AD Organizational Units web query
Overview
AD Organizational Units web query displays Active Directory organizational units within the query scope. The built-in Active Directory Admin Unit features a template AD Organizational Units web query by default. You can deploy a copy of the AD Organizational Units web query in a custom Admin Unit.
Web query settings
| Setting | Description |
|---|---|
| Limit scope to this domain or OU | Define and limit the scope of the web query. Split the entire scope into multiple queries to granularly manage the items. |
| Query criteria |
Use the setting to filter out objects by the property values. Query criteria are sent with the query to the target system; the target system filters data before it returns the resulting set. The default value for this setting is specified in the Web query default filter field in Active Directory extension settings, set to include all objects by default. TIP: See How to use Query Builder dialog for Query Criteria and Filter rule settings for use cases. |
| More options | |
| Properties to display |
Each object property defined in this setting matches the column that will be displayed in the Web Portal for this web query. To display additional columns, add the required properties to the Properties to display list. To add extension attribute 1 that is synchronized from AD, you need to use a value like:
Copy
|
| Other required properties | Define a list of properties required for this rule to be executed correctly; use the list to create advanced filters. Refer to the following article for additional information: Using filters in web queries. |
| Filter |
Specify additional filter conditions to hide unwanted data based on criteria not supported by Active Directory query. E.g., use the setting to filter out objects based on their distinguished names. TIP: For optimal performance, use Query criteria above to filter objects whenever possible. |
| Sort by | Specify a property to sort the resulting object list. |
| Disable partial name search | Disable the substring search functionality to improve search performance in your web query. This setting does not affect the wildcard search logic. |
| Global search mode | The setting is not supported in AD Organizational Units web queries. |
| Additional query criteria |
Define additional criteria for all object pickers in this query. IMPORTANT: If the attribute in this criteria does not exist for the picker object type (e.g., user attributes for group pickers), the filter will not work correctly. If you want these criteria to work with some object pickers but not others, you can disable the use of these additional criteria per picker type in the object picker configuration. E.g., exclude some users from the search: |
| Default number of objects to show | Select the number of objects to display in the web query. By default, the global Web Portal setting from the Web Portal Settings > Default number of objects to show is used. |
| Action and picker scopes | |
| Default OU for new user |
Define a default OU to store new users created using the New User or Clone User actions in the web query. By default, the default OU is the scope OU. NOTE: When you create new objects, you can also use the domain of the connected user as a default value for the Create In field; set the default OU value to the Connected user domain. |
|
Define default OUs for new objects based on the type. IMPORTANT: The default OU for new organizational units is picked from the Default OU for new object field. |
| Default domain | Define the default UserPrincipalName suffix. E.g., @cayo.com. The default domain value is the default domain suffix for the current forest. It is defined in the Forest Settings setting of the Active Directory extension settings. |
| Additional scope for object selection |
Use this setting in two primary scenarios:
Object Picker dialog is used on multiple forms. The Object Picker dialog appears when you need to select an object inside the form. For example, in the Add to Groups form when selecting groups, the Properties form when selecting the user's manager, and so on. By default, this setting is empty, and only objects from the scope, specified in the Limit scope to this domain or OU setting, would be listed on Object Picker. To allow delegated administrators to select objects from additional Organizational Units, add those OUs to the Additional Scope(s) for Object Selection setting. Example: Let the AD Users web query scope is limited by In the Additional Scope for Object Selection, specify the distinguished names: |
| Move scope |
Specify additional scopes to search for Organizational Units on the Object Picker dialog. The Object Picker dialog appears when you need to select an object inside the form. The Object Picker dialog is used on Move forms for Active Directory users, groups, contacts, and computers. By default, this setting is empty, and only OUs from the scope, specified in the Limit scope to this domain or OU setting, would be listed in the Object Picker. To allow delegated administrators to move objects to additional Organizational Units, add those OUs to the Move Scope(s) setting. Example: Let the AD Users web query scope is limited by OU=OU1,DC=cayo,DC=com. We need to move User1, located in OU1, to OU2. In the Move Scope(s), specify the distinguished name of an additional OU: OU=OU2,DC=cayo,DC=com. This OU is not included in the AD Users web query scope. In this case, when you move a User1 to another OU, you could move this user not only to OUs located in OU1 but also to OU2. You would be able to find and select this OU in the Object Picker dialog. |
| Move scope search depth |
You can select the depth of the moving scope. There are two options:
|
| Cayosoft Suspend (legacy policies) | |
| Default user suspend settings | Specify AD User Suspend configuration. By default, it is taken from the Admin Unit settings. |
| Default user undo suspend settings | Specify Microsoft 365 User Suspend configuration. By default, it is taken from the Admin Unit settings. |
| Default group suspend settings | Specify AD User Undo Suspend configuration. By default, it is taken from the Admin Unit settings. |
| Default group undo suspend settings | Specify Microsoft 365 User Undo Suspend configuration. By default, it is taken from the Admin Unit settings. |
| Regional settings | |
| Default country/region |
Define a country/region to assign to new users created in the Web Portal. If a cloud user account is provisioned for this user in Microsoft 365, a user country is automatically used as a Microsoft 365 usage location. The default value is set in the Active Directory extension settings > Default country/region setting. For more information about the Microsoft 365 settings, see the Microsoft 365 extension settings article. |
|
Default user language Time zone |
Define the default values for cases when a cloud user account is provisioned for AD users. The default values for these settings are specified in the Microsoft 365 extension settings > Other User Provisioning Settings section. Values are used in the Regional settings section in New User | Office 365 Mailbox post creation tasks rule. |
Change history
| Version | Notes |
|---|---|
| 13.2.1 | The web query has been added. |
Comments
0 comments
Please sign in to leave a comment.