Why not place any special accounts you don't want to be visible into a special OU off the root of the AD structure, such as OU=Hidden,DC=cisco,DC=com. Then, those users you DO want to show up in AD, you place in a container that is at the same level as the special OU for hidden objects, such as OU=Corp Users,DC=cisco,DC=com. Then, for your LDAP integration, you specify the LDAP Search Base to start at the level of users you want to be included in the corporate directory.
Another alternative exists which I recently had to use on a client. By default, the "account enabled" property determines whether a user appears in the Corporate Directory. I had to change that property for the LDAP Integration query so that instead of querying on "account enabled" it looked to see if there was a value in the "ip phone" field. It involved using the AXL Toolkit utilities to modify the default LDAP query string which determines whether a user appears in the Corporate Directory, but might also work for you. This was a solution which was proposed by Cisco TAC as the way to accomplish what I was trying to do. So, I guess they support modifications to the LDAP query string as long as it happens via the AXL Toolkit. Earl Hough CCIE #16508 (R/S, Security) From: [email protected] [mailto:[email protected]] On Behalf Of Daniel Berlinski Sent: Friday, September 10, 2010 5:28 PM To: Tam Nhu Cc: [email protected] Subject: Re: [OSL | CCIE_Voice] Hide a particular user in the CorporateDirectory Hi Tam Yeah the is the only doco I know about for instructions on hiding users in CUCM DC as well. The other thing that comes to mind is if you are considering this solution in AD as I saw you trying with AD 2003 integration, you could place a special character such as a Tilda ~ in front of the first name and last name in AD and I believe it should have it to disappear from the corp directory on the phones. On Sat, Sep 11, 2010 at 9:06 AM, Tam Nhu <[email protected]> wrote: OK, here are the results of my lab testing: CUCM 7.0(1) and UCCX 7.0(1). * I first tried with the workaround solution on the document via the link below http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_tech_note0 9186a00804d2087.shtml The workaround for DC directory is to delete out of End User and create Application User did not work out since the UCCX server only search and see in the End User, not the Application User. The newly user 'crsadmin' I created in Application User did not show up in the UCCX web page to get assign as UCCX admin user. * I then tried with the AD 2003 integration and it didn't work also, with either ways by the document to import hideuser.ldif or by Deniel's trick to delete the last name on AD user crsadmin. a. By hideuser.ldif, it imported successfully and did put "CiscoPrivatedUser" in the Description field, but after Resync'ed on the UCM, it is still showing in the Corporate Directory b. By deleting the last name - user 'crsadmin' shown up as "Pending Delete" or "Inactive" on UCM End User page, and still shows in the directory; and more important, you cannot login on UCCX web page with crsadmin user when it is "Inactive" Any more suggestions is very appreciate. Thanks, TN. _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ The information contained in this transmission is confidential. It is intended solely for the use of the individual(s) or organization(s) to whom it is addressed. Any disclosure, copying or further distribution is not permitted unless such privilege is explicitly granted in writing by PC Mall, Inc. Furthermore, PC Mall, Inc. is not responsible for the proper and complete transmission of the substance of this communication, nor for any delay in its receipt.
_______________________________________________ For more information regarding industry leading CCIE Lab training, please visit www.ipexpert.com
