How do you certify your users?
Category None
Bookmark :
Here's a nice one - I'm currently working on a company-wide recertification. Every name is going to get changed, and not just the O, but also all the OU's as well (in for a penny.....)
So, this raises a question? How do you certify your users? I could really do with some examples here - no need for company names, though it would help me. Do you certify based on country? city? department? a combination of both? flat?
I'll start the ball rolling
BE certify
based on role and position. So for instance, I'm Warren Elsmore/Users/Corporate/BEGroup.
What are you?
Bookmark :
Here's a nice one - I'm currently working on a company-wide recertification. Every name is going to get changed, and not just the O, but also all the OU's as well (in for a penny.....)
So, this raises a question? How do you certify your users? I could really do with some examples here - no need for company names, though it would help me. Do you certify based on country? city? department? a combination of both? flat?
I'll start the ball rolling
-
Comments
Posted by Duffbert At 12:26:45 On 15/10/2007 | - Website - |
Here's an example Vitor Pereira/RS/EU/Company.
Posted by Vitor Pereira At 13:55:37 On 15/10/2007 | - Website - |
The problem with large organizations with lots of OU's is that the recertification can't keep up with the way people move around withing the organization. In the end you will have an organization with 30 - 50 % of the users in the wrong OU's, and by that, you have lost all meaning with the OU's.
For a company that is completely within one country, OU's could be used to denote city, county or state instead.
Posted by Peter von Stöckel At 13:09:22 On 15/10/2007 | - Website - |
Example
For People
[CN]/[CountryCode]/[CompanyCode]/[ParentCompanyName]
Jack Taylor/GB/CMP/Company
For Servers
[CompanyCode][AirportCode][NumericDigit]/[CountryCode]/[CompanyCode]/[ParentCompanyName]
CMPGLA1/GB/CMP/Company
Posted by Jack Taylor At 14:15:30 On 15/10/2007 | - Website - |
And on the note of recertification customer environments.... I highly suggest using a third party product as doing it manually is SUCH a pain!
Posted by francie At 15:55:12 On 15/10/2007 | - Website - |
The solution was to go flat at the OU level & innocuous at the O level. (Yes, it freaked some people out, and pissed others off, but none had a genuine business case)
John Doe/Domino or potentially John Doe/Users/Domino became the new style. I concider /Users to be safe as an OU because John will nver become a server thus needing to change to the /Servers/Domino OU and /Domino will never become /Exchange. This allows for */Users/Domino to be granted access instead of using default, but, thats trivial.
When this is achieved, the only need to change a persons name is based on a common name change, common name uniqueness was enforced over time, so, when you quit, your common name quit too.
In a large organization that might benefit from some of the other advantage of OU separation, I strongly recomend the use of 3rd party tools for maintenance. Once tools have been used its very hard to go back, and once tools are used all sorts of more complicated options are available. Groups are much easier to maintain than OU's are.
Posted by Dwight Wilbanks At 22:02:11 On 15/10/2007 | - Website - |