We have Jira/Confluence setup to use our LDAP server as the authentication server, using the user principal name as the name attribute and the object filter
(&(objectCategory=Person)(sAMAccountName=*)(memberOf=cn=atlass_company,ou=company,ou=company,dc=company,dc=local))
which allows us to login to our Atlassian products using our email address and domain password.
Due to some internal shuffling in our company, we have had to change the email addresses and subsequently the user principal names of a couple of our staff members. This has caused duplicate users to be created using the new UPN and email addresses, which means that we have exceeded our licence cap as well as all of the content created by those users is tied to an obsolete account.
Is there any way for us to merge these accounts, or to delete the old accounts that are no longer used?
Hi Ryan,
The merging of accounts as you call it is not impossible, but it requires a lot of manual manipulation of the database and can lead to unexpected results.
The safest bet is going to be to disable user accounts that are no longer used. When you disable an account, any content the user has created will still be accessible, but that user should not be counted against the license count.
If there are a large number of users, you might want to use the Confluence CLI and script the removal of the users.
Hi Ryan, we're in the same boat. Did you ever find a way to resolve the new UPN problem?
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
hi
ADManager Plus is a comprehensive web-based Microsoft Windows Active Directory Management software that simplifies User provisioning and Active Directory administration with complete security. It provides a complete set of active directory management tools to administrators for efficient management of active directory. The solution features a single console from which IT management can view and manage Active Directory users, computers, contacts, groups and generate reports for all the domains, servers or any specific domain in Active Directory environment from a central location. ADManager Plus also enables the administrator to delegate repetitive, simple, time consuming tasks to non-administrative users / helpdesk in a completely secure manner and also allows for controlled automation of Active Directory. ADManager Plus avoids manual, error prone administrative activities on Active Directory and saves time and cost. IT administrators can now perform the following list of activities on their Active Directory using ADManager Plus.
Link:http://www.manageengine.com/products/ad-manager/active-directory-management.html
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Due to the fact that this is an unsupported feature, we have decided to not to attempt to edit the database. The users have been disabled and everything is working, however we lost the ties between the users who's UPN changed and the content they had created.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.
Online forums and learning are now in one easy-to-use experience.
By continuing, you accept the updated Community Terms of Use and acknowledge the Privacy Policy. Your public name, photo, and achievements may be publicly visible and available in search engines.
You must be a registered user to add a comment. If you've already registered, sign in. Otherwise, register and sign in.