Where call-recording.com intervenes

From technical requirement to working recording

call-recording.com preserves the relationship between a recorded conversation and the correct user while supported CUCM and Webex Calling capture coexist in one dashboard.

Webex Calling Directory Sync and License Mapping for CUCM Migration

Direct answer: what should be ready before users migrate?

Provision the users in Webex Control Hub before moving their calling service. Choose one authoritative directory, map identities consistently, claim the required domains, and decide which groups receive Webex Calling Standard, Professional, Workspace, or other feature licences.

Cisco recommends a cloud directory such as Microsoft Entra ID as the long-term source of truth, although Cisco Directory Connector remains available for on-premises Active Directory and Okta can synchronize through SCIM. Do not run competing synchronization methods for the same users.

Then map each CUCM user to the Webex licence that supports the features they actually use. Do this before the migration tool tries to turn a directory problem into a calling problem.

Choose one source of truth

CUCM contains end-user records, but it normally should not remain the master identity store after CUCM is retired. Pick the directory that will own user creation, names, email addresses, status, group membership, and removal.

Common choices are:

  • Microsoft Entra ID synchronized to Control Hub;
  • on-premises Active Directory through Cisco Directory Connector;
  • Okta through the Webex SCIM integration; or
  • another supported SCIM application.

Cisco's current design guidance recommends Entra ID for many migrations because it removes the need for an on-premises connector and can remain the cloud identity source after CUCM is gone. That is a recommendation, not a commandment. Existing Active Directory and security operations may make Directory Connector the right answer.

Understand Cisco Directory Connector

Cisco Directory Connector is an on-premises application that synchronizes Active Directory users and groups into Control Hub. Active Directory remains the source of truth and directory changes are reflected in Webex.

Directory Connector supports a dry run. Use it. Review which users will be created, updated, or disabled before applying the first synchronization to production.

Also confirm redundancy and operations. Who monitors the connector? Which Windows server runs it? What happens during a certificate, proxy, or service-account change? A synchronization design is not complete merely because the first sync finished.

Understand Entra ID and Okta synchronization

The Webex Entra ID integration uses SCIM and can synchronize users without on-premises connector infrastructure. Map the work email, name, status, group, and telephone attributes that Webex needs. Test user creation, attribute change, group change, and disablement.

Okta also uses SCIM 2.0. Cisco explicitly notes that an organization already using Directory Connector cannot also synchronize users from Okta. Choose the owner; do not let two identity systems politely fight over the same account.

For either platform, group membership can drive licence assignment templates. This is a clean model when the directory already knows which employees are knowledge workers, contact-center agents, common-area users, or administrators.

Match CUCM users to Webex identities

Export CUCM end users and compare them with the target directory. Pay attention to:

  • primary work email;
  • userId and login conventions;
  • duplicate or shared accounts;
  • contractors and service accounts;
  • phone numbers and extensions;
  • inactive users;
  • users without mailboxes; and
  • existing Webex accounts claimed under another organization.

The email address is especially important because it connects the person across Control Hub, Webex App, and migration tooling. Fix mismatches before the calling migration. A wrong identity can produce the wrong licence, number, recording owner, and access scope all at once.

Provision everyone before the first calling wave

Cisco recommends provisioning all enterprise calling users in Webex before or near the beginning of the project—even people who will remain on CUCM for later waves.

That lets migrated Webex users search for colleagues who still use Jabber or CUCM. It also separates basic identity readiness from the more disruptive calling cutover.

Provisioning does not mean enabling every service immediately. Create the identity, confirm the directory result, then add the correct Webex Calling licence and number when the migration plan requires it.

Map Standard and Professional licences carefully

Do not assume every CUCM user needs the same Webex Calling tier.

Cisco's current design guide separates Standard users, Professional users, common-area Workspaces, Customer Assist users, attendant-console users, Route List Calls, and PSTN plan requirements. Professional licences cover advanced telephony needs and also affect entitlements such as virtual lines and group voicemail.

Build a feature-to-licence matrix. A simple desk-phone user may fit Standard. A user who needs advanced calling features, queue roles, multiple lines, or specialist capabilities may need Professional. A lobby phone belongs in a Workspace rather than under the receptionist's personal identity.

Check the current Cisco feature-by-licence table against the purchased subscription. Product names and entitlements change; a five-year-old ordering spreadsheet is not an authority.

Know the native migration-tool licence boundary

Cisco documents a specific limitation in the Migrate Unified CM data to Webex Calling tool: migrated users can be assigned Calling Professional or CX Essentials licences through that flow.

If a user needs Webex Calling Standard during migration, Cisco says to assign the user through CSV and then use the Migrate features from Unified CM tool for the remaining CUCM data.

This is exactly the kind of small sentence that can derail a large batch. Split the user population by target licence before importing it, and test both paths with pilot accounts.

Use groups and templates without losing control

Control Hub licence templates can assign services automatically by organization or group. Cisco recommends group-based licence templates where possible.

Create groups that represent real service bundles, for example:

  • Webex-Calling-Standard;
  • Webex-Calling-Professional;
  • Webex-Customer-Assist-Agent;
  • Webex-Attendant-Console; and
  • Call-Recording-Reviewers.

Users in multiple groups receive the union of assigned services. Test overlapping membership deliberately. Otherwise a temporary project group can quietly grant a licence or access level nobody intended.

Keep recording identity and access aligned

Identity mapping is also a call-recording requirement. [call-recording.com](/) associates recordings and supported messages with organization users, devices, numbers, and source identities. A stable user mapping makes it much easier to follow the same person from CUCM capture to Webex Calling recording.

Decide who may search, play, download, export, administer, or review recordings. Directory groups can help express those roles, but call-recording.com organization permissions remain the enforcement boundary for the recording platform.

During the pilot, verify that a migrated call appears under the right person in the single call and message dashboard. An audio file labelled with the wrong identity is a migration defect, even when the audio itself sounds perfect.

Test lifecycle events, not only initial sync

Run a controlled identity test before production migration:

  1. create a test user in the source directory;
  2. synchronize it to Control Hub;
  3. apply the correct licence through the intended group or CSV path;
  4. assign a Webex Calling location, number, and extension;
  5. update the user's name and department;
  6. change the licence group;
  7. disable the account; and
  8. confirm the expected result in Control Hub and connected systems.

Include rehire, name change, and contractor-expiry cases if they happen in the business. The identity platform will be operating long after the migration project closes.

Directory and licensing checklist

Before the first user wave, confirm:

  • [ ] one authoritative directory is selected;
  • [ ] domains are verified or claimed correctly;
  • [ ] CUCM and directory users reconcile;
  • [ ] duplicate and inactive accounts are resolved;
  • [ ] phone numbers use the required format;
  • [ ] Standard, Professional, Workspace, and add-on needs are mapped;
  • [ ] native migration-tool and CSV populations are separated;
  • [ ] licence templates and overlapping groups are tested;
  • [ ] recording reviewers and administrators have intentional access; and
  • [ ] joiner, mover, and leaver events work end to end.

Bottom line

Directory sync and licence mapping are not paperwork before the “real” voice migration. They determine who the user is, which calling features appear, how numbers are assigned, and who owns the resulting business records.

Set identity up first. Test the licence path with pilot users. Then use call-recording.com self-service validation to prove that the correctly licensed person can place a call and that authorized reviewers can find the right recording under the right identity.

Continue with the complete CUCM to Webex Calling migration guide and the feature-parity and recording guide.

Where call-recording.com intervenes

From technical requirement to working recording

call-recording.com preserves the relationship between a recorded conversation and the correct user while supported CUCM and Webex Calling capture coexist in one dashboard.

Source ledger

Primary references and technical evidence

Validate version-specific commands, legal scope, and policy decisions against the current source applicable to your environment.

Legal and compliance content is general information, not legal advice. Cisco behavior and commands vary by product release, platform, firmware, and call flow.