Project Server 2010 to 2013 : Will this upgrade help my AD synch problems in any way? RRS feed

  • Question

  • We are planning to upgrade from Project Server 2010 to 2013.

    One of the reasons would be that we have continuos failures in the AD synchronization every week, when users leave the organization and the process is unable to process their now inactive accounts in AD. Then we remove the users from the group being synchronized and the process succeeds.

    Does Project Server 2013 have a new way of dealing with AD synch or is it the same process?

    Thanks in advance!

    Thursday, December 12, 2013 6:40 AM

All replies

  • Project Server 2013 has a major change that IN Project server 2013 is claim based authentication is being used rather than classic based authentication.

    When user leave the organization and AD account will not be available then Project server AD sync will make that Account Inactive in the project server.

    Ideally once user become inactive then administrator need to check if user had any timemheet or updates, If user is not having any updates/timehsset then administrator should delete the user otherwise inactive mode is okay . 

    this link is covering all the scenario how Sync deal the groups. 


    • Proposed as answer by Kirteshtiw Friday, December 13, 2013 2:24 AM
    Thursday, December 12, 2013 6:56 AM
  • When Ad sync runs Project Server pulls in several metadata fields from Active Directory [ADGUID (UserObject.objectGUID),  Windows User Account (domain\sAMAccountName), Display Name (UserObject.displayName), Email Address (UserObject.mail), Department (UserObject.department), Group (resource property only)].

    When a user leaves an organization on a particular scenario his ID is deleted from AD and so he will be removed from the AD group used for AD synchronization. His id will be set to inactive in PWA in the next AD Sync.

    Considering the scenario is the user disabled in the AD once he leave the organization? Are the id's reused for some other users. If yes, then you will come across errors during AD sync.

    Please let me know how the user id's are taken care once the user leaves the organization. It will help us understand the issue better.

    Cheers! Happy troubleshooting !!! Dinesh S. Rai - MSFT Enterprise Project Management

    Please click Mark As Answer; if a post solves your problem or Vote As Helpful if a post has been useful to you. This can be beneficial to other community members reading the thread.

    Friday, December 13, 2013 1:29 AM