Block azure/o365 login if ad account is disabled via ad connect

brenji 6 Reputation points
2021-09-29T20:46:43.05+00:00

I noticed that when accounts are disabled in AD, AD connect does not sync this attribute and block sign-in to azure/o365. Is it possible to sync this attribute to automate this?

Thank you,

Ryan

Active Directory
Active Directory
A set of directory-based technologies included in Windows Server.
5,843 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,453 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Vasil Michev 95,181 Reputation points MVP
    2021-09-30T07:30:08.927+00:00

    That's not the default behavior, accounts disabled on-premises will have the corresponding BlockCredentials flag toggled in Azure AD too. If that's not what you are seeing, check your sync rules. Or do you perhaps mean "locked" accounts?

    1 person found this answer helpful.
    0 comments No comments

  2. Limitless Technology 39,351 Reputation points
    2021-09-30T15:12:11.537+00:00

    Hi there,

    If a synced directory user account is disabled in Azure or Active Directory, the user will be disabled in Duo automatically when the next directory sync occurs. This is by design and I suppose you cannot automate this


    --If the reply is helpful, please Upvote and Accept as answer--

    0 comments No comments