06-03-2021 09:51 AM
Currently having issues synching new employees in AD to CUCM. Has anyone ran into this, or know some troubleshooting steps? Before I would just perform full synch and the users would appear, but about a week ago after creating a new user, they would not pick them up. I verified that all the lines on an AD profile were filled unless there's a specific one that matters and I don't know about.
I can't seem to figure out the issue and I can't think of any changes at all that may have caused this.
When I do perform full synch no errors appear. The system just says that the synch was successful, but the new users don't appear.
Solved! Go to Solution.
06-04-2021 10:47 AM
Okay, I was able to figure out the issue.
I want to start off by explaining some more of the situation. Im still learning the system and the only 2 people that had set it up were long gone and I'm still new.
with that said anyone in the same situation that finds this question, I will provide a video on how the sync system is set up that I found on youtube, just so you know the simple process.
'https://www.youtube.com/watch?v=hiuMoa-sYW8'
What I ended up doing was going to the LDAP Directory in CUCM and under LDAP Manager Distinguished Name I noticed the format. it was CN=CUCM,OU=IT,DC=example,DC=local. out of curiosity, I changed it to 'CUCM@example.local', saved it, and performed full sync. This resolved the issue.
06-03-2021 12:09 PM
Verify that all users has the field “sn” set. This is the only out of the box mandatory field for a user to be synchronised. If you use a custom LDAP filter for your synchronisation there could be additional fields that are required. It all depends on what you have defined in the filter.
06-03-2021 12:40 PM
What is your LDAP search base? Are the users possibly being created in a different location in the LDAP tree? Also, has the password expired on the account you are using to do the LDAP sync? The only special permissions the LDAP sync account requires are "read all properties of user objects" and (optionally) "password never expires".
06-03-2021 02:28 PM
I attached what I think is the LDAP search base. They are being created in the only and same LDAP tree. The password to the account is set to never expire.
06-03-2021 06:34 PM
The LDAP search base in your screen shot is empty.
06-04-2021 10:48 AM
Thank you, I was able to figure out the issue and posted it as a reply and solution in the page.
06-03-2021 08:38 PM
AFAIK, the configuration page is for "Directory Server User Search for Cisco Mobile and Remote Access Clients and Endpoints". To sync user from AD to CUCM, configuration is on "LDAP Directory"
06-03-2021 08:25 PM - edited 06-03-2021 08:26 PM
Make sure the user has last name configured on AD, with only first name User will not get synced.
06-04-2021 10:49 AM
Thank you, I was able to figure out the issue and posted it as a reply and solution on the page.
06-04-2021 10:47 AM
Okay, I was able to figure out the issue.
I want to start off by explaining some more of the situation. Im still learning the system and the only 2 people that had set it up were long gone and I'm still new.
with that said anyone in the same situation that finds this question, I will provide a video on how the sync system is set up that I found on youtube, just so you know the simple process.
'https://www.youtube.com/watch?v=hiuMoa-sYW8'
What I ended up doing was going to the LDAP Directory in CUCM and under LDAP Manager Distinguished Name I noticed the format. it was CN=CUCM,OU=IT,DC=example,DC=local. out of curiosity, I changed it to 'CUCM@example.local', saved it, and performed full sync. This resolved the issue.
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide