question

BrettSh-0485 avatar image
0 Votes"
BrettSh-0485 asked ·

Map Extra Attributes to ADDS LDAP Interface?

I have setup LDAPS by basically following these steps:

https://docs.microsoft.com/en-us/azure/active-directory-domain-services/tutorial-configure-ldaps

Plus, I have created a service account that allows me to extract user information. However, I haven't figured out how to add further attributes. In particular, I would like to add userPrincipalName and employeeId.

Any suggestions?

Thanks in advance.

BrettSh

azure-ad-user-provisioning
· 3
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

@BrettSh-0485 How are you extracting user information? Are you running PowerShell cmdlet under service account context or by making LDAP call?

0 Votes 0 ·

I'm following up on this please let us know if there are anymore questions. In order to progress this issue forward, we will need you to reply/respond in regards to the replies above. Thanks

0 Votes 0 ·

I'm using LDAP calls via a service account.


0 Votes 0 ·

1 Answer

amanpreetsingh-msft avatar image
0 Votes"
amanpreetsingh-msft answered ·

@BrettSh-0485 You can use LDP.exe on the computer where you have installed AD DS Tools.

  1. Run Nltest /dsgetdc: command and copy the DC name from the output.

  2. Run LDP.exe and click on Connection > Connect > Paste the DCName, use Port 636 and select SSL checkbox.

  3. Click on bind under connection menu and login using your service account.

  4. Click on Browse menu > Search and specify the parameters as highlighted below. In the output you will get UPN and Employee ID.
    alt text

OR

Download ADFind.exe from http://www.joeware.net/freetools/tools/adfind/ and run below command:

AdFind.exe -h DC_Name:636 -b cn=users,dc=your_domain,dc=your_domain_suffix -f "objectcategory=person" userprincipalname name employeeID

Note: Instead of cn=users you can specify OU=your_OU_name to search within specific OU or just specify domain's DN to perform domain wide search.


Please "mark as answer" or "vote as helpful" wherever the information provided helps you to help others in the community.









untitled.png (27.2 KiB)
· 1 ·
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Thank you for the extremely detailed reply amanpreetsingh-msft.


Unfortunately, the client is actually a Linux box. Also, if I try to run ldp.exe on a Windows 10 (home edition) PC I get the following message: "This App can't run on your PC.". So, not sure where to go from there :-(


Anyway, I do appreciate the effort you took with your answer so, thank you :-)


0 Votes 0 ·