Issues with AD sync

avatar

Hello all,

We are having issues with AD Sync scheduler in RDM.
All our AD OUIs and Computer objects are synced perfectly.
When we create shortcuts out of the synced objects (entries) and the sync job runs after, it deletes all created shortcuts and AD entries related to those shortcuts, and syncs the entries again, so we need to create again the shortcuts.
Custom settings are lost on those objects.

Here are some settings from the sync scheduler:

LDAP is used
Create folders from OU/containers
Level 3
Session name: Host and description
Host DNS host name (FQDN)
Import description
Search scope: Subtree
Duplicate check: Destination folder
Verify folder on mismatch
Update non-critical fields on mismatch
Action on entry mismatch = delete

RDM Version: 2023.1.20.0


Regards,

Sameeer

All Comments (7)

avatar

Hello Sameer,

Thank you for getting in touch with us about the issue.

Based on the configuration you provided, it seems that the "Action on entry mismatch" setting is set to "Delete". This means that if a change has been made to an entry, the previous version of that entry will be deleted in order to prevent duplicates.

Therefore, since the entry has been removed, it is expected that the shortcuts associated with it will also be removed.

I will reach out to our engineering department to see if there could be an alternative method that would allow you to keep the shortcuts.

Please let us know if you have any further questions or concerns.

Best regards,

Samuel Dery

avatar

Hello Saumel,

Thx for the feedback.
We set "Action on entry mismatch" to delete, so that entry which we delete in AD will be also deleted in RDM.
Hopefully there is a posibility to have this in place with the shortcuts.


Regards,

Samir

avatar

Hello Samir

Thank you for your reply,

After further discussion with our engineering department, I'm afraid this would be the expected behavior since when performing the sync any entries that have been changed will trigger a mismatch and will be recreated with a different ID causing any existing shortcuts or changes to be lost.

Let me know if you have further questions regarding this,

Best regards,

Samuel Dery

avatar

Hello Samuel,

Thank you for the feedback.

Is there any posibility to setup AD sync, so that the sync is only looking for changes on the Domain OU level and not RDM ?
That means if a change is done on AD OU (OU is being deleted, computer object deleted) that those changes are synced in RDM and entries or OUs are deleted in RDM as well.
This is what i expected to be honest :)

Best regards,

Samir

avatar

Hello Samir,

Thank you for your reply,

I see, I will discuss this with our engineering department and get back to you once I have news,

Best regards,

Samuel Dery

avatar
I second this thought process as well. I have experienced this duplication entries for as long as I can remember. I have an open case right now because deleting 300+ duplicate entries is a pain when the AD sync has a hiccup. Running the Duplicate report help to find them but tagging all of them is a challenge as the duplicate report does not contain a column to view by creation dates. This has let me into deleting the wrong entries which results in the removal of the shortcut (favorites) items that the users have saved.

We should be allowing the ability to check against the HOST name/server name as key identifiers instead of Entry ID or at least flag duplicates before importing them. Imo. Ticket#: 00028927



Hello Samuel,

Thank you for the feedback.

Is there any posibility to setup AD sync, so that the sync is only looking for changes on the Domain OU level and not RDM ?
That means if a change is done on AD OU (OU is being deleted, computer object deleted) that those changes are synced in RDM and entries or OUs are deleted in RDM as well.
This is what i expected to be honest :)

Best regards,

Samir
avatar

Hello,

Thank you for your patience,

As mentioned I've discussed this with our engineering department and they have confirmed that if the entries were originally created with the Synchronizer and the "Mismatch Action" is set to "Delete" the entries should be automatically deleted when performing the sync.

Let me know if this helps or if you have further questions regarding this,

Best regards,

Samuel Dery