{"id":152,"date":"2008-11-09T20:32:28","date_gmt":"2008-11-10T02:32:28","guid":{"rendered":"http:\/\/idubbs.com\/blog\/?p=152"},"modified":"2008-11-09T20:32:28","modified_gmt":"2008-11-10T02:32:28","slug":"testing-and-tweaking-the-ldap-filter-for-your-profile-import-connections","status":"publish","type":"post","link":"https:\/\/www.idubbs.com\/blog\/2008\/testing-and-tweaking-the-ldap-filter-for-your-profile-import-connections\/","title":{"rendered":"Testing and tweaking the LDAP filter for your profile import connections"},"content":{"rendered":"<p><a href=\"http:\/\/idubbs.com\/blog\/wp-content\/uploads\/2008\/11\/searchsettings1.png\"><\/a>Note: This post got a lot longer than I anticipated &#8211; even without screenshots &#8211; and because I don&#8217;t want to lose you before you get to what I consider the good stuff, I have it labeled as such below and you can jump right to it if you want.\u00a0 In order to provide what I consider a more complete story however, I feel obligated to provide a little foundation first for those that are interested.\u00a0 \ud83d\ude42<\/p>\n<p><span style=\"color: #3366ff;\">The background \/ foundation:<\/span><br \/>\nAs part of setting up a SharePoint (MOSS) environment, administrators need to configure the Profile Import in SSP in order to\u00a0get user accounts\u00a0from Active Directory into the SharePoint Profile database.\u00a0 By default, SharePoint will import all users from the Current domain &#8211; which is not always the desired list of accounts.\u00a0<\/p>\n<p>To change the accounts that are being imported, you can do the following:<\/p>\n<ol>\n<li>From the Shared Services home page, select <strong>User profiles and properties<\/strong><\/li>\n<li>Select <strong>View import connections<\/strong><\/li>\n<li>Hover over the name of your connection and select <strong>Edit<\/strong><\/li>\n<li>The Search Settings section of the Edit Connections page will display the <strong>Search base<\/strong> and the <strong>User filter<\/strong> values.\u00a0<\/li>\n<li>If users from a particular directory node is desired, you can make changes in the <strong>Search base<\/strong> field.<\/li>\n<li style=\"text-align: left;\">We&#8217;re currently talking about\u00a0tweaking the values in the <strong>User filter<\/strong> field.\u00a0Default value:<br \/>\n(&amp;(objectCategory=Person)(objectClass=User))Minimum change you should use\u00a0per the MS article (below)\u00a0to remove disabled accounts:<br \/>\n(&amp;(objectCategory=person)(objectClass=user)( !(userAccountControl:1.2.840.113556.1.4.803:=2)))<\/li>\n<\/ol>\n<p>The default User filter will likely import more accounts than you are intending for use in SharePoint.\u00a0 Remember, the accounts that are imported will also be crawled by the search indexer and will be available as search results from the People Search scope.\u00a0 Because of this, we want to keep the accounts imported to a minimum so that the search results aren&#8217;t cluttered\u00a0up with non-useful information.\u00a0<\/p>\n<p>There are a number of good references out there for help with creating a specific\u00a0LDAP filter for your import, including one by MS:\u00a0 <a href=\"http:\/\/support.microsoft.com\/kb\/827754\">http:\/\/support.microsoft.com\/kb\/827754<\/a>\u00a0\u00a0<\/p>\n<p><span style=\"color: #3366ff;\">The <em>good<\/em> stuff:<\/span><br \/>\nThere are a lot\u00a0of queries and filters\u00a0available, depending on what you&#8217;re looking to filter.\u00a0 Regardless, what IS irritating is having to change your filter,\u00a0<strong>Start full\u00a0import<\/strong> and then <strong>View user profiles<\/strong> over and over until you get the list of accounts that you like.\u00a0\u00a0So, what\u00a0I&#8217;ve really been building up to is to use the following as a way to shortcut that process and test your\u00a0LDAP filter before using it\u00a0for your\u00a0SSP import.\u00a0 \u00a0\u00a0<\/p>\n<ol>\n<li>Go to Run -&gt; mmc\u00a0 (This is the Microsoft Management Console)<\/li>\n<li>Once the application starts, select File -&gt; Add\/Remove Snap-in&#8230;<\/li>\n<li>Select <strong>Add<\/strong><\/li>\n<li>Select <strong>Active Directory Users and Computers<\/strong>.\u00a0 Select <strong>Add<\/strong>, then <strong>Close<\/strong><\/li>\n<li>Select <strong>OK<\/strong><\/li>\n<li><strong>Active Directory Users and Computers<\/strong> should now be on the Console<\/li>\n<li>Expand <strong>Active Directory Users and Computers<\/strong> and the current domain should be visible<\/li>\n<li>Select the current domain, and the accounts, etc should be visible in the right pane<\/li>\n<li>Right click on the current domain in the left pane, and select <strong>Find<\/strong><\/li>\n<li>In the Find dropdown, select <strong>Custom Search<\/strong><\/li>\n<li>Select the <strong>Advanced<\/strong> tab<\/li>\n<\/ol>\n<p>You should now be able to enter an LDAP query string and test it to see if you are getting the approximate number of users that you&#8217;d expect in your SSP Profile Import.\u00a0 For starters, you could cut and paste the default value of the User Filter and see what users are returned by pressing the Find Now button.\u00a0 A list of accounts and a count should be returned by the tool.\u00a0<\/p>\n<p>Now, a few more notes for after you&#8217;ve found the filter value you want.\u00a0 Once you&#8217;ve entered your new filter value and re-run the full import, you may notice that the Number of user profiles number reported on the User <strong>Profiles and Properties<\/strong> page hasn&#8217;t changed.\u00a0 The page you want to check <strong>View User Profiles<\/strong>.\u00a0 This page will show you both the total number of user profiles, as well as the list of <em>active<\/em> user profiles, which is likely a lower number and hopefully matches the number that the mmc tool reported during your testing of the query.\u00a0<\/p>\n<p>Now what you need to do, and why you should tweak your import query <em>before<\/em> your first import, is remove all the accounts you don&#8217;t want.\u00a0 On the View User Profile page, change the <strong>View<\/strong> dropdown from <strong>Active Profiles<\/strong> to <strong>Profiles missing from import<\/strong>.\u00a0 You need to select each account, or each screen-full of accounts and delete them.\u00a0 (I hope you don&#8217;t have a lot, because that will be a pain.)\u00a0<\/p>\n<p>Once you&#8217;ve got all the junk cleaned out, start a full crawl on your profile database and your index should also be updated.\u00a0<\/p>\n<p>Thanks to <a href=\"http:\/\/blogs.inetium.com\/blogs\/bcaauwe\/default.aspx\" target=\"_blank\">Brian<\/a> for showing me this a few months ago&#8230; I&#8217;ve used it a bunch of times and have since passed it on to\u00a0a number of co-workers and clients alike.\u00a0 Hopefully you&#8217;ll find it handy as well.<\/p>\n<p>\u00a0<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Note: This post got a lot longer than I anticipated &#8211; even without screenshots &#8211; and because I don&#8217;t want to lose you before you get to what I consider [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_jetpack_newsletter_access":"","_jetpack_dont_email_post_to_subs":false,"_jetpack_newsletter_tier_id":0,"_jetpack_memberships_contains_paywalled_content":false,"_jetpack_feature_clip_id":0,"_jetpack_memberships_contains_paid_content":false,"footnotes":"","jetpack_publicize_message":"","jetpack_publicize_feature_enabled":true,"jetpack_social_post_already_shared":false,"jetpack_social_options":{"image_generator_settings":{"template":"highway","default_image_id":0,"font":"","enabled":false},"version":2},"jetpack_post_was_ever_published":false},"categories":[11],"tags":[],"class_list":["post-152","post","type-post","status-publish","format-standard","hentry","category-sharepoint"],"jetpack_publicize_connections":[],"jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/pgWQ1-2s","jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/www.idubbs.com\/blog\/wp-json\/wp\/v2\/posts\/152","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.idubbs.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.idubbs.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.idubbs.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.idubbs.com\/blog\/wp-json\/wp\/v2\/comments?post=152"}],"version-history":[{"count":0,"href":"https:\/\/www.idubbs.com\/blog\/wp-json\/wp\/v2\/posts\/152\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.idubbs.com\/blog\/wp-json\/wp\/v2\/media?parent=152"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.idubbs.com\/blog\/wp-json\/wp\/v2\/categories?post=152"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.idubbs.com\/blog\/wp-json\/wp\/v2\/tags?post=152"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}