Users/groups not visible in WGM after migration. (UIDs lower than 500)

I have migrated from a 10.5 to a 10.6 server.
Some of my user & groups are not visible in the WGM. However, the user can login to the system.
I discovered that if I check Workgroup Manager > View > Show System Records, that I can see the missing users and groups. The users and groups all of UID/GID's from 100 to 130.
All of the affected users & groups were created many versions ago, probably Mac OS X 10.1 Server. The accounts that are visible are newer and have UID's starting in either at 501 or 1025. So it looks like overtime OS X server has changed what ID's are used for system vs. users.
What is the proper way to solve this problem? The WGM will let me to manually change the UID/GID, but I am worried about doing this will not change file ownerships.
Thansk!

You are correct, the ACL and or POSIX permissions will not update if you just change the UID of the group or user account. You will need to add the new UID to the directories in question. And be sure to propagate the permissions.
I would take one each group and user account and use it as a test case to discover how much is involved. Document what steps are needed to make the changes and then do them in bits and pieces.

Similar Messages

  • OIM 11gR2 : User groups not visible on UI

    Hello Experts,
    I have a requirement in which i need to assign the user provisioned to AD to some group(s) depending upon certain conditions like BU, Location etc. I created a Process Task adapter for the same and am able to successfully assign the users to the desired groups.
    But i am able to check for this validity from the Backend only.
    Ideally the groups assigned to the user must be visible after following these steps:
    *1. Search for a user provisioned to AD.
    2. Go the the Accounts tab.
    3. Click on the AD account (to which the user has been provisioned)
    4. A process form is displayed in the lower half of the webpage which also shows the information regarding the groups assigned to the User. But the groups are not getting displayed.*
    Kindly Help.
    Edited by: IDM_newbie on Jan 24, 2013 11:24 PM

    But sir, the groups are listed under the Accounts tab. Is there any schedule job provided by OIM 11gR2 which results in the display of Groups assigned to the user as well under the Accounts tab ?
    Edited by: IDM_newbie on Jan 25, 2013 1:51 AM

  • LDAP user groups not visible for configuring a Group Portal

    Hi,
    We have created a Custom Security Realm(myRealm) on WebLogic 7.0 SP2 in which
    I've added the Novell LDAP Authentication provider as the authentication provider
    and then set "myRealm" as the default realm for the domain. I am able to start
    the WLS server instance and login to portalAppTools with the "administrator" account.
    We would like to configure a Group Portal. In Portal Administration interfaces,
    when I click on Group Administartion, I am unable to see any of my external LDAP
    groups. I know that we cannot create/delete users or groups in the external LDAP
    repository thru the Admin UI but the documentation says that I should be able
    to view the users/groups in the Admin UI. Authentication against the external
    LDAP repository works fine. Can anybody suggest the reason why we are unable to
    view any of the Users or Groups in our external LDAP repository thru the User
    Administration interfactes.
    Appreciate any feedback.
    Thanks
    Vikram

    Hi Jim,
    I've configured a default LDAP V2 Compatibility Realm by modifying the Config.xml
    file. I was able to restart Weblogic and see the LDAP Groups and Users thru the
    WLS console. In our project we've a unique requirement wherein all Application
    Groups and User Accounts would be stored in an LDAP repository and all BEA SERVICE
    level accounts and groups are stored in a Database (groups like AdminEligible,
    Administrators etc.). We need to be able to look at the groups in both the Database
    and LDAP repositories in order to administer and configure a Group Portal. On
    the outset it looks like we will not be able to do what we want to with the current
    portal framework. Please suggest if there are any alternatives in order to implement
    this solution. I am sure there are lot of other Clients who cannot create groups
    like Administrators, AdminEligible etc in their LDAP repositories and will be
    forced to think of alternatives.
    I would appreciate if you can reply back at your earliest convenience.
    Thanks
    Vikram
    Jim Litton <replyto@newsgroup> wrote:
    The Weblogic 7.0 Authentication Providers (new JAAS Framework) is not
    supported with Portal 7.0. You will need to configure the Compatibility
    Security CustomRealm for Novell to try to get Portal working.
    see defaultLDAPRealmForNovellDirectoryServices at
    http://e-docs.bea.com/wls/docs61/adminguide/cnfgsec.html#1083149
    In addition, remember to test functionality through the Weblogic
    Console. If you can see groups and users there okay it is very likely
    that Portal will operate.
    -- Jim
    Vikram wrote:
    Hi,
    We have created a Custom Security Realm(myRealm) on WebLogic 7.0 SP2in which
    I've added the Novell LDAP Authentication provider as the authenticationprovider
    and then set "myRealm" as the default realm for the domain. I am ableto start
    the WLS server instance and login to portalAppTools with the "administrator"account.
    We would like to configure a Group Portal. In Portal Administrationinterfaces,
    when I click on Group Administartion, I am unable to see any of myexternal LDAP
    groups. I know that we cannot create/delete users or groups in theexternal LDAP
    repository thru the Admin UI but the documentation says that I shouldbe able
    to view the users/groups in the Admin UI. Authentication against theexternal
    LDAP repository works fine. Can anybody suggest the reason why we areunable to
    view any of the Users or Groups in our external LDAP repository thruthe User
    Administration interfactes.
    Appreciate any feedback.
    Thanks
    Vikram

  • Personal folders not visible in Thunderbirds after migration to new computer

    I moved my Thunderbird profile to a new computer (and edited profiles.ini to point to the backed-up profile. Now in Thunderbird on the new machine I have the Local Folders Inbox, Sent, Trash, but the Personal Files folder with my saved and categorized mail sub-folders is not visible in the left-hand panel. It appears to be intact in the /Mail/Local Folders/Personal Folders.sbd/Archives.sbd folder, just not visible when I run Thunderbird.
    What do I have to do to get these folders and their subfolders back again.
    ...Doug

    Doug,
    I had the same problem, and believe I found the solution. I was transferring a profile from one computer running Win XP to a new computer running Win 7.
    I could see the file folders evident, as you did, using Windows Explorer to look in the profile folder, but they were not showing in the left hand pane of Thunderbird when it was running as they did in the XP machine.
    I went to the "Tools" menu, selecting "Account Settings," and then clicked on "Local Folders" in the left portion of the dialog box. Then in the right portion of the dialog box under "Local directory:" I selected the "Browse" button. I then browsed down into the "...AppData\Local\Thunderbird\Profiles\xxxxxxxx.default\Mail\Local Folders\Outlook Express Import.sbd" ( in my case - the very last portion of yours might be different but should probably still be a ".sbd" file, and of course, the eight x's would be the random name Thunderbird assigns to your Profile file. ) I then clicked the "OK" button at the bottom of the dialog box. ( I believe the program then informs you it must close and restart. ) Anyway, go ahead and close Thunderbird and restart at this point.
    When it restarts, my old folder structure appeared as it did on the earlier machine, and all the files were intact.

  • "podcasts" is not visible in iTunes after software update

    iTunes no longer shows "podcasts" as a category.  I have several active subscriptions--they seem to have disappeared.  All of the other usual categories (e.g., music, TV shows) are still there.  This occurred immediately after I downloaded today's iTunes upgrade.  I have tried downloading more podcasts.  That happens fine--but they are not visible from iTunes after the download.

    I can re-check the "podcasts" box in the Windows version.  It's not grayed out.  But there doesn't seem to be any way to save my changes.  Didn't the "preferences" dialog box used to have a "save changes" button at the bottom? 

  • My other mail boxes are not visible in mail after upgrading to Mountain Lion

    my other mail boxes are not visible in mail after upgrading to Mountain Lion

    In the mailbox panel move your cursor slowly down the right hand side . Should reveal show and hide.

  • Keyboard not visible in whatsapp after I upgraded to ios7. I have to type on the chat to get my keyboard visible. This is a bug :( poor testers..

    Keyboard not visible in whatsapp after I upgraded to ios7. I have to type on the chat to get my keyboard visible. This is a bug poor testers..

    Hello dhiliptcs,
    It sounds like the WhatsApp app on your iPhone does not have a visible keyboard.  I recommend following the steps in the article below for an issue like this (you can skip step 3 since it is not related to this issue):
    iOS: Troubleshooting apps purchased from the App Store
    http://support.apple.com/kb/TS1702
    Thank you for using Apple Support Communities.
    Best,
    Sheila M.

  • Users & Groups not in Get Info options

    When opening a Get Info window to change Sharing & Permissions, adding a new entry to the list shows maybe 4 options when the OS has dozens of users & groups. Why are standard options like "staff" not showing up?

    I need to enable a folder to be read/write by "staff" for a specific application I am using, and the new GUI isn't allowing me to do that
    What app is it? Why does it require you to do this? What folder is it that you want to modify? What are you trying to achieve? More then likely there is a better way to do it, or may not be needed in the first place.
    Lasso web application. In order to execute file editing commands (read txt files, write them, manipulate uploads, etc), the target file/folder must have, under the POSIX rules of 10.4, either an owner of "lasso" (a user created by the software), or the group of "staff."
    In order to make the source code files themselves easy to administer on the server, I typically have always left owner as the main user I log into the system with, and set group to staff. This is the most convenient configuration for ≤ 10.4 systems.
    In 10.5, after copying files to servers I'm seeing a mixture in the Get Info ACL of {user owner}, admin, and everyone in some systems, and {user owner}, staff, and everyone in other systems. Haven't tracked down why the difference (I suspect preservation of permissions somehow during the copy). Even when staff is in the ACL, it's not a part of the options the GUI presents.
    Anyway, I was trying to take advantage of the ACL in allowing two otherwise separate users/groups to have some shared access, and needed "staff" as a group for these files.
    I didn't just use the chgrp command as I don't yet know the consequence of using POSIX commands on what I want to be ACL controls. So, am trying to do some digging into all that now. I was just thrown by the lack of visibility of all the usual user & groups options I am used to seeing in ≤ 10.4.

  • Message thrown as User group not created

    Hi,
    When the User tries to access a Transaction Code which is a (Query created from table BSEG) he gets a message that User Group has not yet been created, where as the User Group has been created and can be seen.
    We checked the SU53 screen after accessing this transaction and all checks were successful.
    Please provide ur suggestions.
    Regards,
    Priya

    Just check if the query is attached is to a User Group or not .
    GOTO to SQ02 find the infoset for the query
    goto to Environment->User Group .
    Please check this and reward if useful.

  • Groups not visible in GAL

    Hi All,
     We are in co-existence with OCS 2007 R2 and Lync 2013. The security groups are visible in the users who are still located at OCS pool and using OCS client, but not users who are moved to Lync 213 and using Lync 2013 client and OCS 2007 R2 pool users
    and using Lycn 2013 client. Both the files GalContacts.db
    and GalContacts.db.idx
    are not seen among the uses who use Lync 2013 clients.
    Which server generated the address book OCS FE or Lync 2013 FE during the co-existence? How to configure Lync 2013 FE to generate the Addressbook.
    Regards,
    Swamy

    I have noticed the command fails when i use  -TargetUri https://southlyncpool.contoso.com/abs/handler, but succeeds when i use -TargetUri https://southlyncintweb.contoso.com:443/abs/handler
    adding :443 at the URL suceeds !!
    Test-CsAddressBookService -TargetUri https://southlyncpool.contoso.com/abs/handler -UserSipAddress "sip:[email protected]"
    Target Fqdn   :
    Target Uri    : https://southlyncpool.contoso.com/abs/handler
    Result        : Failure
    Latency       : 00:00:00
    Error Message : Getting web ticket for the given user is failed. Error Code: 28037 , Error Reason: The AppliesTo element of web ticket request points to a different web server or site.
    Diagnosis     :
    Test-CsAddressBookService -TargetUri https://southlyncintweb.contoso.com:443/abs/handler -UserSipAddress "sip:[email protected]"
    Target Fqdn   :
    Target Uri    : https://southlyncintweb.contoso.com:443/abs/handler
    Result        : Success
    Latency       : 00:00:00
    Error Message :
    Diagnosis     :

  • Application not visible in PDA  after server deployment

    Hi All,
    I developed an Mi 7.1 application.Deployed  all the sdas in the Mi server using sdoe_upload_archive.I created a device.Assigned all the mobile components to the device .I synchronized the device and it is successful.
    I can see the service and mobile ui component in the  mobileapps folder of the device.
    But I am not able to see the application in the application launcher of the  PDA.
    Any clues in resolving this?
    Thanks and regards,
    Rajesh.A

    Hi Rajesh,
    The application link may not be visible for the below given reason. Check whether it solves your issue :
    Reason 1. If the role SAP_DOE_ALL_APP_VISIBLE is missing for the user on the DOE system, then the application link is not visible on the home page.
    Solution 1. Add the role via agents in the NWM portal.You should also perform a delta download for the following data objects in the SAP BASIS 7.10 software component version (SWCV):
    1. USERDETAILS
    2. USER_AUTHORIZATION
    Reason 2. The application link is not visible because of the user authorization issue. Check whether the SAP BASIS 7.10 software component version is assigned to the device or not.
    If the SAP BASIS 7.10 software component version is not assigned to the device, then follow either of the steps specified below (2a or 2b):
    Solution 2a. Disable the authorization check on the mobile client
    (For PDAs)
    This can be done by creating a configuration.properties file in the \MI\Settings\ folder with the entry com.sap.tc.mobile.cfs.deploy.check_authorizations=false. Stop and start the client. The file is consumed, the authorization check is disabled, and then the application is visible in the application launcher.
    Solution 2b. Assign the authorization-related SWCV to the device (in the NWM portal)
    In the NWM portal, go to the DMSWCV tab in Device Management. Manually assign the SWCV containing the authorization data objects (SAP BASIS 7.10). Trigger an extract. Synchronize the device. The authorization objects are now available on the device. The application appears in the application launcher.
    Reason 3. If the installed client version and the NWMCLIENT.SCA version uploaded in the DOE are different, even then the application link is not visible on the home page.
    Solution 3. Upload the NWMCLIENT.SCA (same version of the client) to the DOE using transaction SDOE_UPLOAD_ARCHIVE.
    Regards,
    Suma

  • Custom attributes added to user objects not visible in OWA address book

    Hi,
    I am using Exchange 2013 and recently added a new custom attribute in the user object properties using the details template editor to be visible in the GAL  The new attribute is correctly getting displayed in the GAL from outlook clients but not visible
    in OWA address book. Is there a way to update the display of user objects in OWA address book to include the new custom attribute?
    Thanks!

    Hi Abu,
    Please see following link:
    Customize Details Templates
    http://technet.microsoft.com/en-us/library/ms.exch.toolbox.detailstemplate(v=exchg.150).aspx
    It says, Use the Details Templates Editor to customize the client-side graphical user interface (GUI) presentation of object properties that are accessed by using address lists in Microsoft Outlook.
    My understanding is this setting only visible in Outlook.
    Please correct me if there is any misunderstanding.
    Thanks
    Mavis
    Mavis Huang
    TechNet Community Support

  • New user creation in AE- user group not getting assigned

    Hi All,
    Here is a typical case, wherein when we create a new user with AE for the production system, the user gets created and the roles are also assigned but the user group is not getting assigned. The user group is being fetched from a table from the backend and all that is working fine. Infact in order to test the configurations we even created a new user in the production instance of AE giving the development system as the target system for user creation and in this case the user was successfully created and the user group is also assigned. The problem is arising only when the target system is production system.
    Connectors are all working fine, but we are unable to think of a reason. Can somebody help us on this?

    Hi Vani,
    If you are provisioning the user group using user defaults, check  that production system is selected in the user defaults configured. Configuration -> user defaults. You can define any user default system, but for perticuticular user defaults that is applicable define all the systems, in which you want user defaults to be provisioned.
    Kind Regards,
    Srinivasan

  • Batch Risk Analysis in Full Sync mode with special user groups not working

    Dear All,
    we start Batch Risk Analyse Job in Full Sync with special User groups (use Range). In the Joblog I can see, that he selecet lesser users as in jobs before. But after all is finished (also managment job) when I go in Informer, he shows me also this user groups I have no analysed in Backgroudjob... Also he shows me in the detailed anlayse the date from a run before.. And we have deactivated some Risk - these are still in the analysis.
    Have some one a information for me what here is wrong..
    Best Regards
    Gabriele Herr

    to old..

  • Process chain is not visible in Quality after TR transport

    Hi,
    I have transported process chain to Qua, but its not visible, only the technical id of process chain is displayed in RSPC tcode. I've tried activating through RSPC_CHAIN_ACTIVE_REMOTE, but still, its not visible in rspc tcode.

    Thru not assigned nodes you have issue.
    All objects are at prod not in place or not inactive.
    So first transport your data flow objects(one by one as suggested at another thread) one by one again to prod and make them proper activation.
    at final you can transport your process chain into prod and check it.
    With out info pack/dtps at prd, connected process chain how will display the chain.
    One the data flow you have issue, please try understand the issue and re transport whole data flow.

Maybe you are looking for