Employee ID for logon name?

Hey guys, need some thoughts on this. This is not my idea nor am I an favor for it, but can any of you give me pros or cons why usernames should be replaced by a users' employee ID number? There are talks where I work that they would like to replace
everyone's username with their employee ID.... Seems to me that just having to always cross reference a number with a user's name is just asking for more trouble than its worth....
Thanks!
Mike

Hey guys, need some thoughts on this. This is not my idea nor am I an favor for it, but can any of you give me pros or cons why usernames should be replaced by a users' employee ID number? There are talks where I work that they would like to replace
everyone's username with their employee ID.... Seems to me that just having to always cross reference a number with a user's name is just asking for more trouble than its worth....
Thanks!
Mike
Hello,
I don't see an advantage here but it depends of your company policy. Maybe it is easier for them to identify users by their IDs!
Howerver, please make sure that this update is supported for all applications in use since there is many applications are using samaccountname attribute and not SID to identify users. Here, updating the samaccountname will brake access to these applications
and they should be updated here. So, please check this part before proceeding!
This
posting is provided "AS IS" with no warranties or guarantees , and confers no rights.   
Microsoft
Student Partner 2010 / 2011
Microsoft
Certified Professional
Microsoft
Certified Systems Administrator: Security
Microsoft
Certified Systems Engineer: Security
Microsoft
Certified Technology Specialist: Windows Server 2008 Active Directory, Configuration
Microsoft
Certified Technology Specialist: Windows Server 2008 Network Infrastructure, Configuration
Microsoft
Certified Technology Specialist: Windows Server 2008 Applications Infrastructure, Configuration
Microsoft
Certified Technology Specialist: Windows 7, Configuring
Microsoft
Certified Technology Specialist: Designing and Providing Volume Licensing Solutions to Large Organizations
Microsoft Certified IT Professional: Enterprise Administrator
Microsoft Certified IT Professional: Server Administrator
Microsoft Certified Trainer

Similar Messages

  • Information about logon name pre-windows 2000

    Hi,
    In active directory while creating users we have two fields like logon name and logon name (pre-windows 2000). In windows2008R2 server I created new user (Test user) and 1 new group. I mapped new user to the group. While creating user I have given 123456789
    for logon name field and user.test for logon name pre-windows 2000.
    But with this user while doing LDAP search user is not listing from the server and also getting error as No groups found for the new user. So can you please let me know whether we need to give same name for logon name and logon name pre-windows 2000 fields?
    If possible brief me about those fields.
    Appreciate your earlier response.
    Thanks & Regards,
    Sitaramaiah

    Hi,
    Please go through the link which will clear your doubts.
    http://technet.microsoft.com/en-in/library/cc739093%28v=ws.10%29.aspx
    Biswajeet

  • Impact on roaming profile accounts if we Change User logon Name to Employee Number format in Active Directory for all User accounts

    I want to understand if we change User logon Name to Employee Number format in Active Directory for all User accounts, then what would be the impact on existing profile. Whether we need to change it manualy or it will connect to same profiles in terminal
    session.
    As i observed it create new profile after logon name changed to employee number where existing users profile settings get fails to load and prompt for new settings (such as outlook reconfiguration, share drive mapping etc.).
    Kindly let me know the proper process to overcome with this, how to connect same existing roaming profile with employee number format change.

    Hi,
    What if we change the user name of user account, will it have impact on roaming profiles.
    Yes, it will affect roaming profiles. Please rename the roaming profile folder as the new user account name, in addition, change the profile path in ADUC.
    Here is an related article below for you:
    How to Rename a Windows 7 User Account and Related Profile Folder
    http://social.technet.microsoft.com/wiki/contents/articles/19834.how-to-rename-a-windows-7-user-account-and-related-profile-folder.aspx
    Best Regards,
    Amy

  • Active Directory requires display name for log in not logon name

    I have a weblogic 10 server and I have created an Active directory authenticator. I can list the users and groups in the console.
    The problem is that I can only logon using the Display name e.g. "Smith, Fred" and not the logon name e.g. "smithf"
    I would like to logon using the logon name.
    I have set in the Weblogic ActiveDirectoryAuthenticator
    User Name Attribute: cn
    User Object Class: user
    Static Group DNs from Member DN Filter: (&(member=%M)(objectclass=group))
    User From Name Filter: (&(cn=%u)(objectclass=user))
    As I said - all works fine - but I want to be able to logon with the userlogon name and not the display name. Any ideas?

    Hi,
    In the end I managed to get it working by changing all references to cn in the above to sAMAccountName as follows:
    User Name Attribute:      sAMAccountName
    User from name filter:      (&(sAMAccountName=%u)(objectclass=user))
    Group from name filter:     (&(sAMAccountName=%g)(objectclass=group))
    Static Group Name Attribute: sAMAccountName
    It seems to work, but I am not sure it is correct becasue I don't know much about AD.

  • Cannot delete the Folder on the desktop after Mavericks update. when I try to delete it, it is asking for logon password, When I give the logon password, it plays a sound of moving to Trash, but the folder still remains on the desktop

    Cannot delete the Folder on the desktop after Mavericks update. when I try to delete it, it is asking for logon password, When I give the logon password, it plays a sound of moving to Trash, but the folder still remains on the desktop
    Please help

    It is a folder which I have created. Name is "SAP".
    I copied some of my office stuff and then deleted the contents inside the folder. But I couldnt delete the folder SAP.
    This is happening after the Mavericks update.

  • Entry for host name is missing or empty (Secure Store key: admin/host/).

    Hi All,
    I am in the process of installing EP7 on SLES9 and MaxDB 7.6 on a clustered HA environment where the SCS, DB and JC components are installed under and referenced by their virtual hostname (eg. sapinst SAPINST_USE_HOSTNAME <virt name>).
    The SCS instance is installed, the Database Instance is installed and I'm currently in the process of Installing the JC and Deploying the EP packages. 
    During the installation, SDM is put into standalone mode and sapinst tries to deploy the package EPBC06_0.SCA where it fails and the sdm_server.err shows :
    "com.sap.sdm.serverext.servertype.inqmy.TargetEngineConfigurationException: Cannot retrieve Engine logon data from Secure Store: Entry for host name is missing or empty (Secure Store key: admin/host/).        at com.sap.sdm.serverext.servertype.inqmy.InQMyTargetSystemConfigurator.getLoginDataFromSecStoreInQMyTargetSystemConfigurator.java:286)        at com.sap.sdm.serverext.servertype.inqmy.InQMyTargetSystemConfigurator.getEngineLoginDataInQMyTargetSystemConfigurator.java:197)        at com.sap.sdm.serverext.servertype.inqmy.EngineStateServiceImpl.determineCurrentEngineStateEngineStateServiceImpl.java:53)        at com.sap.sdm.app.proc.deployment.states.State.determineJ2EEEngineState(State.java:97)        at com.sap.sdm.app.proc.deployment.states.StateBeforeFirstDeployment.getJ2EEEngineStateChangeDescriptionStateBeforeFirstDeployment.java:75)        at com.sap.sdm.app.view.proc.deployment.mapper.StateMapper.map(StateMapper.java:56)        at com.sap.sdm.app.view.proc.deployment.mapper.FlowMapper.map(FlowMapper.java:28)        at com.sap.sdm.app.view.session.AppViewUpdater.updateAppView(AppViewUpdater.java:22)        at com.sap.sdm.app.view.session.AppViewUpdater.sessionStateChanged(AppViewUpdater.java:18)        at com.sap.sdm.app.proc.deployment.impl.SessionStateObserversImpl.notifySessionStateChangedSessionStateObserversImpl.java:46)        at com.sap.sdm.app.proc.deployment.states.InstContext.processEventServerSide(InstContext.java:85)        at com.sap.sdm.app.proc.deployment.states.InstContext.processEvent(InstContext.java:59)        at com.sap.sdm.app.view.controllers.DeployEventProcessor.processEvent(DeployEventProcessor.java:11)        at com.sap.sdm.client_server.deployserver.DeployCmdProcessor.processEvent(DeployCmdProcessor.java:264)        at com.sap.sdm.client_server.deployserver.DeployCmdProcessor.process(DeployCmdProcessor.java:108)        at com.sap.sdm.gui.server.GuiAdminRoleCmdProcessor.processGuiAdminRoleCmdProcessor.java:72)        at com.sap.sdm.is.cs.session.server.SessionCmdProcessor.process(SessionCmdProcessor.java:67)        at com.sap.sdm.is.cs.cmd.server.CmdServer.execCommandCmdServer.java:76)        at com.sap.sdm.client_server.launch.ServerLauncher$ConnectionHandlerImpl.handle(ServerLauncher.java:286)        at com.sap.sdm.is.cs.ncserver.NetCommServer.serveNetCommServer.java:43)        at com.sap.sdm.is.cs.ncwrapper.impl.ServiceWrapper.serveServiceWrapper.java:39)        at com.sap.bc.cts.tp.net.Worker.run(Worker.java:50)       at java.lang.Thread.run(Thread.java:816)"
    The same problem occurs if I try to deploy this package or any other package using SDM in standalone or integrated mode. 
    configtool -> Secure Store -> admin/host/<SID> is the virtual hostname of the JC instance.
    I've tried the following to no avail:
    - Changed configtool -> Secure Store -> admin/host/<SID> to be the physical hostname of the box.
    - Changed configtool -> Server -> Dispatcher -> Service -> P4 -> bindhost (from 0.0.0.0 to JC virt IP).
    - Changed the <Host> entry in sdmrepository.sdc from <phys hostname> to <jc virt hostname>.
    The SAPLOCALHOST, SAPGLOBALHOST all seem to be set correctly in the SAP profiles.
    Has anyone had this issue?  If so, what do I need to check/change?  Any ideas?
    Notice the message does not reference the <SID> in "admin/host", could this be related to the issue?  If so, what can cause this?
    TIA
    Anthony

    Hi All,
    Just an update, I was able to get around my problems by patching the 2004s media from sp6 to sp8, uninstalling my scs, and database and re-installing from the patched media.

  • PowerShell script for AD name change

    I need to change all users logon name in AD to their first name.last name    Server 2003

    Here is my suggestion of a PowerShell V1 script to rename all users (sAMAccountName):
    # Filter on all users that have givenName and sn assigned.
    $searcher=[adsisearcher]'(&(objectCategory=person)(objectClass=user)(givenName=*)(sn=*))'
    [void]$searcher.PropertiesToLoad.Add('distinguishedName')
    [void]$searcher.PropertiesToLoad.Add('sAMAccountName')
    [void]$searcher.PropertiesToLoad.Add('givenName')
    [void]$searcher.PropertiesToLoad.Add('sn')
    $searcher.PageSize
    = 200
    $Results =
    $searcher.FindAll()
    ForEach ($Result
    In $Results)
        # Retrieve values.
        $DN
    = $Result.Properties.Item("distinguishedName")
        $NTName
    = $Result.Properties.Item("sAMAccountName")
        $First
    = $Result.Properties.Item("givenName")
        $Last
    = $Result.Properties.Item("sn")
        # Construct desired "pre-Windows 2000 logon" name.
        $NewName
    = "$First.Last"
        # Make sure new name 20 characters or less.
        If ($NewName.Length
    -gt 20)
            # I don't know how to trim $First in PowerShell to make $NewName 20 characters.
        # Check if name should be updated (case insensitive).
        If ($NTName
    -ine $NewName)
            # Trap possible error.
            Trap
                "Unable to rename user $DN to $NewName"
                "Error description: $_"
                Continue
            # Bind to user object in AD.
            $User
    = [ADSI]"LDAP://$DN"
            # Assign new name.
            $User.sAMAccountName
    = $NewName
            # Save the change to AD.
            $User.SetInfo()
    Test first, by commenting out the SetInfo() statement and echo $DN and $NewName for all  users. Note that the script could trim $First to limit $First.$Last to 20 characters, but I could not find a way to do this. Also, this script does nothing to prevent
    duplicate sAMAccountName values, but the possible error will echo to the screen.
    Richard Mueller - MVP Directory Services

  • How do I find the logon name associated with a roaming profile folder

    Hello,
    We have Server 2003 R2 Enterprise and Windows 7 Enterprise workstations.
    We normally name the profile path \\server\profiles\%username% and that assigns the users logon name to the profile folder.
    Someone created a user account and incorrectly named the profile path so the folder name and user logon name do not match. I am trying to find out who owns the folder without taking ownership of the folder (by default, we did not include Administrators in
    NTFS permissions).
    Is there a way I can find out what the user logon name for the profile folder is without taking ownership of the folder?
    Thanks in advance.

    if there is a chance that the user/owner is still configured with this folder as profile attribute, check the profile attributes of you users for the user account with the matching profile folder attribute.
    check the script gallery, or similar, for a script which will list out all user account profile attributes to a text file, then search/browse that text file for the matching folder name -> user account.
    I have some older scripts tucked away which do ADSI queries in VBscript, to dump out the home_folder and profile_folder attributes for every user in our AD. This helps when we are re-shuffling home_folders or profile_folders from one server to another, etc.
    Don
    (Please take a moment to "Vote as Helpful" and/or "Mark as Answer", where applicable.
    This helps the community, keeps the forums tidy, and recognises useful contributions. Thanks!)

  • Table for user name

    All,
    In the GR slip, ' Issued By : ' is coming as SAP LOgon name .
    I need this as the name of person which will put against this LOgon name .
    Can anyone tell me the table  and field for this to pick ?
    Kindly advise.
    regards

    Hello Sandeep,
    Each use will be assigned with "Person number" (field name PERSNUMBER) and that name against person number will be available in table ADRP. Also you need to filter out for Person group = BC01 (SAP User)
    Hope this helps.
    Regards
    Arif Mansuri

  • High Avg Response time for logon requests via CMS

    Hi Team ,
    We are continuously receiving observing high Average reponse time for logon requests to the BO system  via  Central Management Server.
    We observe response time up to 25043 ms .
    Currently we are on SAP BO 4.0  SP7 patch 9  (4.0.7.9)
    DB = SQL server 2008 R2
    App Server = SAP NW 7.31 SP 7.
    Also the size of our CMS DB is around 15 GB .
    What could be  the possible reasons ?
    Regards ,
    Abhinav

    Hi Abhinav,
    As one of the issues has been raised as a bug which is resolved in BI 4.1 so you can upgrade to resolve this bug. Also if the CMS database size is large then CMS has to search for objects through huge number of rows hence that will affect overall performance. So you can try to reduce this size as per my previous upate.
    Apart this you can try following steps
    Try to ping CMS DB server from BO servers and confirm the response is coming in 1 ms. Run tracert <DB servers name> from CMD and check the number of hops. If response time is not 1 ms or there are more number of hops then ask your network team to resolve network latency issue
    You can increase the "System database connections"  for each CMS from server properties. It is set to 14 by default which means the CMS will establish 14 connections to CMS database at any time. You can increase this value, however please make sure that the system database allows more connections than default 14 from DB side. This needs to be confirmed from your DBA.
    Please add CMS cluster members in platformservices.properties file under Tomcat folder. Please refer following SAP KBA for steps to add the cluster members
           http://service.sap.com/sap/support/notes/1668515
           http://service.sap.com/sap/support/notes/1766935    
       4. Also please confirm number of users simultaneously login to system at peak time. Usually one           CMS is capable of handling around 500 requests. So if you have more then 1000 users then add           another new CMS on same nodes if there is enough free memory on the server
    Regards,
    Hrishikesh

  • Firefox asks for user name and password even though the proxy auto detection

    After upgrading Firefox to ver. 6.01 and next to 6.02 Firefox asks for user name and password of proxy server even though proxy settings are set to Automatic detect proxy settings.

    Sorry can't do anything more than offer support. We have been having this problem for months and support is clueless. Do you also have the migrating homepage issue? We can have 3 or 4 different homepage set-ups throughout the day. Between Verizon and FIOS, there isn't an employee in the corporation who cares about customer service. Since the failed email migrations dating back to Spring of 2011, we have had this login situation constantly. Our normal login count for a day is 12. We figure they are regulating traffic by having customers constantly login.

  • Child dashboard asking for logon credentials when opening it in infoview..

    hi al,
    iam trying to open a child dash board form a parent dash board ( i have converted them in to swf files and exported them to infoview) in infoview.while iam accessing the child swf file in Infoview it is asking for logon credentials..my architecture is like
    infoset->crystal reports->live office->dash board
    i have used the following  url to avoid login  credentials:
    [http://myserver:8080/Xcelsius/opendoc/documentDownload?iDocID=1234&sKind=Flash&lsSCELogonToken=<token>]
    initially,i have created a flash variable with name CElogonToken and binded it to a cell f3 in my excel sheet .
    then again i have concatenated the above url and f3 cell ,in my parent dashboard.
    note that iam able to access the child dash board from tha parent dash board in infoview by giving the logon credentials.
    i dont want to enter login details while accessing the child swf file in infoview.
    any help is highly appreciated...

    Stratos,
    i have tried ur solution but it  did not work out to me.thnq for ur prompt reply.
    and thnks to google...i have got the below link which is working fine without asking me any logon credentials
    http://server:8080/Xcelsius/opendoc/documentDownload?iDocID=26927&sKind=Flash&CELogonToken=
    i have clipped the lsS part before the CELogonToken
    once again thnks to google and other forum members whose replies helped me a lot

  • WPA2 does not allow “Automatically use my Windows logon name &password"

    I have setup WPA2 and I can logon to the domain but Windows XP SP2 still askes for user authentication.
    Even though I am using windows to pass the user name and password. i.e. The "Network Connections", "Wireless Properties", "Authentication", “Protected EAP Properties”, “EAP MSCHAPv2 Properties”, “Automatically use my Windows logon name and password (and domain if any)” checkbox is enabled.
    Has anyone seen this issue?
    Thanks

    Access ACS server using loop back address using JAVA enabled web browser and create a administrative user. After that try accessing ACS using Administrator username and password.

  • Searching by "User Logon Name"

    Hey guys
    I am currently searching the AD by a user's Common Name. For example:
    String searchFilter = "( & ( objectClass = user ) { CN = " + commonName + " } )";But if I want to search the AD by a "User Logon Name", what do I write in the search filter instead of "CN"? Is this piece of information even available?
    If not, is there any other way for me to search the AD by a "User Logon Name"?
    Thanks
    Noam

    Ordinarily I would suggest that you browse the Active Directory using a tool such as ldp.exe and it would become quite obvious which attributes are used to store the user logon names.
    But because it's Monday, the birds are chirping and it's not raining, I'll make it kind of easy for you:
    If you are logging with a NT style domain name like ANTIPODES\alberte, then you will want to search for soemthing like:String searchFilter = "( & ( objectClass = user ) (samAccountName = alberte) )";otherwise if you are using an e-mail style logon name then your search will look something like:String searchFilter = "( & ( objectClass = user ) ( userPrincipalName = [email protected] ) )";

  • User Logon Name domain list

    We are in the process of turning on DirSync and later ADFS. I've been on the phone with MS and have a question. After running DirSync the program was changing our user logon names because our actual internal/local domain was not verified within the Azure/Office
    365 systems. So, I'm looking into different options as to how to fix this.
    Quick description of our domain.
    Server 2008 R2 native Empty root with all everything in the child domain. So company.domain.com. With all users and everything being in the company domain. This is actually a different name then our email domain which we'll say is email.com.
    The domain we have verified in the Office 365 environment is email.com. While we have registered domain.com on the public internet we have no records defined. Everything external is in the email.com public domain.
    In troubleshooting our dirsync user issue the engineer opened the users property page in AD users and computers. From there he went to the "Account" tab.
    There it showed the User logon name: user1 @company.domain.com with a down arrow. I've looked at the pull down before and I've seen two options... domain.com and company.domain.com... I've always assumed just because these are our two onsite
    local domains that my DC's know about.  Well, he picked the pull down and there were three options... the two internal domains PLUS email.com. I have no idea when that showed up. He mentioned if we set the users
    UPN there to email.com instead of company.domain.com dirsync would work properly... And we tested that and it did.
    My question is what determines this drop down list? And what are the ramifications of changing my internal users to that email.com domain.
    I've tested logging into various PC's on site after I changed a test user to that email.com domain and everything seems to still work fine. I have access to corp data, email... I can't find an issue.  
    Can anyone enlighten me with this?
    Sorry for the long description... I hope I've been relatively clear...
    Thanks in advance
    RS 

    Respectfully,
    While the original problem described was related to Office 365, my question is 100% Directory Services related and has nothing to do with Office 365. I'm sorry if my post was misleading. 
    In Active Directory Users and Computers, in a user objects properties page, under the "Account" tab.  At the very top it shows
    User logon name:
    <<USER LOGON>> a separation and a <<@domain>> box.  With a pull down list populated with what I thought were the domains in the local AD forest. 
    My question is what populates or what determines what is listed in this pull down... As stated, I thought it's populated with the Active Directory domains in the local AD forest. But, the pull down in my case has one extra...
    @company.domain.com (default and my primary AD domain)
    @domain.com (my empty root domain in my AD forest)
    @email.com (I have no AD domain for this but it is my primary email domain)
    I thought about this last night and I know Exchange is very integrated into AD... So does Exchange input its primary email domain into this AD pull down list as well? I have Exchange 2010 on site.
    Thanks
    RS

Maybe you are looking for

  • Itunes wont open -- Screenshot of problem

    This is the problem I encounter: Is this the same as all of you guys out there? If so, how do I fix it? I get it whenever trying to open Itunes from any spot on my computer, and have tried un-installing and re-installing itunes but that had no effect

  • Third Party Workflow in my UWL

    Hi, I need to configure third party workflow(Documentum) in my UWL of my Portal.Please let me know the steps to get the required functionality. Regards Nidhideep Bhandari

  • Question about "library" folder

    Sorry if this is dumb question, just got the computer yesterday. Anyway, I was snooping around in the library folder and I deleted some things in an attempt to free up some space, however I think that the things I deleted may have been important. I d

  • Plannin Application Access

    Hi All, I have created a user, and provided Planner acccess to the application. And I login with the provisoned user , user able to see the forms according according to the access he has. Now I provisoned access Financial Reports, when the user tryin

  • Offsetting Account Description in FBL3N.

    Hi All I am trying to include Offsetting Account Description in FBL3N Report. BTE 00001650 for offset accout info is already activated and the values for the GKONT & GKART fields are available in the report. I have checked couple of SAP Notes (112312