Installing CC4 UEV (User Environment Virtualisation) removes the profile path mappings used by RM Unify AD Sync
Published Date : 18 Dec 2018
Last Updated : 04 Oct 2024
Content Ref: TEC6583553
Operating System
(none)
Part No
(none)
Summary
Details an issue with installing CC4 UEV on a network with RM Unify AD Sync, which may result in disabling all RM Unify accounts.
Symptoms
You have RM Unify AD Sync installed on your CC4 network, which by default uses the CC4 profile path of the users to determine which role mapping to apply to their RM Unify accounts.
After installing RM CC4 UEV (User Environment Virtualisation), you find that all your existing RM Unify user accounts are disabled, no user changes are synced from CC4 to RM Unify, and no new users are provisioned.
Cause
As part of the RM CC4 UEV installation, existing CC4 accounts can have their profile folder deleted, along with any reference to their profile path in CC4 (and Active Directory). Without this profile path, AD Sync is unable to assign a role to the RM Unify account, which makes it unusable.
Procedure
The resolution is to use either the OU location or CC4 group membership of the users to determine the RM Unify AD Sync role mapping. The role of your RM Unify users will then be determined either by the location of those users in CC4 (e.g the Students OU), or by their group membership (e.g CC4 Students). Note: Only use one of the following two options for role mapping.
Group membership:
Log on to the server with RM Unify AD Sync installed and open the Configuration Tool.
Expand Role Mappings in the left-hand pane and select the first role mapping.
In the right-hand pane, select 'Group membership' from the drop-down menu.
In the 'Select the group' section, click Browse, select the group to use, click OK and then Save.
Repeat for the remaining role mappings.
AD container:
Log on to the server with RM Unify AD Sync installed and open the Configuration Tool.
Expand Role Mappings in the left-hand pane and select the first role mapping.
In the right-hand pane, select 'Group membership' from the drop-down menu.
In the 'Select an AD container' section, click Browse, select the container to use, click OK and then Save.
Repeat for the remaining role mappings.
Possible Issues
If your RM Unify users are not corrected by the procedure within the next AD Sync scan cycle (by default this is 15 minutes), you may have to run a full resync. Please see TEC5694616 in the Other Useful Articles section below.