Limit the users synced with AADsync

Hello,
Is it possible to limit the users who are synced to Azure AD based on something else than the OU?
We want to sync some users, not all of the AD users, to the cloud.  The user set is different from the OU organization in AD.
Can this be done in an easy way?
Our security policy is Always 'whitelist only what is needed', not 'blacklist what is not needed'. in AADsync this seems now to be OK for the attributes, but is it also for the users?
Herman Van Uytven

You can limit by domain, OU or attribute. Perfectly possible to whitelist users based on attribute-based filtering, check this article:
https://msdn.microsoft.com/en-us/library/azure/dn801051.aspx?f=255&MSPPError=-2147217396#BKMK_ConfigureAttributeBasedFiltering

Similar Messages

  • Is it possible to limit the user to one session?

    Hi
    We have Oracle apps R 12.0.6, single node installation. Because of performance issues, i want to restrict the user to have only one session. Is it possible to limit the user to one session?
    Regards
    Arizuddin

    Ateeq,
    I tried to load the event and subscription according to metalink document id
    About the oracle.apps.icx.security.session.created business event. [ID 304209.1]. it says file does not exist.How to resolve this?Could you please post the command along with the complete error?
    Regards,
    Hussein

  • HT201077 Why can't I access my iCloud albums from apps on my mobile devices?When I go to access my albums from any app on my phone or iPad, I cannot access the iCloud albums, only the albums synced with iTunes/iPhoto manually.  This is frustrating because

    When I go to access my albums from any app on my phone or iPad, I cannot access the iCloud albums, only the albums synced with iTunes/iPhoto manually.  This is frustrating because I cannot add to those albums from mobile device, I have to add to them during a Mac sync.  I would like to be able to use my iCloud albums to organize my photos but if I cannot access them from apps it seems pointless.  I will end up having to maintain both an iCloud library and a separate iPhoto library which is more work that seems necessary.  I want everything easy to organize and access.  It seems like in this age where most people are more likely to use their mobile devices than their Macs (and some do not even own Macs) that there should be a mobile solution.  Hopefully I am simply without a clue and you folks can help me out with a fix or a source of info as a solution.  I have not found answers yet.

    gail from maine wrote:
    Hi keriah,
    When you go to Settings>Pages, do you have the "Use iCloud" option turned on?
    Cheers,
    GB
    That was it!  Thanks!!!

  • I embedded a pdf in an Outlook appointment.  The appointment synced with my iPad calendar, but the pdf did not come through.  Am I missing a setting?

    I embedded a pdf in an Outlook appointment on my desktop.  The appointment synced with my iPad calendar correctly but the pdf did not come through.  Did I miss a setting on my iPad?
    Thank you

    Then your family members will probably have bought their ipads with a data plan from some phone company like AT&T in the States. Maybe they even got it "sponsored", because they bought a data plan with it.
    If you bought your "iPad only" from a hardware seller, you will have to get a data plan from some phone company. Seems like you only bougth the hardware! You can still use your ipad, however, and if you have an iPhone, you do not even need a sim card in your iPad, because it can use your iPhone's data plan.
    That is what I did. I save the extra money for the 3G version, because with an iPhone 4 there is no need for an own sim Card in an iPad.
    But that is another topic.

  • Did ios7.4 help the ipad sync with itunes

    did the update of ios 7.4 help the ipad sync with itunes - songs not playing

    Try reset all settings
    Settings>General>Reset>Reset All Settings
    Note: Data will not be affected but settings will be reset.

  • I recently did a "over the air" sync with my notes to my email account and when i did i didnt get back all my notes, could the other notes be in another location?

    i recently did a "over the air" sync with my notes to my email account and when i did i didnt get back all my notes, could the other notes be in another location?

    Go to Settings>iCloud and set up the iCloud account you were using before by singing in with the same Apple ID.  Then turn the data you were syncing with your iCloud account back to On, and if prompted, choose merge.

  • HT1296 I am facing a problem with my iPhone 4. I applied the first syncing with outlook 2007 by choosing the "merge" option. At the end of the process, some contacts are correctly sync, but most are only sync with the names. Numbers are lost. Any suggesti

    I am facing a problem with my iPhone 4. I applied the first syncing with outlook 2007 by choosing the "merge" option. At the end of the process, some contacts are correctly sync, but most are only sync with the names. Numbers are lost. Any suggestion?

    I would love to do this as well. All I need is my calendar appts from outlook. Right now I am using google calendar sync, but I would like to move to the cloud and away from google. I find it hard to believe there isn't an option to do this.

  • How to retrieve all the users along with their password from LDAP

    Hello,
    Can anyone let me know how to retrieve and list all the user along with their password from LDAP.
    Thanks

    Hi Prashant,
    I have limited experience with Synchronization, but I agree with you - if you need to synchronize Passwords, you need to have the Password in clear Text.
    If you trying to build your own Synchronization Solution using any of the avaliable LDAP APIs, I don't think you can ever retrieve a user's Password in clear text.
    However, I did come across an interesting article & I hope you find it useful :-
    http://www.oracle.com/technology/obe/obe_as_10g/im/configssl/configssl.htm
    I am not sure if SSL is necessary - If you have a look at Metalink Note 277382.1 ( How to Configure OID External Authentication Plug-In for Authentication Via Microsoft Active Directory (MS AD) ), teh question asked by oidspadi.sh for the same is asnwered as "N".
    Regards,
    Sandeep

  • R12 limit the user privilage under multi-org situation

    Hi
    In R12, users needn't change the repsonsibilty to achieve the same transaction for multi-org.i.e. u can do the ou1,ou2....under the same AP responsibility.
    while if i want to limit users privilage under this situation, user1 is just limited to the ou1, user2 is just limited to the ou2....how can i relaize it?
    Any help will be preciated.
    Regards,
    Chelsea

    you can achieve this easily...I would suggest go through Documentation atleast once. This Subject is very new.
    Here is one senario how can it acheive for AP Invoice Entry
    Responsibility: Payables
    Navigation: Invoices:Entry > Invoices
    On the Invoice Workbench, you can select an Operating Unit, or enter another field, such as PO or Supplier Site, from which the system will default an OU. Your list of available OUs is determined by your multi-org security profile defined in Oracle HR and associated to their responsibility through the MO Security Profile profile option.
    How it works....once the application automatically provides the operating unit of new (uncommitted) invoices during entry. The following are methods by which the operating unit is derived:
    1)Default Operating Unit from “MO: Default Operating Unit” Profile Option
    2)Default Operating Unit from Invoice Batch Header
    >>When entering invoice batches, users have the option of establishing a default operating unit for the invoices entered in the batch. This can be overridden at the invoice level as with any other value (Payment Method, for example) entered in the Invoice Batches window.
    3)Derive Operating Unit from Transaction Attributes
    >>>Oracle Payables will derive the operating unit of an invoice based on certain user entered attributes. If the user chooses a PO (via PO Default or QuickMatch features) or supplier site when the Operating Unit field is empty, the Operating Unit corresponding to the selected value will be populated onto the invoice.
    4) Set Operating Unit from Single Operating Unit Security Profile
    >>>>> That mean when a user’s security profile contains only one operating unit, it can be said that the user’s operating unit context has been “set” to this operating unit. This value is automatically defaulted to all new invoices and it cannot be overridden.
    Hope this make sense.
    same is true for other activity like payment , period close.Let me know , in case if you are not clear.
    thanks

  • Files users sync with OID

    The Oracle Files is not Synchronizing with the OID, even after setting OID Sync.agent to 3m instead of 24h.
    Whenever i logon to files it gives me "You don't have an Oracle files account"
    Any idea why this is happening?

    You have recently created a user in OID and are immediately trying to login to Oracle Files using that userid. The error message you get is,
    "Error. You do not have an account on Oracle Files"
    To get the error;
    1) http://host.domain:7779/files/app/AdminLogin
    2) Click, "Login using Single Sign-on"
    3) Enter the new userid & password to get "Error. You do not have an account on Oracle Files."
    The FilesOidUserSynchronizationAgentConfiguration agent is set to 24hours by default, so a new user must wait 24 hours before it will import the user into Oracle Files. You need to create a new Synchronization agent
    with a shorter time period:
    1) Start EMD, also known as Oracle Enterprise Manager, from the command-line using
    $ORACLE_HOME/bin/emctl start
    2) Connect to EMD at http://hostname:1810 and log in as ias_admin using the same password you entered for the Oracle Collaboration Suite instance when you installed Oracle Collaboration Suite.
    3) Click Files. The Files Domain page appears.
    4) Click Server Configuration.
    5) Click and Edit the FilesOidUserSynchronizationAgentConfiguration,
    changing the value of IFS.SERVER.TIMER.ActivationPeriod from 24h to 3m (for a check every 3 minutes).
    6) Save FilesOidUserSynchronizationAgentConfiguration.
    7) Stop FilesOidUserSynchronizationAgent by clicking on the <server> Node. Now you should now see a list of servers. Click the radio button for
    FilesOidUserSynchronizationAgent and click Stop.
    8) To load the new Server, then click on the Load Server push button. Enter a new name in the Server Name (ie: OIDSYNC). In Server name field, select IfsDefaultServer from the drop down list. For the Server Configuration Field, select FilesOidUserSynchronizationAgentConfiguration. Then, click OK. You should see a new server named, OIDSYNC.
    9) Start the newly loaded FilesOidUserSynchronizationAgent. Do not start
    the same agent that you just stopped. Click on the radio button for OIDSYNC, then click on start. Keep the FilesOidSynchronizationAgent stopped.
    After a few minutes (when the new FilesOidUserSynchronizationAgent synchronizes
    the Oracle Files users with those newly created in OiD) every new user receives an e-mail containing a password.
    Once the FilesOidUserSynchronizationAgent has created the users, you can change the ActivationPeriod back to 24h or whatever is your preference.

  • How can I limit the User not to create OPPT for a given BP grouping

    Hi ,
    We did create a Business Partner grouping (BUT000-BU_GROUP) and wish to block the user to create an Opportunity ( Transaction Type OPPT ) for this Business Partner grouping ?
    How can we do that ?

    Hi,
    You can do this with the help of BADI
    Customer Relationship Management  Transactions  Settings for Opportunities  Business Add-Ins  Business Add-In for Opportunity: Header Data
    You will have to do enhancements for opportunity header data.
    Please use the BADI : CRM_OPPORT_H_BADI:
    In this BADI use the method : CRM_OPPORT_H_CHECK
    With this you can carry out additional checks - the results of these checks can be copied as error messages. Here you can check the grouping of the business partner you are entering in the transaction and if e.g. grouping of the BP is u201CXu201D the error message can be triggered u201COpportunity can not be created for this BPu201D.
    Please let me know if this helped in resolving your problem
    Regards
    Dinesh

  • How can i limit the user to enter only A to Z and space in JFormattedText

    dear
    i want to use JFormatedTextField in two manners
    1.Limit the no of charecters.means in a text field only 20 charecters r allowed.
    2.and also check the enterd charecter must be a to z and space not other chareters r allowed.
    3.same for numbers means 0 to 9 and decimal.
    how can i do by using the JFormated TextFilef.

    Probably lacks in some cases but what the hell.
    * Filename:           JSMaskedTextField.java
    * Creation date:      22-mei-2004
    * Author:                Kevin Pors
    package jsupport.swingext;
    import java.awt.event.KeyEvent;
    import java.util.Arrays;
    import javax.swing.JTextField;
    * A masked textfield is a textfield which allows only a specific mask of
    * characters to be typed. If characters typed do not occur in the mask
    * provided, the typed character will not be 'written' at all. The default mask
    * for this <code>JSMaskedTextField</code> is <code>MASK_ALPHA_NUMERIC</code>
    * @author Kevin Pors
    * @version 1.32
    public class JSMaskedTextField extends JTextField {
        /** Masking for alphabetical lowercase characters only. */
        public static final String MASK_ALPHA_LCASE = "abcdefghijklmnopqrstuvwxyz ";
        /** Masking for alpha-numeric characters (lcase/ucase) only. */
        public static final String MASK_ALPHA_NUMERIC = "0123456789abcdefghijklmnopqrstuvwxyzABCDEFGHIJKLMNOPQRSTUVWXYZ ";
        /** Masking for alphabetical uppercase characters only. */
        public static final String MASK_ALPHA_UCASE = "ABCDEFGHIJKLMNOPQRSTUVWXYZ ";
        /** Masking for numbers only. */
        public static final String MASK_NUMERIC = "0123456789";
        /** Masking for hexadecimals. */
        public static final String MASK_HEXADECIMAL = "0123456789ABCDEF";
         * An array of keyevent constants defining which keys are always to be
         * allowed, no matter what.
        private final int[] ALWAYS_ALLOWED = new int[] { KeyEvent.VK_BACK_SPACE,
                KeyEvent.VK_DELETE, KeyEvent.VK_UP, KeyEvent.VK_DOWN,
                KeyEvent.VK_LEFT, KeyEvent.VK_RIGHT, KeyEvent.VK_SHIFT,
                KeyEvent.VK_HOME, KeyEvent.VK_END};
        /** Boolean specifying whether casing should be ignored. */
        private boolean ignoringCase = true;
        /** Specifying whether the maskin is enabled */
        private boolean isMaskingEnabled = true;
        /** The mask for the textfield. */
        private String mask = MASK_ALPHA_NUMERIC;
         * Creates a default number field.
        public JSMaskedTextField() {
            super(null, null, 0);
            Arrays.sort(ALWAYS_ALLOWED);
         * Creates a number field, with a specified number of columns.
         * @param columns The columnnumber.
        public JSMaskedTextField(int columns) {
            super(null, null, columns);
            Arrays.sort(ALWAYS_ALLOWED);
         * Creates a JSMaskedTextField with a masking.
         * @param mask The masking to be used.
        public JSMaskedTextField(String mask) {
            super(null, null, 0);
            Arrays.sort(ALWAYS_ALLOWED);
            setMask(mask);
         * Gets the masking for this masked textfield.
         * @return Returns the mask.
        public String getMask() {
            return this.mask;
         * Gets whether this JSMaskedTextField should be ignoring casing.
         * @return Returns if the component should be ignoring casing.
        public boolean isIgnoringCase() {
            return this.ignoringCase;
         * Checks whether masking is enabled. Default should be true.
         * @return Returns true if masking is enabled, false if not.
        public boolean isMaskingEnabled() {
            return this.isMaskingEnabled;
         * Sets whether it should be ignoring casing when checking for alpha-chars.
         * @param ignoringCase The ignoringCase to set.
        public void setIgnoringCase(boolean ignoringCase) {
            this.ignoringCase = ignoringCase;
         * Sets the masking for this textfield. The masking will determine which
         * characters can be typed. If the characters in de <code>mask</code> do
         * not occur in the typed character, it won't be typed.
         * @param mask The mask to set.
        public void setMask(String mask) {
            this.mask = mask;
         * Sets the masking enabled. If <code>false</code> this component will
         * behave just like a normal textfield.
         * @param isMaskingEnabled true if masking should be enabled.
        public void setMaskingEnabled(boolean isMaskingEnabled) {
            this.isMaskingEnabled = isMaskingEnabled;
         * Sets text of this textfield. If the blah blah.
         * @see javax.swing.text.JTextComponent#setText(java.lang.String)
        public void setText(String text) {
            for (int i = 0; i < text.length(); i++) {
                if (getMask().indexOf(text.charAt(i)) < 0) { // does not occur
                    return;
            super.setText(text);
         * @see javax.swing.JComponent#processKeyEvent(java.awt.event.KeyEvent)
        protected void processKeyEvent(KeyEvent e) {
            if (!isMaskingEnabled()) {
                return;
            char typed = e.getKeyChar();
            int code = e.getKeyCode();
            for (int i = 0; i < ALWAYS_ALLOWED.length; i++) {
                if (ALWAYS_ALLOWED[i] == code) {
                    super.processKeyEvent(e);
                    return;
            if (typed == KeyEvent.VK_BACK_SPACE) {
                super.processKeyEvent(e);
            if (isIgnoringCase()) {
                String tString = new String(typed + "");
                String ucase = tString.toUpperCase();
                String lcase = tString.toLowerCase();
                if (getMask().indexOf(ucase) < 0 || getMask().indexOf(lcase) < 0) {
                    e.consume();
                } else {
                    super.processKeyEvent(e);
                    return;
            } else { // not ignoring casing
                if (getMask().indexOf(typed) < 0) {
                    e.consume();
                } else {
                    super.processKeyEvent(e);
    }

  • Report/ Tool to identify the users sync information in Syclo?

    Hi Experts,
    Is there any way to identify last sync time of the users/mobile devices.  Is there any report/tool we can use to find this information?
    When the users need to sync their devices for the changes -- I think after deploying the build to server the users needs to sync their devices then the updated definitions will be downloaded to the device.
    Please provide some ideas.
    Thanks & Regards,
    Swaroopa
    Tags edited by: Michael Appleby

    There is  no need to push Agentry  defintions to users once deployed to Server,  SMP/Agentry service will take care of pushing any new changes  to users  when sync next time.   Server will check  whether definitions on client and Agentry server are same if not changes will be pushed to the client
    Check /n/scylo/admin TCODE in SAP, there are lot of monitoring/Administration/statistics reports available.
    Thanks
    Manju.  

  • Functionality in Discoverer 11g to limit the users or reports that consume

    Experts,
    I am using Discoverer 10g(9.0.4) ... we are upgrading to Discoverer 11g Fusion Middleware . i want to know if there is any functionality in 11g where we can limit the resources for users or reports that they usually consume in 10g .......
    let me know if my question is not clear?

    Hello,
    If I understand your question correctly, no this is not possible. There is no tool or method to have Discoverer 11g review the 9.0.4 statistics/usage and then limit the resources based upon the 9.0.4 usage.
    You can limit the number of rows returned or set requirement to schedule worksheets that are estimated to take over specific time and other such settings. These same settings are available in 9.0.4 as well.
    Regards,
    Sharon

  • I connected my ipad to a diff. Laptop then i think the laptop synced with ipad. When i opened the ipad,  i cannot log in to my icloud account, the fb of the owner of the laptop synced with my ipad, all my photos were deleted. How can i retrieve every

    I Connected my ipad air2 to a different laptop and it synced. i lost all my photos, they,re asking for the apple id of the person who pwned the laptop. How can i retrieve my icloud account and how can i retrieve everything

    Have you tried syncing with your own computer. The one you used to sync the photos to your iPad in the first place?
    Do you have a backup of your iPad on your own computer? Or in iCloud?
    If your iPad is stuck to the Apple ID and password used by the different laptop have the owner of that laptop remove your device from their iCloud account. They can go to iCloud.com on their laptop, enter their Apple ID and password and then remove your iPad from their account.
    Once you sign into your own Apple ID and password and then sign in to your iCloud account, many of your lost items should come back. Specifically these include your Contacts andCalendar entries.

Maybe you are looking for

  • External Drive causes Kernel Panic

    I've been struggling with Time Machine on a Seagate external 1TB drive. Backups have failed consistently since I upgraded to Lion, taking a really long time or generating error messages and failing. I read Pondini ( http://pondini.org/TM/D2.html ), a

  • Adobe Reader 10.1.2 duplex option broken

    After installing the latest upgrade to 10.1.2, Adobe Reader X fails to print single pages, when the "Print on both sides of paper" option is selected.  It gives no error message, but nothing prints, and the printer queue is empty. Is this a new probl

  • Powershell - Help with returning dynamic variable values

    Add-Type -AssemblyName System.Windows.Forms $frm1 = New-Object System.Windows.Forms.form $frm1.Name = "Hey" $flw1 = New-Object System.Windows.Forms.FlowLayoutPanel $flw1.flowdirection = 'TopDown' $frm1.controls.add($flw1) $m = "apple","orange","banan

  • 10.5.5 - Upgrade fails!

    Hi, I can't upgrade to 10.5.5. It started donwloading the upgrade, but after downloading just 5 mb it started installing and then stalled. Can I somehow erase the current downloaded content (the 5 mb) and then download it again?

  • Need to change CSR key size from 1024 to 2048

    Hello SAP experts, I am encountering an error when generating new certificates: · Invalid Key Size Current Key Size: 1024 The key size in the provided CSR is not valid. The key size must be at least 2048. Please attempt the request again. If the prob