How to manage deleted user from AD

I can see this question was posted several times , but I am wondering if somebody can tell me what is actually right process when user is deleted from AD or when user or when usrers properties get updated.

Here is the scenario:

  1. All users are synchronized  via AD connector to CMDB, and they can be seen in User View in SCSM (configuration item- users)
  2. User A leaves the company. The our process is to disable usess  account  and rename it  by adding the date when user object was disabled . For example  (April 15<sup>th</sup>, 2015)user name
  3. After the next sync in User View in SCSM I cannot see  user object , neither old or with disabled properties.
  4. The user object is also not in Deleted Items View in the Administration workplace.
  5. If an analyst wants to create a new ticket , he can by mistake choose disabled user from the picker dialog.  It tells that user still exist in CMDB, but not sure why in that case it cannot be seen in  User View.
  6. After one month user object will be deleted and from it will stay in hidden deleted container in OU for 3 months.
  7. As per one article from Travis , run as account needs to have list object on that folder even I do n see that on any Microsoft document. Or at least I did not find it.

So basically I need to understand if per  Microsoft design user object needs to be deleted from  CMDB after the user is deleted from AD or not? I think it should not. However, we have many contractors who  leaves and comes back.

I think when they come back in the picker dialog it will be listed same user several times in this case which can be a big issue.

I need to know what actually needs to be done by AD connector and what needs to be done manually in SCSM if necessary.

April 21st, 2015 4:06pm

Hi,

We could prevent the disabled Active Directory user accounts are not imported into the SCSM CMDB through the Active Directory Connector. This can be achieved by the LDAP filters in SCSM 2012.

For a complete description of the steps mentioned above, check out this article:

Excluding disabled users from AD Connector

http://blog.dietergasser.com/2013/03/15/excluding-disabled-users-from-ad-connector/

Note: Microsoft provides third-party contact information to help you find technical support. This contact information may change without notice. Microsoft does not guarantee the accuracy of this third-party contact information.

Free Windows Admin Tool Kit Click here and download it now
April 22nd, 2015 3:29am

This topic is archived. No further replies will be accepted.

Other recent topics Other recent topics