• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to footer
ClassThink

ClassThink

School Technology Guides

  • E-mail
  • Facebook
  • RSS
  • Twitter
  • YouTube
  • HOME
  • LATEST
  • Featured
  • School App Search
    • Search
    • Dashboard
    • Directory Login
  • TEACHER GUIDES
    • Microsoft Teams
      • Microsoft Teams Teacher’s Hub
    • Microsoft OneDrive
    • Microsoft Stream
    • Microsoft Office
    • Microsoft Edge
    • Microsoft OneNote
    • Microsoft Office
    • Microsoft Outlook
    • Microsoft Windows
    • Microsoft SDS
    • Google Classroom
    • Google Meet
    • Zoom
  • REVIEWS
  • NEWSLETTER
  • ABOUT
    • Contact Us
    • About ClassThink
    • Support ClassThink
    • Write for ClassThink
    • Advertising and Sponsorship
You are here: Home / Google Apps / How to stop accounts being deleted or suspended by Google Apps Directory Sync

How to stop accounts being deleted or suspended by Google Apps Directory Sync

19 February 2014 by Karl Rivers 3 Comments

Google Apps Directory Sync (GADS) makes syncing your Active Directory users with Google Apps simple. But sometimes you need Google Apps accounts that are independent from AD.

By default GADS will automatically delete any Google Apps accounts it doesn’t find in your Active Directory, which makes accidentally deleting or suspending users really easy.

In this article we show you how to:

  • Set up your based DN so to narrow down which users area synced.
  • Configure GADS’ users deletion and suspension settings to stop accounts being accidentally deleted.
  • Set up Google Apps accounts that don’t exist on your AD and tell GADS to ignore them.

Setting Your Google Apps Directory Sync Base DN

The base DN, found on the LDAP Configuration page, is the entry point that GADS users to start reading user account information from your Active Directory. By setting the base DN “lower” in your Active Directory structure you can better control the number of users GADS syncs and improve security so that you don’t accidentally create Google Apps users you’re not intending to.

The highest level of your directory structure will be:

DC=mydomain,DC=local

By using the above as your base DN, GADS will pull over all of your users and groups unless you exclude specific information in other settings. Preferably you want to specify a “lower” organisational unit by using something like this:

OU=users,DC=mydomain,DC=local

…or even…

OU=year9,OU=students,OU=users,DC=mydomain,DC=local

Google Apps Users Deletion and Suspension Policy Settings

Once your base DN is set you can use the “Google Apps Users Deletion / Suspension Policy” settings to control how GADS deals with Google Apps accounts that don’t exist in Active Directory.

To adjust “Google Apps Users Deletion / Suspension Policy” settings do the following:

  1. Open GADS
  2. Click User Accounts > User Attributes
  3. Scroll to the bottom of the screen and you’ll find the “Google Apps Users Deletion / Suspension Policy” settings.
  4. Choose your preferred options and save the configuration file.

Delete only active Google Apps users not found in LDAP (suspended users are retained).

This option deletes any Google Apps users not found in your Active Directory except for suspended Google Apps accounts. While this is good for security, it only takes a user to be accidentally moved into the wrong AD Organisational Unit for their account and data to be deleted.

Delete active and suspended Google Apps users not found in LDAP.

This deletes both active and suspended Google Apps accounts which are not present in your Active Directory. Again, this is good for security, but it only takes a user to be accidentally moved into the wrong AD Organisational Unit for their account and data to be deleted.

Suspend Google Apps users not found in LDAP, instead of deleting them.

This suspends rather than deletes Google Apps accounts not found in Active Directory. This is my preferred option as the account is made inaccessible but no data is put at risk.

Don’t suspend or delete Google Apps admins not found in LDAP.

This option is probably the most important. Selecting this check-box prevents GADS suspending or deleting any Google Apps accounts which have administrator privileges. This can prevent admin accounts getting accidentally locked out or deleted.

Creating Google Apps accounts that aren’t affected by GADS

Sometimes you may want to create a Google Apps account that doesn’t exist on your Active Directory domain. For example, we have a number of remote users who never need to log in to our school system but they do need Google Drive accounts.

To do this we can create exclusion rules which tell GADS to ignore specific Google Apps users or groups when synchronising users.

  1. Open GADS and navigate to Google Apps Configuration > Exclusion Rules.
  2. Click Add Exclusion Rule.
  3. There are a number of options available to specify which user or group we want GADS to ignore, but in this example we’re going to simply stop GADS deleting or suspending users in a Google Apps Organisation I’ve called “Service Accounts”.
  4. Select Organization Complete Path.
  5. Select Exact Match for the Match Type.
  6. In the Exclusion Rule box enter the path to the Google Apps Organisation. Because my Organisation is at the top level of the Google Apps user structure I can simply enter the name of the organisation — in this case “Service Accounts.” But if my organisation were deeper in my organisation structure I would simply enter the path as “Admins\Users\Service Accounts”.

GADS will now ignore any users within this Google Apps Organisation and will never delete or suspend them even though they don’t exist in Active Directory.

There are many ways to specify which information you want GADS to exclude when syncing, and you can create quite complex regular expressions to pick out specific data to ignore, but that’s for another article!

You might also like...

Filed Under: Google Apps

This page contains references to products from one or more of our advertisers. We may receive compensation when you click on the links to these products. For an explanation of our Affiliate Policy, please visit this page.

About Karl Rivers

Karl Rivers is a Director of IT who has worked in education for more than twenty years. He won the Naace Impact Award for Supporting School Services.

Reader Interactions

Comments

  1. Ignacio Pardo says

    10/16/2014 at 4:23 pm

    Do you know if is there any way to do the same but with calendar resources?

    I’m trying to syncronize Exchange Rooms with gmail but the system delete my google resource calendar

    Is there any way to avoid this behaviour?

    Thanks in advantage

    Nacho

    Log in to Reply
  2. Eric Downing says

    07/01/2016 at 3:23 am

    The suborgs exclusion rule requires forward slashes not backslashes:

    Admins\Users\Service Accounts

    should be

    Admins/Users/Service Accounts

    Log in to Reply
  3. rick says

    08/03/2016 at 1:21 am

    Organization Complete Path seems to NOT be an option anymore?

    Log in to Reply

Leave a Reply Cancel reply

You must be logged in to post a comment.

Primary Sidebar

  • E-mail
  • Facebook
  • RSS
  • Twitter
  • YouTube

You might also like...

Popular School Apps

  • Bromcom Computers Plc

    Bromcom Computers Plc

    MIS/SIS System

  • CleverTouch

    CleverTouch

    Classroom Screens & Projectors

  • Capita SIMS

    Capita SIMS

    MIS/SIS System +3 Parent Communications, Parent Portal, Parents Evenings,

  • Wakelet

    Wakelet

    Learning Platform +1 Social Bookmarking,

  • BKSK

    BKSK

    Assessments +1 Educational Games & Quizzes,

Latest Edtech News

Virtual breakout rooms for Microsoft Teams – everything you need to know

Download the free OneNote for Team Collaboration eBook

New Surface Laptop Go Announced

Featured

Best Chromebooks for students in 2021

Create beautiful infographics for your classroom

Record online lessons with Camtasia

Naace Impact Awards Winner

Footer

Recent

  • Best Chromebooks for students in 2021
  • Create beautiful infographics for your classroom
  • Virtual breakout rooms for Microsoft Teams – everything you need to know
  • Record online lessons with Camtasia
  • Download the free OneNote for Team Collaboration eBook
  • New Surface Laptop Go Announced
  • Managing Windows 10 in schools with Intune and Autopilot
  • How to stop students unmuting themselves in Microsoft Teams
  • How to spotlight students & demonstrations in Microsoft Teams meetings
  • How to record a PowerPoint presentation as a video
Privacy & Cookies: This site uses cookies. By continuing to use this website, you agree to their use.
To find out more, including how to control cookies, see here: Cookie Policy

Recent Forum Topics

  • JvFHf5vfJ HyVSv2mpZ
  • Use VPN Security
  • How less is more with application development
  • How Much Does it Cost to Make an App like Uber
  • Microsoft Team class not appearing for teacher but is correct in Teams admin
  • FCM Test Notification!!! message in Microsoft Teams
  • FAQ: Can students begin a meeting in a private channel in Microsoft Teams
  • Microsoft Lists for Education
  • Benefits of hiring a ghostwriter
  • Things You Need To Make An Android App

Most Popular Posts

  • How to turn off chat for students in Microsoft Teams
  • How to stop students muting and kicking others in Microsoft Teams video meetings
  • How to delete a video from Microsoft Teams
  • How to record and share a lesson in Microsoft Teams
  • How to enable Large Gallery view and Together Mode in Microsoft Teams
  • How to mute students in Microsoft Teams
  • Virtual breakout rooms for Microsoft Teams - everything you need to know
  • How to record a PowerPoint presentation as a video
  • Set students to attendee by default in Microsoft Teams meetings
  • How to set and mark an assignment in Microsoft Teams
  • E-mail
  • Facebook
  • RSS
  • Twitter
  • YouTube

Copyright © 2021 · ClassThink.com · Affiliate Disclaimer · Privacy Policy · Here's the secret · Log in