Sync time for disabled account

NK 1 Reputation point
2019-12-12T11:27:15.96+00:00

Hi There,

If I disable any account in on-premises DC, does this syncs immediately like passwords?

If not, how can I make sure it does?

Cheers,
NG

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
22,611 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Vasil Michev 110.8K Reputation points MVP
    2019-12-12T12:10:56.47+00:00

    No, it syncs like any other attribute, 30 mins by default. You can force a sync as detailed here: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-feature-scheduler#start-the-scheduler

    Start-ADSyncSyncCycle -PolicyType Delta  
    
    1 person found this answer helpful.
    0 comments No comments

  2. NK 1 Reputation point
    2019-12-12T13:30:17.267+00:00

    Hi @Vasil Michev .

    But this is a security risk, isn't it? If we disable an account and it's still enabled in AzureAD so the leaver can still access the cloud resources especially when we have synced the password.

    Cheers,
    Narayan


Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.