question

narayankumargupta avatar image
0 Votes"
narayankumargupta asked narayankumargupta answered

Sync time for disabled account

Hi There,

If I disable any account in on-premises DC, does this syncs immediately like passwords?

If not, how can I make sure it does?

Cheers,
NG

azure-ad-connect
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

michev avatar image
1 Vote"
michev answered

No, it syncs like any other attribute, 30 mins by default. You can force a sync as detailed here: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-feature-scheduler#start-the-scheduler

 Start-ADSyncSyncCycle -PolicyType Delta
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

narayankumargupta avatar image
0 Votes"
narayankumargupta answered michev commented

Hi @michev.

But this is a security risk, isn't it? If we disable an account and it's still enabled in AzureAD so the leaver can still access the cloud resources especially when we have synced the password.

Cheers,
Narayan

· 1
5 |1600 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Not really, disabling the user doesn't stop access immediately anyway. The user will continue to have access for the validity of the access/refresh token. To speed things up, kill the refresh tokens, remove license and block email protocols.

0 Votes 0 ·