Follow the given procedure to resolve duplicate users or groups via queries and actions.
To list duplicate users or groups, the following steps should be followed:
- Log on to the ePO console.
- Navigate to Queries & Report.
- Click New to create a new query.
- Select one of the following:
- Drive Encryption – Duplicate users
- Drive Encryption – Duplicate groups
Choose a table for showing the query results.
- Choose any extra columns to add to the table (for example, the Distinguished Name under the Available Columns or Drive Encryption – Duplicate users/groups section) (not required).
- Choose any filter criteria (not required).
- Optionally click Save to save the query.
- Run the query.
The results are listed as a table of users or groups for which there are multiple entries. The goal is now to select the user(s) that you wish to keep, or the group(s) that you wish to de-assign from all systems.
WARNING:
- Removing duplicate users results in the deletion of associated user data. The users that are retained preserve only the latest user data; older user data is destroyed.
- De-assigning groups from all systems may result in the deletion of all associated user data for users within that group, if they're not assigned to systems elsewhere.
Selecting which user(s) to keep:
- Select the user(s) that you wish to keep. You can use the information provided in columns such as Registered LDAP server name to reach a decision.
- Click Actions, Drive Encryption and Remove all duplicates of the selected user(s).
- When asked to confirm the action, click Yes to confirm.
NOTE: The table does
not update immediately to show the removal of duplicates. This is because the de-assignment of users or groups is performed in a background process. Refreshing the table updates the rows to reflect the status of de-assignment.
To de-assign one or more groups from all systems, perform the steps below:
- Select the group(s) that you wish to de-assign. You can use the information provided in columns such as Registered LDAP server name to reach a decision.
- Click Actions, Drive Encryption and Deassign group(s) from all systems.
- When asked to confirm the action, click Yes to confirm.
NOTE: The table does
not update immediately to show the removal of duplicates. This is because the de-assignment of users or groups is performed in a background process. Refreshing the table updates the rows to reflect the status of de-assignment.
IMPORTANT:
The following caveats should be noted:
- If a member of a duplicate group is individually assigned to a system or branch, the removal of the duplicate group does not remove that user.
- Conversely, if a duplicate user is assigned to a system or branch via a group, then removal of the duplicate user does not remove that user.
- The use of these queries does not resolve the underlying cause of duplicate users or groups. See KB76111 - Duplicate Drive Encryption users shown after running the query 'DE: Users' or 'EE: Users' for information on preventing duplicates.