# LDAP OU movement

**URL:** <https://developer.sailpoint.com/discuss/t/ldap-ou-movement/98014>\
**Category:** SHF Discussion and Questions\
**Tags:** provisioning, identity-security-cloud\
**Created:** [January 20, 2025, 6:39am UTC](https://developer.sailpoint.com/discuss/t/ldap-ou-movement/98014 "2025-01-20T06:39:34Z")\
**Posts on this page:** 4\
**Page:** 1

<div class="post-metadata">

**Author:** ![markbrook](https://avatars.discourse-cdn.com/v4/letter/m/9f8e36/32.png) [@markbrook](https://developer.sailpoint.com/discuss/u/markbrook)\
**Post date:** [January 20, 2025, 6:39am UTC](https://developer.sailpoint.com/discuss/t/ldap-ou-movement/98014/1 "2025-01-20T06:39:34Z")

</div>

Hi,

I have the same scenario that mentioned this below link. Did anyone guide me or give me a proper way to achieve this?

> [@SailPoint ISC LDAP Generic Connector Error 65 - Moving OUD Accounts Between OUs](https://developer.sailpoint.com/discuss/t/sailpoint-isc-ldap-generic-connector-error-65-moving-oud-accounts-between-ous/88858):
>
> Hi guys, I’m facing an issue when trying to move disabled accounts to a different OU in Oracle Unified Directory (OUD) LDAP through SailPoint IdentityNow. Current scenario: Source OU: ou=users,dc=company,dc=com,dc=br Target OU: ou=disabled,dc=company,dc=com,dc=br Need to move accounts when lifecycle state changes to inactive I’ve tried Provisioning Policy with AC\_NewParent (failed - not supported in OUD LDAP) using DN attribute with “Set” operation (failed - schema violation) Error message…

Thanks,  
Mark Brook

---

<div class="post-metadata">

**Author:** ![Santhakumar](https://sea1.discourse-cdn.com/sailpoint/discuss/user_avatar/developer.sailpoint.com/santhakumar/32/17329_2.png) [@Santhakumar](https://developer.sailpoint.com/discuss/u/Santhakumar)\
**Post date:** [January 20, 2025, 6:48am UTC](https://developer.sailpoint.com/discuss/t/ldap-ou-movement/98014/2 "2025-01-20T06:48:43Z")

</div>

Hi @markbrook you can leverage the LDAP attribute newRDN, newSuperior and deleteOldRDN to do the modify process like OU change, CN change…

In LDAP newrdn, deleteoldrdn, and newsuperior are parameters used in the Modify DN operation, which is used to rename an entry in the directory tree.

1. **newrdn**  
This parameter specifies the new Relative Distinguished Name (RDN) for the entry.  
The RDN is the name of the entry relative to its parent entry in the directory tree.  
The newrdn parameter specifies the new name that the entry will have after the modification.
2. **deleteoldrdn**  
This parameter is a Boolean flag that indicates whether the old RDN (Relative Distinguished Name) should be deleted after the entry is renamed.  
If set to true, the old RDN is deleted; if set to false, the old RDN is retained as an attribute of the entry.
3. **newsuperior**  
This parameter specifies the new parent entry for the entry being renamed.  
It is used when the entry is moved to a new location in the directory tree during the rename operation.  
If the entry is not being moved to a new parent, this parameter is not used.

Let me know if any other info you need.

HTH.

---

<div class="post-metadata">

**Author:** ![markbrook](https://avatars.discourse-cdn.com/v4/letter/m/9f8e36/32.png) [@markbrook](https://developer.sailpoint.com/discuss/u/markbrook)\
**Post date:** [January 20, 2025, 6:49am UTC](https://developer.sailpoint.com/discuss/t/ldap-ou-movement/98014/3 "2025-01-20T06:49:43Z")

</div>

Thanks @Santhakumar for the input if possible can you share the screesnshot where you deploy this attribute in rule.

---

<div class="post-metadata">

**Author:** ![system](https://global.discourse-cdn.com/sailpoint/original/2X/f/f2136700ed5e3703e0b85e02f6be799dacca7735.png) [@system](https://developer.sailpoint.com/discuss/u/system)\
**Post date:** [March 21, 2025, 6:50am UTC](https://developer.sailpoint.com/discuss/t/ldap-ou-movement/98014/4 "2025-03-21T06:50:20Z")

</div>

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.
