Skip to Content

User Accounts - create enterprise alias, remove AD account


We are in the process of switching from AD authentication to Enterprise authentication. I know I can create Enterprise accounts as aliases to the existing AD accounts via the BI Support Tool (though I haven't tried this yet), but once the Alias is created, can I also automate the disabling of the AD account and ultimately its deletion somehow? I'm not seeing a way to do that via the BIST...


Add comment
10|10000 characters needed characters exceeded

  • Thanks - been a little while since I posted, was drawing blanks on what tags to select...

    Ok - so... you brought up a good point - the AD groups will eventually go away. If I create the Enterprise aliases, I will have to manually add them to the BO groups that the AD groups are in (permissions are based on the BO groups and then the AD groups are added to BO groups in our environment)... then when I remove the link to AD, the AD accounts will be removed, but the Enterprise accounts will still remain?

    If yes, then that's my answer.

  • Get RSS Feed

2 Answers

  • Best Answer
    Apr 26, 2018 at 10:41 AM

    Big yes. But before AD accounts & groups removal make sure below things.

    - All AD users should have an enterprise alias to avoid any bi content lose from Inbox & Favorites

    - All AD groups should be part of any one of the BO enterprise groups to ensure security setup is not missed anywhere.



    Add comment
    10|10000 characters needed characters exceeded

  • Apr 26, 2018 at 01:29 PM

    Hi Roseann,

    To add to Mani's reply, once you unmap the AD group in the CMC and update, the AD aliases will disappear (or be deleted) from the system. This is why it's important to have Enterprise aliases for users in case the AD group gets unmapped.


    Add comment
    10|10000 characters needed characters exceeded