Select the User Profile Service and click the Manage button on the ribbon. You should see the screen just like the one below.
![SharePoint UPS User Profile Service SharePoint UPS User Profile Service](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vej2_CQQeQaUxN86JDjLXoN1dWYkqkErtkQwyy5XmTVcwQ2qXsxRb8DmxxJvo-ZHgQzTVrUAKUeNp9Vlh3N-xw8KieZj-lbBXjL5xwcryw4LLTvMpsKcOKtI3KS9hRWORKxg3AryFE95OyBhs_LUW_8SQzcakUDkFB2Y3QO4Ftxfpjv3GPeLIK0vYxMMI=s0-d)
Default User
Profile Service configuration window after being created
Select Configure
Synchronization Connections in the Synchronization section. Now
click the Create new Connection option, if you see the
pop-up window In that case go back to Manage Services on Server and wait until the service starts.
![SharePoint UPS User Profile Service SharePoint UPS User Profile Service](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vbJdnrSfTQXTs8I2jwrhyzPgD-df0DLeEi5Uh6L1HZ65U6wyQRpEOgBHmURA4Fi1lVUrD5I0Ytgo_VGDqYsHrd0ZeOr24bdc7ypUlfxs1BxQj7EFJq4XtDBIzYIEW2tzaiPkY0MCfELyLuA0_voC2bk6E97uAfhnWY0piDBlDoyv4PAyraJdobc4gDyc0=s0-d)
Pop-Up window when
attempting to create the UPS synchronization connection
In the Add New
Synchronization connection window, we will need to fill-in several fields.
In the Connection Name
field enter a descriptive name of your connection, such as AD Synchronization.
In the Forest name field
enter the FQDN name of your domain (in my example: ad.local). Leave
the Auto discover domain controller option selected.
In the Account name, Password,
Confirm Password,enter credentials for the synchronization account
(sps_ups_sync).
![SharePoint UPS User Profile Service SharePoint UPS User Profile Service](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_uxzpQlD7KMN7YGIRhaFHAGKR0FsnD85jC1jRPMSUQxn5hktDxaX4jAprVRzoJR8PmxPyfl06aKA2VFGNffMZQD4p-9DOJPnBcrebTVyCFtbPquRFwmgUmwrd9xPGu4Epw7b7fjpKG8IGw5eFJPPbcAwbHssw_rYr1SmkvnbrYfKxQr5_tSyBQWd38egBI1=s0-d)
User Profile
Synchronization Connection configuration
Now click the Populate
Containers button and select your AD organizational units you would like to
import. I’ve selected NetPro and Users OU’s where I usually store
all my users.
![SharePoint UPS User Profile Service SharePoint UPS User Profile Service](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_vyQ0Dv-mma8Qk6ZgqpAXMu9CnJgvyAjnY4Y7VlY_bSwwLE1rwSORrWiWO5joef_U7ixwR5dzcK_zIac95dndndSo_GINtj1OousDo49--DS0h-m3VkjvKz2lybsnA-fQtXBLn83g-qih4ZFY-miH3uXzsEIH4_n-TJOmWErOq8zPFpEBz2fmsRjyJdxLBN=s0-d)
User Profile
Synchronization Connection – AD Container selection
Click OK and after a
while you should see your newly created connection listed. We can add
additional properties now, to tell the UPS Service that we do not want to import
AD accounts that are disabled. In my experience this is often requested by clients, so I propose
to make it a default for your setups.
Scroll over your connection name
and expand the menu using the black arrow on the right, then select Edit
Connection Filters option.
![SharePoint UPS User Profile Service SharePoint UPS User Profile Service](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_sLQPNi0_rtWoS5xZYRKcPc1q1QjLQVFGQzLz4okmdNic8TK7kM982re-3eOS-ABQa0AtVmsxU--aUad1uNo12IpYxKW_Upi18XD2IhwLqZK14QalWWXlHTxPUR8QkQHdKY0NGrb5aGS6OdhMnOWVZZJn2aCnF5hYFSDx-4lqYEQcthy3FUxh8Vo1MtWIw4=s0-d)
Edit Connection
Filters option under Synchronization connection name
Right now we need to add
exclusion filter for users that are disabled. You need to choose userAccountControl
attribute with Bit on equals operator with filter value 2.
See the screenshot below for the exact config you should perform.
![SharePoint UPS User Profile Service SharePoint UPS User Profile Service](https://lh3.googleusercontent.com/blogger_img_proxy/AEn0k_tXvN_lhMhT3otDsLM2bOsPwoU-JW-fd6qIQbnn0w7gvGJFrJ2-enEmG9U_2N2s_fe9EUuBcH9_rI-jmBBCVcyHsr0OA35McFf82ak99xAVP6qQaetzjAqHM7D6kjGHF2eaUoUVJle2YLcgAmuweB6H1alBqSVobo1BqrCpm31o5fIsIDcMCDbMBFtsf45r=s0-d)
Exclusion
configuration that would prevent importing disabled user accounts
Click the Add button – you
should see your newly created filter listed now. Click the OK button and
go back to the User Profile Service settings window.
Default User
Profile Service configuration window after being created
Select Configure
Synchronization Connections in the Synchronization section. Now
click the Create new Connection option, if you see the
pop-up window In that case go back to Manage Services on Server and wait until the service starts.
Pop-Up window when
attempting to create the UPS synchronization connection
In the Add New
Synchronization connection window, we will need to fill-in several fields.
In the Connection Name
field enter a descriptive name of your connection, such as AD Synchronization.
In the Forest name field
enter the FQDN name of your domain (in my example: ad.local). Leave
the Auto discover domain controller option selected.
In the Account name, Password,
Confirm Password,enter credentials for the synchronization account
(sps_ups_sync).
User Profile
Synchronization Connection configuration
Now click the Populate
Containers button and select your AD organizational units you would like to
import. I’ve selected NetPro and Users OU’s where I usually store
all my users.
User Profile
Synchronization Connection – AD Container selection
Click OK and after a
while you should see your newly created connection listed. We can add
additional properties now, to tell the UPS Service that we do not want to import
AD accounts that are disabled. In my experience this is often requested by clients, so I propose
to make it a default for your setups.
Scroll over your connection name
and expand the menu using the black arrow on the right, then select Edit
Connection Filters option.
Edit Connection
Filters option under Synchronization connection name
Right now we need to add
exclusion filter for users that are disabled. You need to choose userAccountControl
attribute with Bit on equals operator with filter value 2.
See the screenshot below for the exact config you should perform.
Exclusion
configuration that would prevent importing disabled user accounts
Click the Add button – you
should see your newly created filter listed now. Click the OK button and
go back to the User Profile Service settings window.
No comments:
Post a Comment