<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Bulk Grant Access to Jabber in Collaboration Applications</title>
    <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446855#M46315</link>
    <description>&lt;P&gt;It depends on your Domain Tree.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Domain :- abc.com&lt;/P&gt;
&lt;P&gt;Assume you have two main OU, OU:- new user and OU:- user.&lt;/P&gt;
&lt;P&gt;OU:- new user&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Assume two sub OU's ,&amp;nbsp; OU staff and OU IT is under User.&lt;/P&gt;
&lt;P&gt;OU:- user&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OU:- staff&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OU:- It&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;LDAP autenticaion work for a secario where your LDAP directory search base has OU=staff,DC=abc,DC=COM,&amp;nbsp; OU=it ,DC=abc,DC=COM and with Authentication search base&amp;nbsp; OU=user ,DC=abc,DC=COM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if you add third&amp;nbsp; LDAP directory with search base, OU=new user,DC=abc,DC=COM&lt;/P&gt;
&lt;P&gt;Authentication wont work with OU=user ,DC=abc,DC=COM.&lt;/P&gt;
&lt;P&gt;It should cover the entire domain and you need DC=abc,DC=COM to cover all the OU's&lt;/P&gt;</description>
    <pubDate>Tue, 10 Aug 2021 05:00:20 GMT</pubDate>
    <dc:creator>Nithin Eluvathingal</dc:creator>
    <dc:date>2021-08-10T05:00:20Z</dc:date>
    <item>
      <title>Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4445677#M46300</link>
      <description>&lt;P&gt;Hello I have had this question for some time. I would like to know if there is an easy way to grant access to Jabber during an LDAP sync. Specifically if I can just add users to an AD group that when processed by CUCM, will give them the necessary permissions to access jabber.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I need to grant users access to jabber by adding them to the 'standard CTI enabled' and the 'standard CCM End Users' groups and selecting the two related check boxes on their user profile. The latter I am able to do through the Bulk admin tool but to add the users to the groups in mass, I must find the groups themselves and add user by department (not all depts get access to jabber so its not all users). This requires three separate actions; Bulk update, first group, second group. How can I automate this so when new users are added, I can grant them access without the administrative overhead?&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 20:48:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4445677#M46300</guid>
      <dc:creator>broncosjkb</dc:creator>
      <dc:date>2021-08-06T20:48:01Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4445696#M46301</link>
      <description>&lt;P&gt;CUCM 11.5+ where you configure the LDAP agreement in that same page you can add information under Group Information, rank, access controls groups and feature group template. That is only applicable for new users brought through that LDAP agreement and would affect anyone who is synced with it.&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 21:29:18 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4445696#M46301</guid>
      <dc:creator>Jaime Valencia</dc:creator>
      <dc:date>2021-08-06T21:29:18Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4445701#M46302</link>
      <description>&lt;P&gt;Hey Jaime, thank you for the reply, I think this is what I am looking for. I went ahead and created a Group template. If I can apply that template and the groups to users that I put into an AD group, im set. I'm still wondering how to exactly tie that template + group info to an AD group specifically. The last two lines of that section reference directory numbers which these users will not have.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Do you possibly know of some good documentation regarding this section?&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank again!&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;</description>
      <pubDate>Fri, 06 Aug 2021 21:41:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4445701#M46302</guid>
      <dc:creator>broncosjkb</dc:creator>
      <dc:date>2021-08-06T21:41:11Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4445763#M46303</link>
      <description>&lt;P&gt;You can apply both feature group template and access control group on LDAP directory page. &amp;nbsp;while synching &lt;STRONG&gt;new users&lt;/STRONG&gt; the Feature and control groups will get applied.&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Add required informations on below fileds.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2021-08-07 at 7.26.24 AM.png" style="width: 999px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/127369i7936F316CC033A3B/image-size/large?v=v2&amp;amp;px=999" role="button" title="Screenshot 2021-08-07 at 7.26.24 AM.png" alt="Screenshot 2021-08-07 at 7.26.24 AM.png" /&gt;&lt;/span&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;A href="https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/11_5_1/sysConfig/CUCM_BK_SE5DAF88_00_cucm-system-configuration-guide-1151/CUCM_BK_SE5DAF88_00_cucm-system-configuration-guide-1151_chapter_0100101.html" target="_blank" rel="noopener"&gt;https://www.cisco.com/c/en/us/td/docs/voice_ip_comm/cucm/admin/11_5_1/sysConfig/CUCM_BK_SE5DAF88_00_cucm-system-configuration-guide-1151/CUCM_BK_SE5DAF88_00_cucm-system-configuration-guide-1151_chapter_0100101.html&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 06:41:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4445763#M46303</guid>
      <dc:creator>Nithin Eluvathingal</dc:creator>
      <dc:date>2021-08-07T06:41:25Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4445778#M46304</link>
      <description>&lt;P&gt;If you need to apply these settings for a specific group of people and base this on membership in a group in AD you’d need to create an LDAP filter and include this as one of the filter criteria’s. If you search the community for LDAP filters you’ll find quite a lot of posts around this. Once you have the filter you need to create another LDAP sync definition that runs &lt;STRONG&gt;before&lt;/STRONG&gt; the current one. This is to have the settings set on the users that match the group and then also get the rest of the users into the system by the original LDAP sync definition. Remember as Java wrote that the settings are only set on the user during the very first sync, this is why you need to have the one that uses a filter to run before the other one.&lt;/P&gt;
&lt;P&gt;One thing to keep in mind is that CM uses a default LDAP filter for AD, even if there are no filter defined in the system. When you create your own filter it’s recommended to include the content of this default filter as part of the custom filter. Have a look at at the CM system configuration guide for details on this.&lt;/P&gt;</description>
      <pubDate>Sat, 07 Aug 2021 06:50:54 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4445778#M46304</guid>
      <dc:creator>Roger Kallberg</dc:creator>
      <dc:date>2021-08-07T06:50:54Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446502#M46307</link>
      <description>&lt;P&gt;Hey Thanks everybody! I did end up getting this sorted out. For anyone else with this issue, here is what I did.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Created an AD group&lt;/P&gt;&lt;P&gt;Created an LDAP custom filter to grab that group&lt;/P&gt;&lt;P&gt;Created and additional LDAP directory config using the new filter&lt;/P&gt;&lt;P&gt;On this directory, I added the group info (Access Control groups and my Jabber template) and hit save&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Now this new synch runs one hour before my other sync.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all for your support on this&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 14:58:35 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446502#M46307</guid>
      <dc:creator>broncosjkb</dc:creator>
      <dc:date>2021-08-09T14:58:35Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446656#M46309</link>
      <description>&lt;P&gt;I would like to ask if having multiple LDAP directories can cause issues with authentication?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just forewarning to anyone who was going to go the same route as me. I completely broke LDAP authentication.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 18:42:01 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446656#M46309</guid>
      <dc:creator>broncosjkb</dc:creator>
      <dc:date>2021-08-09T18:42:01Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446669#M46310</link>
      <description>&lt;P&gt;No, you can have multiple LDAP agreements, the one thing to consider is that you only have &lt;STRONG&gt;ONE&lt;/STRONG&gt; LDAP authentication agreement and it needs to point high enough in the tree to cover all the LDAP agreements you configured.&lt;/P&gt;
&lt;P&gt;Adding LDAP agreements would not break authentication for users if it was working before, they're separate configurations.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 18:55:48 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446669#M46310</guid>
      <dc:creator>Jaime Valencia</dc:creator>
      <dc:date>2021-08-09T18:55:48Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446670#M46311</link>
      <description>&lt;P&gt;No that’s not what caused the authentication to not work. Directory synchronisation and authentication is two different things in CM that has its own configuration items.&lt;/P&gt;
&lt;P&gt;We used to have multiple directory synchronisation setups and it did not have any effect on authentication.&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 18:59:37 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446670#M46311</guid>
      <dc:creator>Roger Kallberg</dc:creator>
      <dc:date>2021-08-09T18:59:37Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446678#M46312</link>
      <description>&lt;P&gt;assume that your AD domain is abc.com and you have OU's staff, user, it etc...&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Since you can create multiple &amp;nbsp;LDAP directories, you can use either &amp;nbsp;entire domain as search base I.e DC=abc,DC=com or you can keep it based on OU. I.e&amp;nbsp;OU=user,DC=abc,DC=com&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;For LDAP authentication settings,&lt;SPAN&gt;Navigate to &lt;/SPAN&gt;&lt;STRONG&gt;CUCM Administration &amp;gt; System &amp;gt; LDAP Authentication&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But &amp;nbsp;authentication can be only one. so to cover the entire domain. use &amp;nbsp;&lt;/P&gt;
&lt;P&gt;search base DC=abc, DC=com&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 19:12:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446678#M46312</guid>
      <dc:creator>Nithin Eluvathingal</dc:creator>
      <dc:date>2021-08-09T19:12:22Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446730#M46314</link>
      <description>&lt;P&gt;Interesting. It sounds like what I did may not have been the root cause then. It seemed like right after I made the change, LDAP broke. I was unable to sign into jabber or authenticate into the CUCM admin page with my AD account. I was also making some application dial rule changes at the same time, which should not have caused issues. I'm thinking I might have synced myself into this new group and stripped my admin rights or something weird. In my panic to bring fix this issue, I did not take a good approach to remediation and just deleted all the work I had done so far, which fixed the issue.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;I have had about enough troubleshooting for the day, but I will probably re-create the directory tomorrow and see if anything breaks.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Just to confirm, I can have two LDAP directories for the same Domain without causing issues with authentication. I was just thinking of these as Sync configurations, would that be correct?&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;Thank you all again for your replies&lt;/P&gt;&lt;P&gt;James&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 09 Aug 2021 20:32:25 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446730#M46314</guid>
      <dc:creator>broncosjkb</dc:creator>
      <dc:date>2021-08-09T20:32:25Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446855#M46315</link>
      <description>&lt;P&gt;It depends on your Domain Tree.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Domain :- abc.com&lt;/P&gt;
&lt;P&gt;Assume you have two main OU, OU:- new user and OU:- user.&lt;/P&gt;
&lt;P&gt;OU:- new user&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Assume two sub OU's ,&amp;nbsp; OU staff and OU IT is under User.&lt;/P&gt;
&lt;P&gt;OU:- user&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OU:- staff&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; OU:- It&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;LDAP autenticaion work for a secario where your LDAP directory search base has OU=staff,DC=abc,DC=COM,&amp;nbsp; OU=it ,DC=abc,DC=COM and with Authentication search base&amp;nbsp; OU=user ,DC=abc,DC=COM.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;But if you add third&amp;nbsp; LDAP directory with search base, OU=new user,DC=abc,DC=COM&lt;/P&gt;
&lt;P&gt;Authentication wont work with OU=user ,DC=abc,DC=COM.&lt;/P&gt;
&lt;P&gt;It should cover the entire domain and you need DC=abc,DC=COM to cover all the OU's&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 05:00:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446855#M46315</guid>
      <dc:creator>Nithin Eluvathingal</dc:creator>
      <dc:date>2021-08-10T05:00:20Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446859#M46316</link>
      <description>&lt;P&gt;Also please remember that whatever changes you do to the directory synchronisation will only affect new users. Any users already synced to CM will not be affected by your change.&lt;/P&gt;
&lt;P&gt;Can you please take screenshots of both your directory synchronisations configuration and your authentication configuration so that we can validate it?&lt;/P&gt;</description>
      <pubDate>Tue, 10 Aug 2021 05:25:42 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4446859#M46316</guid>
      <dc:creator>Roger Kallberg</dc:creator>
      <dc:date>2021-08-10T05:25:42Z</dc:date>
    </item>
    <item>
      <title>Re: Bulk Grant Access to Jabber</title>
      <link>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4447465#M46325</link>
      <description>&lt;P&gt;LDAP authentication shouldn't break, as was said there's only one authentication relationship that can be set. What may have bit you is that if you use multiple relationships, they do go in time order and you have to make sure that the earlier sync has all the groups you want. In that case, that means CCM End User, Standard CTI, etc. Then after syncing &lt;EM&gt;remove&lt;/EM&gt; the other sync so you are not moving the users back and forth and negating what you've done.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;If you don't use rank, I would recommend that you don't touch them. It almost sounds like a way to group users, but it is not, it's a permissions system. If you apply a rank like "CTI Users" to try and differentiate users, you'll break things as the permissions will also be assigned a rank that's applicable and it won't apply to users who aren't in that rank or higher.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;You can also do this with AXL or database query. I have created an access control group that has Standard CCM End User Access, Standard CTI Control Enabled, Allow Control of Rollover and Xfr, etc. I applied this group to the sync and then used AXL to apply it to the end users. I can then modify the group to assign whatever permissions in the future, to avoid this problem later on if you need something else added.&lt;/P&gt;</description>
      <pubDate>Wed, 11 Aug 2021 01:56:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/collaboration-applications/bulk-grant-access-to-jabber/m-p/4447465#M46325</guid>
      <dc:creator>Adam Pawlowski</dc:creator>
      <dc:date>2021-08-11T01:56:15Z</dc:date>
    </item>
  </channel>
</rss>

