-reimportet” warning comes from an discrepancy between the AD CS memory and the connected AD controller, regarding the ad attribute. What should be done to move a user between two OUs? Additional parameter flow? Something else?

 

Using FIM RC1 Update 2 (4.0.2574.0)

 

Best regards

Erlend


Viewing all articles
Browse latest Browse all 1783

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>