jsoderquist (Customer) asked a question.

We have a user who would like to change her Username in Active Directory (AD). We use LDAP integration between AD and Vocera. What workflow should we use for users who have username change in AD?

We had a username change in the past and this corrupted the XMPP tables and caused multiple issues. How do we go about AD Username changes without corrupting Vocera database? Should we delete the Vocera account with the origianal Username and start over with a new Vocera account? Any information about how this process should work when an AD username is changed will be greatly appreciated.


  • mhauslendale (MedSurg and Neurotechnology)

    @jsoderquist (Customer)​ Thank you for your patience on this, I spoke with our integration expert and this is what they advise to be a best practice with name changes in LDAP:

     

    Delete the old user account in Active Directory

    • This will then inactivate the old user account in Vocera

     

    Create new account in Active Directory with new username (sAMAcountName)

    • This will create a new account record with the new username key in Vocera, not to be confused with the old account

     

    Hope this helps, let us know if you have any issues at all.

     

    Expand Post
    Selected as Best
  • mhauslendale (MedSurg and Neurotechnology)

    @jsoderquist (Customer)​  Let me check with our team on this to see what is the best practice to prevent corruption of the database.

    • jsoderquist (Customer)

      IT Department used an existing Active Directory account and changed the Username. This created duplicate users in Vocera for the same LDAPP account. The user was ***** and her username was updated to ***** in AD so she had a row for each username in Vocera, but only one LDAPP integration. We inactivated the **** Vocera account and the ***** had multiple issues with not receiving alerts, becoming unregistered and having to log in multiple times throughout the day. She could always use vocera voice and that was the only thing that worked for her after the AD username change. The knowledge article doesn't address what to do about LDAP integration username changes so isn't helpful.

      1. Should we delete the existing Vocera account
      2. Then Change the Active Directory Username
      3. In my mind doing it this would should create a new LDAP integration with the new username and avoid the corruption caused by the multiple rows for the one AD account.
      4. I was hoping Vocera had a workflow for this so we can do it with confidence.

       

      Expand Post
  • mhauslendale (MedSurg and Neurotechnology)

    @jsoderquist (Customer)​ I am checking with our team and seeing if I can get an integration expert that specializes in SSO and the best order of operations for making name changes like this without impacting the user. You are right the article I provided only provides instructions on how to do the change in our system, so I am going to check on the best practice.

  • mhauslendale (MedSurg and Neurotechnology)

    @jsoderquist (Customer)​ Thank you for your patience on this, I spoke with our integration expert and this is what they advise to be a best practice with name changes in LDAP:

     

    Delete the old user account in Active Directory

    • This will then inactivate the old user account in Vocera

     

    Create new account in Active Directory with new username (sAMAcountName)

    • This will create a new account record with the new username key in Vocera, not to be confused with the old account

     

    Hope this helps, let us know if you have any issues at all.

     

    Expand Post
    Selected as Best
  • mhauslendale (MedSurg and Neurotechnology)

    @jsoderquist (Customer)​ definitely keep us posted, this helped us identify the need for an article for others too that might be encountering the same issue so we appreciate you posting this.