question

narayankumargupta avatar image
narayankumargupta asked ·

Sync time for disabled account

Hi There,

If I disable any account in on-premises DC, does this syncs immediately like passwords?

If not, how can I make sure it does?

Cheers,
NG

azure-ad-connect
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

michev avatar image
michev answered ·

No, it syncs like any other attribute, 30 mins by default. You can force a sync as detailed here: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-feature-scheduler#start-the-scheduler

 Start-ADSyncSyncCycle -PolicyType Delta
Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

narayankumargupta avatar image
narayankumargupta answered ·

Hi @michev.

But this is a security risk, isn't it? If we disable an account and it's still enabled in AzureAD so the leaver can still access the cloud resources especially when we have synced the password.

Cheers,
Narayan

1 comment Share
10 |1000 characters needed characters left characters exceeded

Up to 10 attachments (including images) can be used with a maximum of 3.0 MiB each and 30.0 MiB total.

Not really, disabling the user doesn't stop access immediately anyway. The user will continue to have access for the validity of the access/refresh token. To speed things up, kill the refresh tokens, remove license and block email protocols.

0 Votes 0 · ·