AD Admin account to be disabled when employee quits

I have case where customer would like to disable AD Admin accounts when person is left.

There are currently lot of admin accounts created directly in AD, first we would need to map them to identity, but we don't want to update information / birth rights to them. We just would need to disable those accounts when person is left. Persons do also have another AD account which they use in daily life, but those admin accounts are used to sign shared servers etc.

What is the preferred way to handle this kind of  scenario?

Parents
  • Hei Timo,

    In the AD created admin accounts need to read into the One Identity Manager. Then they need to mapped against the correct persons. The accounts do not need to be mapped with an TSBAccountDef. The Configuration parameter QER\Person\TemporaryDeactivation takes care that the active directory accounts are disabled when the person quits.

Reply
  • Hei Timo,

    In the AD created admin accounts need to read into the One Identity Manager. Then they need to mapped against the correct persons. The accounts do not need to be mapped with an TSBAccountDef. The Configuration parameter QER\Person\TemporaryDeactivation takes care that the active directory accounts are disabled when the person quits.

Children