LDAP Sync: Failsafe in case of too many deleted Users

17 votes

Suddenly all users have disappeared from the LDAP Group and the LDAP sync removed them from Checkmk including all manually entered settings. Even if the users are automatically added again later, all manual settings are lost. With a larger number of users this can quickly become a big problem and Murphy is not far away. And then the hassle starts...

Solution:
Instead of deleting the users immediately from checmk it would be better to deactivate the account first and remove if after a certain waiting time. If the account reappears again within this period, the account only needs to be reactivated and the manually entered settings are still ther.

In addition, the sync should be aborted if a large number of changes are detected. In such a case, the sync should be initiated manually in the GUI to ensure that this does not happen unnoticed.

This avoids a lot of hassle, and if it is a legitimate mass change, it would be a small additional effort.

Not planned Suggested by: Lars Sörensen Upvoted: 13 Dec, '23 Comments: 1

Comments: 1