BOB: Business Objects Board
Not endorsed by or affiliated with SAP

Register | Login 

Want to sponsor BOB? 
Want to sponsor BOB? (Opens a new window)  

General Notice: No events within the next 45 days.

[BI 4.x] Migration from 3.1 into 4.2 with SSO


 
Search this topic... | Search XI Server Discussion... | Search Box
Register or Login to Post    Forum Index -> Server Administration, Installation, Upgrades -> XI Server Discussion  Previous TopicPrint TopicNext Topic
Author Message
mike nagel
Senior Member
Senior Member



Joined: 18 Apr 2005

Posts: 77



PostPosted: Wed Feb 06, 2019 9:54 am 
Post subject: Migration from 3.1 into 4.2 with SSO

All,

I'm working toward migrating our XI 3.1 installation to 4.2 using SSO. Currently I'm creating Active Directory groups that will ultimately replace the Enterprise groups currently used in 3.1. I have a question concerning the migration process.

When I apply the new AD groups to the authentication list, the user IDs should be automatically added. Afterwards, when I run the migration tool, will the existing accounts "merge" with the AD accounts or will the accounts be "duplicated" with different ID/CUIDs (one with an Enterprise alias and one with an AD alias)?

If duplication occurs, it's not a big deal as we have less than 500 accounts and less than 20% of them actually create their own reports so moving the content around after the fact is not a heavy lift. I'd just like to get an idea of what will happen in advance (or if there's a preferable order in which to process the migration to eliminate the duplication).

Thanks! icon_biggrin.gif

_________________
Mike Nagel
Office Automation Supervisor
Judiciary/AOC
State of New Jersey
Back to top
hilfy
Forum Enthusiast
Forum Enthusiast



Joined: 16 Apr 2007
ASUG Icon
speaker.gif*3
Posts: 1894
Location: Atlanta, GA


flag
PostPosted: Thu Feb 07, 2019 12:47 pm 
Post subject: Re: Migration from 3.1 into 4.2 with SSO

They will duplicate. However, there is a way this might work for you:

1. Configure AD authentication but don't add any AD groups to the 4.2 system. If you've already added them, delete them, which will delete the users, and turn off any updated schedule that you may have configured.

2. Migrate your 3.1 users to the new system.

3. Add the AD groups back to the AD configuration. Be sure to turn on "Assign each new AD alias to an existing User Account with the same name" under "New User Options". If the Enterprise user name is the same as the AD user name, the AD user will be added as an "alias" of the Enterprise user instead of as a new users.

4. If you're going to use the AD groups to assign access instead of just using them to authenticate the user, make each AD group a member of one or more of your existing Enterprise groups. This is a best practice to make sure that you don't lose your security if the system ever has an issue connecting to the AD Domain Controller. Assign security to Enterprise groups and make the AD groups a member of the corresponding Enterprise group. This will also ensure that your users will have the correct security if they only have an AD alias without the Enterprise alias.

-Dell

_________________
Protiviti
Data & Analytics Practice
https://www.protiviti.com/US-en/data-management-advanced-analytics
Back to top
Display posts from previous:   
Register or Login to Post    Forum Index -> Server Administration, Installation, Upgrades -> XI Server Discussion  Previous TopicPrint TopicNext Topic
Page 1 of 1 All times are GMT - 5 Hours
 
Jump to:  

Index | About | FAQ | RAG | Privacy | Search |  Register |  Login 

Get community updates via Twitter:

Not endorsed by or affiliated with SAP
Powered by phpBB © phpBB Group
Generated in 0.0296 seconds using 17 queries. (SQL 0.0026 Parse 0.0009 Other 0.0261)
CCBot/2.0 (https://commoncrawl.org/faq/)
Hosted by ForumTopics.com | Terms of Service
phpBB Customizations by the phpBBDoctor.com
Shameless plug for MomentsOfLight.com Moments of Light Logo