We have a user who would like to change her Username in Active Directory (AD). We use LDAP integration between AD and Vocera. What workflow should we use for users who have username change in AD?
We had a username change in the past and this corrupted the XMPP tables and caused multiple issues. How do we go about AD Username changes without corrupting Vocera database? Should we delete the Vocera account with the origianal Username and start over with a new Vocera account? Any information about how this process should work when an AD username is changed will be greatly appreciated.
@jsoderquist (Customer) Thank you for your patience on this, I spoke with our integration expert and this is what they advise to be a best practice with name changes in LDAP:
Delete the old user account in Active Directory
This will then inactivate the old user account in Vocera
Create new account in Active Directory with new username (sAMAcountName)
This will create a new account record with the new username key in Vocera, not to be confused with the old account
Hope this helps, let us know if you have any issues at all.
IT Department used an existing Active Directory account and changed the Username. This created duplicate users in Vocera for the same LDAPP account. The user was ***** and her username was updated to ***** in AD so she had a row for each username in Vocera, but only one LDAPP integration. We inactivated the **** Vocera account and the ***** had multiple issues with not receiving alerts, becoming unregistered and having to log in multiple times throughout the day. She could always use vocera voice and that was the only thing that worked for her after the AD username change. The knowledge article doesn't address what to do about LDAP integration username changes so isn't helpful.
Should we delete the existing Vocera account
Then Change the Active Directory Username
In my mind doing it this would should create a new LDAP integration with the new username and avoid the corruption caused by the multiple rows for the one AD account.
I was hoping Vocera had a workflow for this so we can do it with confidence.
@jsoderquist (Customer) I am checking with our team and seeing if I can get an integration expert that specializes in SSO and the best order of operations for making name changes like this without impacting the user. You are right the article I provided only provides instructions on how to do the change in our system, so I am going to check on the best practice.
@jsoderquist (Customer) Thank you for your patience on this, I spoke with our integration expert and this is what they advise to be a best practice with name changes in LDAP:
Delete the old user account in Active Directory
This will then inactivate the old user account in Vocera
Create new account in Active Directory with new username (sAMAcountName)
This will create a new account record with the new username key in Vocera, not to be confused with the old account
Hope this helps, let us know if you have any issues at all.
Yes, This helps we will try this workflow and see how it goes.
Jennifer Soderquist, RN, MSN-BC Clinical Informatics Kearney County Health Services 727 East 1st Street Minden, NE. 68959 Phone: 308-832-3400 x2207 Fax: 308-832-3418 jsoderquist@kchs.org<mailto:jsoderquist@kchs.org>
@jsoderquist (Customer) definitely keep us posted, this helped us identify the need for an article for others too that might be encountering the same issue so we appreciate you posting this.
We have a user who would like to change her Username in Active Directory (AD). We use LDAP integration between AD and Vocera. What workflow should we use for users who have username change in AD?
By clicking “Accept All Cookies”, you agree to the storing of cookies on your device to enhance site navigation, analyze site usage, and assist in our marketing efforts, including tracking your activity on this and other websites and sharing your information with our third-party partners.
Privacy Preference Center
When you visit any website, it may store or retrieve information on your browser, mostly in the form of cookies. This information might be about you, your preferences or your device and is mostly used to make the site work as you expect it to. The information does not usually directly identify you, but it can give you a more personalized web experience. Because we respect your right to privacy, we provide details on each type of cookie below. You can choose not to allow some types of cookies, either by changing our default settings below or using a universal opt-out signal (which we discuss further in our privacy policy). However, blocking some types of cookies may impact your experience of the site and the services we are able to offer.
Manage Consent Preferences
Strictly Necessary Cookies
Always Active
These cookies are necessary for the website to function and cannot be switched off in our systems. They are usually only set in response to actions made by you which amount to a request for services, such as setting your privacy preferences, logging in or filling in forms. You can set your browser to block or alert you about these cookies, but some parts of the site will not then work. These cookies do not store any personally identifiable information.
Targeting cookies
These cookies may be set through our site by our advertising partners. They may be used by those companies to build a profile of your interests and show you relevant adverts on other sites. They do not store directly personal information, but are based on uniquely identifying your browser and internet device. If you do not allow these cookies, you will experience less targeted advertising.
@jsoderquist (Customer) Thank you for your patience on this, I spoke with our integration expert and this is what they advise to be a best practice with name changes in LDAP:
Delete the old user account in Active Directory
Create new account in Active Directory with new username (sAMAcountName)
Hope this helps, let us know if you have any issues at all.