Why not place any special accounts you don't want to be visible into a
special OU off the root of the AD structure, such as
OU=Hidden,DC=cisco,DC=com.  Then, those users you DO want to show up in
AD, you place in a container that is at the same level as the special OU
for hidden objects, such as OU=Corp Users,DC=cisco,DC=com.  Then, for
your LDAP integration, you specify the LDAP Search Base to start at the
level of users you want to be included in the corporate directory.

 

Another alternative exists which I recently had to use on a client.  By
default, the "account enabled" property determines whether a user
appears in the Corporate Directory.  I had to change that property for
the LDAP Integration query so that instead of querying on "account
enabled" it looked to see if there was a value in the "ip phone" field.
It involved using the AXL Toolkit utilities to modify the default LDAP
query string which determines whether a user appears in the Corporate
Directory, but might also work for you.  This was a solution which was
proposed by Cisco TAC as the way to accomplish what I was trying to do.
So, I guess they support modifications to the LDAP query string as long
as it happens via the AXL Toolkit.

 

Earl Hough

CCIE #16508 (R/S, Security)

 

From: [email protected]
[mailto:[email protected]] On Behalf Of Daniel
Berlinski
Sent: Friday, September 10, 2010 5:28 PM
To: Tam Nhu
Cc: [email protected]
Subject: Re: [OSL | CCIE_Voice] Hide a particular user in the
CorporateDirectory

 

Hi Tam

Yeah the is the only doco I know about for instructions on hiding users
in CUCM DC as well.  

The other thing that comes to mind is if you are considering this
solution in AD as I saw you trying with AD 2003 integration, you could
place a special character such as a Tilda ~ in front of the first name
and last name in AD and I believe it should have it to disappear from
the corp directory on the phones.  




On Sat, Sep 11, 2010 at 9:06 AM, Tam Nhu <[email protected]> wrote:

 

OK, here are the results of my lab testing:  CUCM 7.0(1) and UCCX
7.0(1).

 

*       I first tried with the workaround solution on the document via
the link below


 
http://www.cisco.com/en/US/products/sw/voicesw/ps556/products_tech_note0
9186a00804d2087.shtml    

 

The workaround for DC directory is to delete out of End User and create
Application User did not work out since the UCCX server only search and
see in the End User, not the Application User.  The newly user
'crsadmin' I created in Application User did not show up in the UCCX web
page to get assign as UCCX admin user.

 

*       I then tried with the AD 2003 integration and it didn't work
also, with either ways by the document to import hideuser.ldif or by
Deniel's trick to delete the last name on AD user crsadmin.

a.    By hideuser.ldif, it imported successfully and did put
"CiscoPrivatedUser" in the Description field, but after Resync'ed on the
UCM, it is still showing in the Corporate Directory

 

b.    By deleting the last name -  user 'crsadmin' shown up as "Pending
Delete" or "Inactive" on UCM End User page, and still shows in the
directory; and more important, you cannot login on UCCX web page with
crsadmin user when it is "Inactive"

 

 

Any more suggestions is very appreciate.

Thanks,
TN.

 

_ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _ _

The information contained in this transmission is confidential. It is
intended solely for the use of the individual(s) or organization(s) to
whom it is addressed. Any disclosure, copying or further distribution is
not permitted unless such privilege is explicitly granted in writing by
PC Mall, Inc. Furthermore, PC Mall, Inc. is not responsible for
the proper and complete transmission of the substance of this
communication, nor for any delay in its receipt. 

_______________________________________________
For more information regarding industry leading CCIE Lab training, please visit 
www.ipexpert.com

Reply via email to