cancel
Showing results for 
Show  only  | Search instead for 
Did you mean: 

Directory Services Attributes Administration

I'm trying to configure the Directory Services Attributes. I succefully connect and get the attributes available, but not the right ones.

If I connect to my AD with Sysinternals ADExplorer.exe or with Microsoft dsa.msc I can see the right attributes, ex. Department instead of DepartmentNumber.

I can use the username, email address and one or two general attributes but can't get others.

Authentication is Working.

The Directory Service Connection have the following configuration:
Directory Service Identification
Directory Service Type: Active Directory
Directory Service Port: 389 (tried 3268, connects but don't get any attribute)

Server Administration Credentials (are OK)

Server Attribute Mapping
Group Class Name: group
Group Name Attribute: cn
Group Member Attribute: member
User Class Name: user
User Name Attribute: samaccountname

I omited sensitive information.

Thanks in advance for your help.
(1) Reply
Hi There,

From what I recall, certain accounts have permissions to query against different attributes.

Are you using the same account when you're looking around with the standalone tools?

If so, then there might be some issue with the query that's being made. I think the builtin logging won't show this granularity for AD communication, but if you're connecting on port 389, you can use Wireshark to sniff the communication with the domain controller, and see the query and any results that are getting passed back.

If you like, you can PM me with the log, and I can look to see what's going on.

Regards,

Cary