Is there a way to limit what user accounts are synchronized from Active 
Directory?  There are around 15,000 entries in our production AD system, but 
probably only about 300 of those need to have an account in the IPA system.  
Can we set an attribute in the user information in AD that would flag that this 
is a candidate for replication, and lack of that attribute would cause an 
account to be skipped?

Mark Tovey - UNIX Engineer | Service Strategy & Design
UTi<> | 400 SW Sixth Ave, Suite 1100 | Portland | Oregon 
| 97204 | USA<> | O / C +1 503 953-1389 | Skype: 

Freeipa-users mailing list

Reply via email to