Hey!

I gave spiceworks a try and really like it so far. Just one thing is missing: I’d like to manage the AD users in spiceworks. So far I could import them and regenerate passwords which seems quite nice. For our admin-team would it be really nice to sync users created in spiceworks back to the AD, so that we have only one source of managing them, e.g. out of ticket-informations.

But it seems that spiceworks just creates ‘local’ users and never writes them back into the AD, is there any way achieving this?

I found some really old threads here, that because you can’t set a password in spiceworks it’s not possible and my question is, if it’s possible to do so now or still in this status. Thanks

3 Spice ups

I do not believe spiceworks supports doing this.

I also do not believe you should ever want spiceworks to do this. You should be creating users in AD and having spiceworks pick those users up.

https://community.spiceworks.com/support/inventory/docs/advanced-active-directory

1 Spice up

Hm that’s a shame.

Why not? I’m able to edit them and trigger password resets, so a create would not be that evil (if you know what you are doing, which I hope I do).

Still thanks for the answer

Because an administrator of SW may not be an active directory administrator and you wouldn’t want a non AD admin creating users.

SW does not use the credentials of the logged on user to update or edit AD attributes, if uses the generic account you use to sync with AD - someone who has no AD rights would still be able to edit/add AD users - meaning you have no audit trail either.

If you’re up for proper user creation in Active Directory, check out what we offer with Adaxes. It has automation rules and a customizable web interface , which you can delegate to whoever is responsible for onboarding and be sure that they won’t be able to break something.

Once they fill in the forms, the automation rules are triggered and they will do the rest according to the business logic you put in, e.g. creating a home folder for the user, updating/generating values for attributes like Description, moving the account to an OU (e.g. based on Office), adding it to groups (e.g. based on Job Title), assigning Office 365 licenses, creating and configuring an Exchange mailbox, etc.

The rule itself looks something like this:

Screenshot_342.png

Adaxes comes with a free 30-day trial with no limitations on user count or functionality whatsoever, so you can just download it and see if it fits you.

1 Spice up

@Rod-It

If you have write permissions on that AD user, it will update e.g. the email on first login on helpdesk or set the department/group, at least it does that on our installation. And yes you MAY not want that, but I don’t see why that shouldn’t be possible.

@Anton

Looks interesting, will have a look, thank you!

Anyway, no that I know SW doesn’t support this, I can have a look for a solution, thanks guys.