AugForums.com

An Acumatica User Group

  • Free
    • Start Here
    • Rolodex
    • Podcast
    • Blog
    • Forums
  • Paid
    • AugSQL
    • GI Course
    • GI Library
    • Consulting
  • Register
Acumatica Forums

By using this website, you agree to our Terms of Use (click here)

Forums
AUG Forums
Everything Else
Moving from one Win...
 
Notifications
Clear all

Questions Moving from one Windows AD Forest to Another

 
Everything Else
Last Post by Pat Long 6 years ago
4 Posts
2 Users
1 Reactions
1,543 Views
RSS
Pat Long
Posts: 19
 Pat Long
Topic starter
December 18, 2019 12:56 pm
(@pat-long)
Eminent Member
Joined: 6 years ago

We are consolidating Windows AD Forests and our users are currently on abc\username.  The abc users have been copied to the def forest.  

Any idea on how to change the users from abc\username to def\username on the system.

I have tried sql scripts that Acumatica recommended for when a name changes ( married divorced types of things...) 

  • https://portal.acumatica.com/kb/how-to-enable-a-user-to-sign-in-when-the-users-logon-name-has-been-changed-in-active-directory/

I changed the AD path in the web.config file.  Ran the script to change the user from abc\ to def\.  Verified that they are all def\.

When they log in the changed user account gets a username of Deleted_from_AD_def\username and a new def\username is built.  All the roles are dropped and we would have to rebuild them.

We have a lot of users and would hate to have to rebuild them all. 

Thanks for any help ahead of time.


Topic Tags
Windows AD
3 Replies
Pat Long
Posts: 19
 Pat Long
Topic starter
January 6, 2020 3:02 pm
(@pat-long)
Eminent Member
Joined: 6 years ago

I have had my VAR talking with Acumatica and they recommended updating the ExtRef field on the User table with the SID of the new Windows AD tree.  

My preliminary tests look good.  After converting several accounts, they seem to retain their roles and access. 

So it was a change of username from old\username to new\username and ExtRef to the SID from the new Windows AD domain from the new\username account.


Reply
Tim Rodman
Posts: 3193
 Tim Rodman
Admin
January 18, 2020 4:06 pm
(@timrodman)
Famed Member
Joined: 10 years ago

Thanks for posting the solution.

Just curious, is this local/hosted Active Directory or Azure Active Directory? And are you only using it for SSO or also for synching User Security Roles?


Reply
Pat Long
Posts: 19
 Pat Long
Topic starter
January 22, 2020 9:51 am
(@pat-long)
Eminent Member
Joined: 6 years ago

These locally hosted directories. 

I am trying to move to ADFS for login, but I needed to move to the standardized server farm first.   That forced the new AD Tree.

Right now, we are only synching one role to the Windows AD group.   If we go to ADFS, we will have over a thousand for each of our residences.  


Reply
Tim Rodman reacted
Forum Jump:
  Previous Topic
Next Topic  
Topic Tags:  Windows AD (1) ,
Forum Information
Recent Posts
Unread Posts
Tags
  • 12 Forums
  • 2,526 Topics
  • 10.9 K Posts
  • 38 Online
  • 2,338 Members
Our newest member: Shoaib Shafquat
Latest Post: Pick List report suddenly not splitting on Shipment
Forum Icons: Forum contains no unread posts Forum contains unread posts
Topic Icons: Not Replied Replied Active Hot Sticky Unapproved Solved Private Closed

Online Members

 No online members at the moment

Acumatica Forums

Terms of Use & Disclaimers :: Privacy Policy

Copyright © 2025 · AUG Forums, LLC. All rights reserved. This website is not owned, affiliated with, or endorsed by Acumatica, Inc.

‹›×

    ‹›×