How to Sync User attributes between local forests?

Hi
We are currently migrating three AD domains to one.
We are migrating users and distrubution groups with ADMT to the new domain, and stating to move services to the new domain. starting with sharepoint.
But for some time, some services will remain in the three old domains. To avoid maintaining user attributes like phonenumber, address etc multiple places, I would like to schedule a sync of some user attributes from the old domains to the
new.
Just like DirSync between a local directory to office 365 - but how is it done with local domains and not with office365?
So if a helpdesk user is updating a users phonenumber i one of the three old AD, it should be synced to the new domain after. I would like to run this as a schedule task every 15 minute or so.
ADMT is like a one time migrating tool to create the users in the new domain, but I can't see that it will support user attribute
synchronisation.
Do you have any suggention on how I can solve this task?
Best Regards, Steffen. 

ADMT is like a one time migrating tool to create the users in the new domain, but I can't see that it will support user attribute
synchronisation.
I am not sure about the schedule task and if it is available to use in this scenario or not. You have two different security boundaries, so it is not easy as setting up a scheduled task to sync data. Even if it is possible, it would be very hard to established.
For selected users you have to define what to sync and what not to sync and etc.
I believe on of the things you can do is to use FIM 2010 in order to have a synchronized directory. That is the best thing you can do AFAIK.
Sync Users between domains with Forefront 2010
Mahdi Tehrani   |  
  |  
www.mahditehrani.ir
Please click on Propose As Answer or
to mark this post as
and helpful for other people.
This posting is provided AS-IS with no warranties, and confers no rights.

Similar Messages

  • How to sync user for planning from Shared Services

    Hi ..
    Can anybody please let me know how to sync users for planning from shared services.
    Thank you.

    You need to expand on your question.
    But the basic concept is you create or connect (for LDAP) users in Shared Services. You also create groups as required for these users. Then in shared services you provision those user to Planning applications (directly or indirectly through groups)
    Then in Planning you will see users or groups. And in planning you connect them to either members in dimensions or to objects like Forms, Task lists, Business Rules.
    There is therefore no such thing as synching Shared Services with Planning.
    Note: the 2 steps mentioned above can be done in batch through load utilities.
    Please expand you question if necessary

  • How to sync the data between the two iSCSI target server

    Hi experts:
    I have double HP dl380g8 server, i plan to install the server 2012r2 iSCSI target as storage, i know the iSCSI storage can setup as high ability too, but after some research i doesn't find out how to sync the data between the two iSCSI target server, can
    any body help me?
    Thanks

    Hi experts:
    I have double HP dl380g8 server, i plan to install the server 2012r2 iSCSI target as storage, i know the iSCSI storage can setup as high ability too, but after some research i doesn't find out how to sync the data between the two iSCSI target server, can
    any body help me?
    Thanks
    There are basically three ways to go:
    1) Get compatible software. Microsoft iSCSI target cannot do what you want out-of-box but good news third-party software (there are even free versions with a set of limitations) can do what you want. See:
    StarWind Virtual SAN [VSAN]
    http://www.starwindsoftware.com/native-san-for-hyper-v-free-edition
    DataCore SANxxx
    http://datacore.com/products/SANsymphony-V.aspx
    SteelEye DataKeeper
    http://us.sios.com/what-we-do/windows/
    All of them do basically the same: mirror set of LUs between Windows hosts to emulate a high performance and fault tolerant virtual SAN. All of them do this in active-active mode (all nodes handle I/O) and at least StarWind and DataCore have sophisticated
    distributed cache implementations (RAM and flash).
    2) Get incompatible software (MSFT iSCSI target) and run it in generic Windows cluster. That would require you to have CSV so physical shared storage (FC or SAS, iSCSI obviously has zero sense as you can feed THAT iSCSI target directly to your block storage
    consumers). This is doable and is supported by MSFS but has numerous drawbacks. First of all it's SLOW as a) MSFT target does no caching and even does not use file system cache (at all, VHDX it uses as a containers are opened and I/O-ed in a "pass-thru" mode)
    b) it's only active-passive (one node will handle I/O @ a time with other one just doing nothing in standby mode) and c) long I/O route (iSCSI initiator -> MSFT iSCSI target -> clustered block back end). For reference see:
    Configuring iSCSI Storage for High Availability
    http://technet.microsoft.com/en-us/library/gg232621(v=ws.10).aspx
    MSFT iSCSI Target Cluster
    http://techontip.wordpress.com/2011/05/03/microsoft-iscsi-target-cluster-building-walkthrough/
    3) Re-think what you do. Except iSCSI target from MSFT you can use newer technologies like SoFS (obviously faster but requires a set of a dedicated servers) or just a shared VHDX if you have a fault tolerant SAS or FC back end and want to spawn a guest VM
    cluster. See:
    Scale-Out File Servers
    http://technet.microsoft.com/en-us/library/hh831349.aspx
    Deploy a Guest Cluster Using a Shared Virtual Hard Disk
    http://technet.microsoft.com/en-us/library/dn265980.aspx
    With Windows Server 2012 R2 release virtual FC and clustered MSFT target are both really deprecated features as shared VHDX is both faster and easier to setup and use if you have FC or SAS block back end and need to have guest VM cluster.
    Hope this helped a bit :)
    StarWind VSAN [Virtual SAN] clusters Hyper-V without SAS, Fibre Channel, SMB 3.0 or iSCSI, uses Ethernet to mirror internally mounted SATA disks between hosts.

  • How to establish user equvalance between 2 rac nodes on non default ports??

    Hi Friends,
    Please shed some light on how to establish user equvalance between 2 rac nodes on non default ports such as ssh on 22...
    i want to establish user equvalance on other ports..
    Thanks
    RB

    R12DBA wrote:
    Hi Friends,
    Please shed some light on how to establish user equvalance between 2 rac nodes on non default ports such as ssh on 22...
    i want to establish user equvalance on other ports..
    Thanks
    RBHi RB ,
    22 is default port for ssh. For configuring
    http://yasarmoran.wordpress.com/2010/06/12/configuring-ssh-on-oracle-rac-nodes/
    For non default port , first of all you need to configure ssh on new port . For that refer :
    http://www.itworld.com/nls_unixssh0500506

  • Searching and matching user objects between 2 forests

    I have two forests A (old) and B (new)
    I need to compare forest A user objects(~2000) with forest B (~14000) user objects and if they match by any one of the following attributes email, DisplayName or cn ... then, i need to csvde/ldifde the matching objects in a spreadsheet line by line for reporting
    purposes.
    I know how to manually do it using spreadsheet but i would like to automate/script it for efficiency and accuracy. Any scripting help?
    the report should look something like this for all matching objects e.g. email matched in this case, but it could it cn or email also.
    domainname dn
    cn displayname
    email Matched
    forestA fin/users
    user1 user1 last
    n [email protected]
    Y
    forestB ht/users
    user2 user2 last
    n [email protected]
    Y
    thanks
    Navgup

    Hi Navgup,
    Not exactly, however, please refer to the script below, please try to export all the users' information to separate .csv files, and compare this two files with Compare-Object:
    get-aduser -filter * -properties * |select displayname, distinguishedname|export-csv d:\oldforest.csv
    get-aduser -filter * -properties * |select displayname, distinguishedname|export-csv d:\newforest.csv
    $file1 = import-csv -Path "d:\oldforest.csv"
    $file2 = import-csv -Path "d:\newforest.csv"
    $properties=@("displayname","distinguishedname")
    foreach($property in $properties){
    Compare-Object $file1 $file2 -property $property -IncludeEqual -PassThru | Where-Object{$_.SideIndicator -eq '=='} | select displayname, distinguishedname
    I hope this helps.

  • How to sync mailboxes / folders between iPhone and iPad

    How does one sync email folders between iPhone and iPad ?

    Hi Doc,
    I have just been on the phone to Apple for over 2 hours ! Both devices were already on IMAP . It turned out that one particular folder was a rogue and did not sync between desktop, iPhone and iPad. I created a new folder dragged every email into it from my desk top , deleted the original folder and all emails in that folder are now synched. Even Apple was baffled but the problem is now resolved so thank you for your assistance .
    Regards,
    Salmon Man

  • How to get user attributes from LDAP authenticator

    I am using an LDAP authenticator and identity asserter to get user / group information.
    I would like to access LDAP attributes for the user in my ADF Taskflow (Deployed into webcenter spaces).
    Is there an available api to get all the user attributes through the established weblogic authenticator provider or do i have to directly connect to the LDAP server again?
    Any help would be appreciated

    Hi Julián,
    in fact, I've never worked with BSP iViews and so I don't know if there is a direct way to achieve what you want. Maybe you should ask within BSP forum...
    A possibility would be to create a proxy iView around the BSP iView (in fact: before the BSP AppIntegrator component) which reads the user names and passes this as application params to the BSP component. But this is
    Beginner
    Medium
    Advanced
    Also see http://help.sap.com/saphelp_nw04/helpdata/en/16/1e0541a407f06fe10000000a1550b0/frameset.htm
    Hope it helps
    Detlev

  • How to sync safari bookmarks between 2 macs

    I'm about to buy a new MacBook Pro and like to know how to sync the bookmarks in Safari, Opera.

    HI,
    Try MobileMe: Resetting sync data
    Then open System Preferences / MobileMe - Sync
    Select Bookmarks in the list and click Sync.
    Carolyn

  • How to modify user attributes in Microsoft IAS or Active Directory??

    Anyone have an idea?? What I'm trying to do is to authenticate management access to an ACE 4710 against a Microsoft IAS server.
    According to the document below:
    http://www.cisco.com/en/US/docs/app_ntwk_services/data_center_app_services/ace_appliances/vA1_7_/configuration/security/guide/aaa.html#wp1519045
    it sounds like I need to be able to modify user attributes similar to what I know is doable in ACS. I base my assumption on this because of the following statement in the link above:
    "Step 3 Go to the User Setup section of the Cisco Secure ACS HTML interface and double-click the name of an existing user that you want to define a user profile attribute for virtualization. The User Setup page appears.
    Step 4 Under the TACACS+ Settings section of the page, configure the following settings:
    •Click the Shell (exec) check box.
    •Click the Custom attributes check box.
    •In the text box under the Custom attributes, enter the user role and associated domain for a specific context in the following format:
    shell:<contextname>=<role> <domain1> <domain2>...<domainN>"
    Is something like this possible in IAS??
    I have the authentication piece working for the ACE however when I login, I'm assigned an ACE defined default role of 'network-monitor' which gives me only read-only access. The way I'm interpreting what needs to be done to resolve this is to have the authentication server send an attribute value that states that the user is in the role 'Admin' in which case I'll have unlimited access to my ACE.
    Make sense?? Any thoughts??
    Thanks in advance.
    -Lloyd

    Lloyd,
    It is possible via Radius and not TACACS. On the same link if you scroll down, you will see option of doing it via Radius.
    "Defining Private Attributes for Virtualization Support in a RADIUS Serve"
    Find attached the doc that explains about setting up user attributes on IAS.
    Regards,
    ~JG
    Do rate helpful posts

  • How to sync Firefox settings between multiple OS's on one computer or multiple computers

    I have three OS's on a single computer (XP SP3, WIN7 & WIN8. Each OS has it's own Firefox install and of course, different settings in each since they are all handled separately, I have no idea how to synch the user-data from all three different Firefox installations. My goal is to be able to boot up in any of the OS's and have the same user settings/details across all three.
    Once I get that figured out, then I can try to find a way to synch Thunderbird across all three OS's so that mail collected or sent in one OS is shared or synched with Thunderbird on the other two OS's.
    It's probably a tall order and not possible to accomplish, but if I don't ask then I'll never know.
    Thanks in advance for taking the time to read this.
    Ed ~ [email protected]
    Computer details: Windows XP SP3, Windows 7 SP1, Windows 8
    Asus P7P55D m/b, Intel i5 LGA 1156 cpu, Corsair water-cooled CPU HX1000, 16 GB RAM, 14 TB drive space, GT460 Video card, 3 Bluray optical drives, 5 printers, 2 scanners

    hello fastlane, for firefox you can use firefox sync to share bookmarks, passwords & history between your three OSs - [[How do I set up Firefox Sync?]]
    & for keeping your mails synced it's possibly the easiest way to use a mail-provider that offers IMAP, which keeps the mails on the server so that your mail program on any OS has the same data when it's connecting...
    (but we're not specialised on thunderbird here, you might head over to https://getsatisfaction.com/mozilla_messaging/ for more detailed questions).

  • Here's how to sync your Notes between iPad and Mac

    This is not immediately obvious and took me several conversations with various AppleCare techs before I finally got the solution as to why my notes on my iPad where not syncing to my Mac Pro. The problem seems to be that you can't sync if you only have Notes on your iPad. You must have notes on your Mac to which unlike Calendar and Contacts don't have corresponding standalone applications, iCal and Addressbook, respectively. Notes exist within Mac Mail. I only had Notes on my iPad and none on my Mac Pro. In this event here's what to do to get setup and syncing:
    SETUP:
    1. Go to System Preferences on your Mac > MobileMe > Sync > and make sure Notes is checked although, syncing via the cloud apparently won't happen until iOS 4.2.
    2. With Mac Mail launched, if you've never created a note in Mac Mail, in the left column you should see:
    MAILBOXES
    ON MY MAC
    RSS
    or if you've created some notes on your Mac Mail, you'll see:
    MAILBOXES
    REMINDER
    - Notes
    ON MY MAC
    RSS
    The key is you have to have REMINDERS created. So if you don't have it created, when you sync your iPad and Mac, the iPad doesn't know what to do as there's no "receptacle" for it's notes on your Mac.
    So in Mail, in the top of the window create a new Note, click the notepad icon to the right of the New Message.
    Now REMINDERS will be created in Mail's left column with this new note. You can simply put "Test" or whatever and click "Done" in the upper left of the Note's window.
    3. Plug your iPad into your Mac, in iTunes, in the left column click your iPad under DEVICES the Info tab in the top. At the bottom of the page is "Other" > click: Sync notes. Do NOT click the checkbox "Notes" in the next section under "Advanced"
    4. Click "Apply" at the bottom of the page and your iPad and Mac will begin to sync. It may take awhile as I believe it is doing both a sync and backup.
    Once this process is done, you'll see your notes fully sync'd on your iPad and Mac. Yea! but there's more...
    5. Notes created in Mac Mail show up in 2 places: your MAILBOXES > Inbox and under REMINDERS > Notes, and if you delete the Mac Mail note in your inbox, it deletes the note in your REMINDERS.
    This is unfortunate and not great interface design IMHO and should be remedied.
    Luckily the last Tier 2 AppleCare tech I just spoke with had a workaround for this, which is:
    6. Create a new mailbox inside Notes under REMINDERS. Click Notes, then go to Mailbox > New Mailbox... in the top of your monitor screen.
    Under the location pulldown it should show a notepad icon and On My Mac.
    For the Name, I called my new mailbox "iPad Notes" Then click OK.
    Then a triangle appears next to Notes mailbox to access this new subfolder (iPad Notes) and you then drag your now sync'd notes from Notes under REMINDERS to your "iPad Notes" subfolder under Notes. Now your left column will look like:
    MAILBOXES
    REMINDERS
    -Notes
    --iPad Notes
    ON MY MAC
    RSS
    Doing this drag to "iPad Notes" will remove the note(s) from your inbox, but keep it in your REMINDERS and thus be available for Syncing, which currently can only be done with your iPad when plugged in via USB to your Mac.
    Apparently, in iOS 4.2, you'll be able to use MobileMe to sync Notes just like Calendar and Contacts. We'll see.
    I hope this is helpful. It took me awhile to get all this set up, and being that I am not an AppleCare tech, if you have questions instead of asking me, I recommend you call AppleCare and review with them. Let them know I got the above info from Tier 2 support.
    Once iOS 4.2 and Lion come out, all this may, hopefully be a simpler process, but as of this writing, pre 4.2 and Lion, this is now working on my iPad and Mac Pro.
    Good Luck.
    Steven

    Thanks ,,, but when I "Go to System Preferences on your Mac > MobileMe > Sync > and make sure Notes is checked"
    I CANNOT check the "Notes". It is NOT highlighted. MAYBE because I am NOT logged-in to mail.mac.com?
    Is this why my Sync Notes between MacBook Pro and iPAD 2 does NOT work?
    How do I fix it?
    Also I continue to get Error Message "smtp.mail.com" password not accepted.
    I DO NOT know my mail.mac.com password.

  • How to sync data/apps between different iTouches?

    I have my itouch, and some apps for my kid.
    If I buy a new itouch, I'd like to move all my existing data to the new ipod touch, then put only a few apps on the old ipod touch.
    how would i go about managing multiple ipod touch devices using itunes?
    Can I mix and match apps between the various ipods?

    You can sync as many ipods as you like to one computer/library.
    Each device is different and can be set to sync whatever you like.

  • Question re: syncing User Accounts between 2 machines wirelessly. Possible?

    I'm soon to take delivery of a 24" iMac and I plan to have 2 User accounts on there for myself and my partner. My partner also has a G4 iBook.
    My question is, is there anyway that my partner can sync her account (documents and settings) on her iBook with her account on the iMac? ie. if she starts a Word document on one machine, then moves to the other machine and syncs, can she continue to edit the document, and vice versa?
    Is there something in OS X or third party that would facilitate this?
    Any advice much appreciated.
    Neil

    We do use portable accounts. This is so that we don't tie up the network letting users work directly from their network accounts. We also need to have the ability of our users to work at different computers, but still get access to their own stuff. We have it set up so that when a user logs onto another computer for the first time, he is asked if he wishes to create a portable home directory. We have them answer "yes". I think at that time it then brings down from their network account all their files and settings so that the new computer will look like any other computer that they already have worked at. This appears to creat what is called a mobile account on the computer. We also have syncing set up to sync at login and logout. This, hopefully will sync up their network directory to any changes made at different computers and thus make those changes appear on any other computer that they work at. Sometimes the user gets a message that their network account has changed since last logon and ask if they wish to sync to their network account or their local account. We normally tell them to sync to their network account, assuming that it has the newest changes. None of our users ever work offline from our network so their network account should always be the most recent version of any files. This is assuming that the syncing is working properly. Does this make any sense? Does it sound like we are doing this properly or is there a better, more efficient procedure?

  • CAnnot see the tree and how to sync users

    Setting up a demo network.
    1 Novell Netware SBS server
    1 Linux SBS server
    Installed eDirectory to the Linux box, imanager and everything works fine.
    Netware - master replica
    Linux - read/write
    If the Netware server goes down, we cannot see the tree.
    Tried with SLP and without.
    creating users in iManager from either server IP works fine and shows up in
    Console1
    Is there a way that when we add a user to the NDS, that it will create a
    user on the Linux server as well? I mean on the actual linux server, not
    eDirectory?
    I suppose similar to setting DirXML for Active Directory and NDS?

    Hi, thanks for your e-mail, pretty much the same deal for me, except one of
    my techs is a Red Hat guy, so we had some tech knowledge before testing
    this.
    Actually, we noted that through ldap, we can see the eDirectory users on the
    Linux server under the users section, and we can add them to linux groups
    and shares, which through the setup of Samba, can map drives to the linux
    server.
    you should check out the article I sent along earlier that explains how to
    set that up. Very interesting.
    >>> <stanch@**.co.uk> 3/4/2006 1:11:31 AM >>>
    Hello Robert,
    Just so you don't feel alone out there..
    A little of my background. I am a Linux newbie, ex MCNE from NW4 days and
    run and deploy NW65 im my job. I decided to learn Linux and as I don't use
    it at work. I thought the only real way to get familiar with it was to run
    it at home. I purchased NLSBS9 and have installed it as the home server
    and it runs the households email and Internet access. My users have
    resistance to Linux at the desktop so its XPpro for now.
    My experiences with NLSBS9..(remember I am a Linux newbie, hopefully if I
    tell you something that is incorrect someone will jump in and correct me.)
    It appears that NLSBS9 with it's accompanying Novell Linux desktop
    licences was conceived as a total package. Linux clients to Linux server.
    Windows client support is not so well implemented. For Windows user file
    and printer access you need to run and configure Samba. Samba requires
    linux users to be created and these are stored in an Ldap directory.
    eDirectory is present solely for GroupWise to run, it is not linked to the
    LDAP directory. The two directories are not linked or synced in any way.
    I thought NLSBS consisted of Suse Linux Open server plus Groupwise.
    Apparently not, as Suse has a facilty called LUM (Linux user management)
    which is a tool that you can manage users with and it is linked to
    eDirectory.
    A little birdie tells me an announcement about NLSBS9 and future
    developments could be made during Brainshare....
    There is a .PDF of nearly 8 mbs. that is a introductory course to
    installing and configuring NLSBS9 you can get it by running this url :-
    http://www.novell.com/partners/nlsbs...lsbs_final.pdf
    NLSBS9, for me, has been rock solid and all issues with it have been
    caused by my own inexperienced hands.....GroupWise has performed
    faultlessly.
    Hope this helps..
    Rgds.
    Stan Chelchowski

  • How to compare user attribute : Urgent

    Hi,
    I have two users in same company code with (although department is different but should not be an issue ), however their behavior is different in shopping cart ( one calculate tax one does not with same ship-to zip code ), is it possible to compare them extensively  their internal associations with plant etc.
    Points will be awarded.
    Thanks,

    Hi. Table HRT1222 stores the normal attributes. You get from there to the actual org unit / position in HRP1222.
    HRT5502 holds the plants and storage locations, linked to org unit / position in HRP5502.
    If you get the 2 users side by side i SE16 and flick between the 2 you should see differences quickly.
    Regards,
    Dave.

Maybe you are looking for

  • Which product I need (Std or Pro)

    Which product do I need to update a PDF form on our Web site. The person who created it is no longer available . We do not have Adobe Acrobat and like to purchse one. The Pro version is very expensive for just updating or creating a new PDF form. Tha

  • How to Redirect Customer to a Account Page

    I am trying to set up a user log in page where after the user logs in using their user name and password they are then redirected to a User Page where they can update their profile. How do I get the submit button to redirect to a new page? Thanks!

  • Fotostream

    I cant use photostream on my IMAC - no problem with the iphone or Ipad. When I login on ICloud, open Iphoto and ask to connect to photostream I am told: " Iphoto could not connect to Photostream" What is wrong ?

  • Which hard drive config is the best for an existing system?

    Hy there, We have this system: DELL PRECISION T3500 64 BITS CPU INTEL XEON W3520 2.67GHZ  266 MHZ 4 CORE - 12 GB RAM NVIDIA GEFORCE GTS450 MATROX RTX2 - 5.1.2.8 PREMIERE PRO CS5 (5.02) WINDOWS 7 PRO SYSTEM HD 500 MB With this HD config: B: EXPORT (pa

  • Itunes music download statistics

    Working on a project. How can I get the itunes music download statistics by year and genre, etc?