cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
4909
Views
0
Helpful
1
Replies

WFO: QM System Administrators and AD Integration

Anthony Holloway
Cisco Employee
Cisco Employee

Workforce Optimization, Quality Management, Active Directory

 

I cannot seem to figure out what happened, but in my brand new installation of QM 11.5(1), after integrating with AD and supplying the Admin Group field, the System Administrators have been created as local QM accounts (User ID begins with "0.", vs "1." for ACD accounts), and now I cannot link their ACD account to their Windows account, because it's already linked to the local QM account.

 

I'm going to assume this is working as designed, and you cannot have the same AD account be an Administrator and also synced from the ACD, though I have not read that anywhere.

 

Local QM Account Created Automatically After AD Integration

qm-system-administrator.png

 

ACD Synced Account

qm-agent.png

 

Linking ACD Account Error

qm-link-error.png

 

Obviously, I cannot just delete the account its asking me to, as that's the account I login into the Admin tool with in the first place.

1 Accepted Solution

Accepted Solutions

Anthony Holloway
Cisco Employee
Cisco Employee

I found the language in the QM Administration Guide for 11.5, Section User Administration, page 152.

 

UPDATE:

The instructions are not correct in my opinion.  Where it says to create a new non-ACD user, that's not correct.  What I did was, I deleted the "0." local account that was created automatically.  Then I linked the user's "1." ACD account to their AD account.  Then I opened PostInstall.exe and looked at the Administrator Configuration section, and the linked ACD/AD user account showed up here.  I needed to add the user to the System Admin role once again.

 

Turns out, you can have your cake and eat it too.

 

But it's still looking like, if you need your Admins to also be in the ACD (and thus recorded), you cannot do this.  When I follow the instructions in the guide (pasted below), I either end up where I started, or I end up with an ACD user who cannot administer the system.

 

Since no one is replying, I'm going to just assume the product has a defect and this isn't possible.  Seems like QM is going to force this customer to use a shared service account for QM Administration out of AD, instead of individual logins.

 

Document Link

https://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/cust_contact/contact_center/workforce_optimization/qm_11_5/user/guide/qm-administrator-guide-cisco-115.pdf

 

Document Snippet

Important: If the Active Directory account you are trying to link to an ACD user is already assigned to the system administrator role, the following message appears:

 

AD user <doe, john=""> is already designated as a QM user. Delete user <doe, john=""> first.

 

Delete the user as instructed (see User Administration), create a new non-ACD user (see Creating a non-ACD User using Active Directory or Creating a Non-ACD User without Active Directory) and then reassign the system administrator role to the user (see Managing Administrators).

View solution in original post

1 Reply 1

Anthony Holloway
Cisco Employee
Cisco Employee

I found the language in the QM Administration Guide for 11.5, Section User Administration, page 152.

 

UPDATE:

The instructions are not correct in my opinion.  Where it says to create a new non-ACD user, that's not correct.  What I did was, I deleted the "0." local account that was created automatically.  Then I linked the user's "1." ACD account to their AD account.  Then I opened PostInstall.exe and looked at the Administrator Configuration section, and the linked ACD/AD user account showed up here.  I needed to add the user to the System Admin role once again.

 

Turns out, you can have your cake and eat it too.

 

But it's still looking like, if you need your Admins to also be in the ACD (and thus recorded), you cannot do this.  When I follow the instructions in the guide (pasted below), I either end up where I started, or I end up with an ACD user who cannot administer the system.

 

Since no one is replying, I'm going to just assume the product has a defect and this isn't possible.  Seems like QM is going to force this customer to use a shared service account for QM Administration out of AD, instead of individual logins.

 

Document Link

https://www.cisco.com/c/dam/en/us/td/docs/voice_ip_comm/cust_contact/contact_center/workforce_optimization/qm_11_5/user/guide/qm-administrator-guide-cisco-115.pdf

 

Document Snippet

Important: If the Active Directory account you are trying to link to an ACD user is already assigned to the system administrator role, the following message appears:

 

AD user <doe, john=""> is already designated as a QM user. Delete user <doe, john=""> first.

 

Delete the user as instructed (see User Administration), create a new non-ACD user (see Creating a non-ACD User using Active Directory or Creating a Non-ACD User without Active Directory) and then reassign the system administrator role to the user (see Managing Administrators).