cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
3091
Views
0
Helpful
7
Replies

CUCM AD sync and local users

Hi . We have users synced with AD . I was checking out CUCM and see we have 395 local enabled users and 390 Active LDAP Synchronized User. 

I see many duplication = Active LDAP Synchronized User also exist as local enabled users but with different USERID (extension number as USERID). I am not sure is it glitch on CUCM or fault of our servicedesk technicians . And I think because of these duplication we use double of licenses ..

Can someone make it clear for me please is it glitch on CUCM or... ?  If its glitch I should be able to delete those duplicate users with no harm to service if it's not associated to any device, correct ? 

Thank you

7 Replies 7

zdesignstudio
Level 4
Level 4

This usually happens when local users are created before AD is added into the system. The only issue you will have "converting" them is if the user accounts have a device or line associated to them. Those will all need to be updated.

I would also check on Unity Connections and make sure those users are not linked to a "PhoneSystem" user that is a local user in CUCM.

As far as the user id being the extension, that could be a mistake in the AD side or the AD configuration with what field in AD CUCM will use for the user id.

Please rate useful posts and marks answers as correct if applicable.

Please rate useful posts and mark answers as correct if applicable.

so u mean it's either local users are created before AD is added into the system OR that could be a mistake in the AD side or the AD configuration with what field in AD CUCM will use for the user id.

Right ?

The local users were probably already in CUCM before you added the AD integration.

The reason for the AD user id being the extension is either the CUCM--AD mapping is incorrect, AD is incorrect, or CUCM defaulted to extension since there is already a user (local) with the same user id.

Please rate useful posts and marks answers as correct if applicable.

Please rate useful posts and mark answers as correct if applicable.

ok, I see what r u saying. so when you add user in AD  it will not create that local user, right?

so either they were created earlier or somebody still adding local users together with AD , which is non-sense .... 

You got it. The local users were added by a human somehow, someway, sometime past or present.

Please rate useful posts and marks answers as correct if applicable.

Please rate useful posts and mark answers as correct if applicable.

I see now why we have duplicate endusers, in order to user will be able to login with Extesnion mobility by using their phone number. AD  import will bring usernames and password not phone number, so who did installation here they created second user acccounts with ext# as userid.  

I am curious what if I change LDAP Attribute for User ID to 'telephone number from "samaccountname"   and then I should be able delete duplicate endusers  and users should be able to login as before with ext and pin code , right? 

Do you want the user id to be the ext? If you do but only because it will be easier to type in instead of say first.last then I would look into an application called EM-SSO by VoIP Integration. Its a third party app that integrates with your AD environment and CUCM and will automatically log a user into a phone when they log into the computer.

Please rate useful posts and marks answers as correct if applicable.

Please rate useful posts and mark answers as correct if applicable.