You can automatically disable Unix accounts when users are de-provisioned in ActiveRoles Server. 
To de-provision Unix users
- From the ActiveRoles Server Console, navigate to Configuration | Policies | Administration. 
- From the Action menu, select New | Deprovisioning Policy. 
- When the New Deprovisioning Policy Object Wizard starts, click Next. 
- On the Name and Description page, enter Disable Unix accounts for deprovisioned users in the Name box and click Next. 
- On the Policy to Configure page, locate the Safeguard Authentication Services Integration Pack and select the Deprovision Unix User policy type and click Next. 
- On the Policy Parameters page, select the UnixDisable parameter and click Edit. 
- On the Edit Parameter page, open the Value: drop-down menu, select True and click OK. 
- On the Policy Parameters page, select the PrimaryGidNumber parameter and click Edit. 
- On the Edit Parameter page, specify an integer value for the Primary GID number and click OK. 
- On the Policy Parameters page, click Next. 
- On the Enforce Policy page, click the Add button. 
- On the Select Objects page, click Browse, select Active Directory (to apply this policy to all new users), and click OK. 
- On the Select Objects page, select the Active Directory item at the top of the list, click Add and then click OK. 
- On the Enforce Policy page, click Next. 
- Click Finish to create the new policy object and close the wizard. 
When you de-provision a user account, the Integration Pack automatically disables the user's Unix attributes. 
 
    
To automatically Unix-enable groups 
- From the ActiveRoles Server Console, navigate to Configuration | Policies | Administration. 
- From the Action menu, select New | Provisioning Policy. 
- When the New Provisioning Policy Object Wizard starts, click Next. 
- On the Name and Description page, enter Unix-enable new groups in the Name box and click Next. 
- On the Policy to Configure page, locate the Safeguard Authentication Services Integration Pack and select the Provision Unix Group policy type and click Next. 
- On the Policy Parameters page, select the AutoUnixEnable parameter and click Edit. 
- On the Edit Parameter page, open the Value: drop-down menu, select True and click OK. 
- On the Policy Parameters page, click Next. 
- On the Enforce Policy page, click the Add button. 
- On the Select Objects page, click Browse, select Active Directory (to apply this policy to all new Active Directory groups), and click OK. 
- On the Select Objects page, select the Active Directory item at the top of the list, click Add and then click OK. 
- On the Enforce Policy page, click Next. 
- Click Finish to create the new policy object. 
- On the ActiveRoles Server dialog, click OK to return to the ActiveRoles Server Console. 
When you provision a new group account, the Integration Pack automatically Unix-enables the users associated with that account. That is, it populates the user's Unix attributes. 
 
    
You can automatically disable Unix accounts when groups are de-provisioned in ActiveRoles Server.
To de-provision Unix groups 
- From the ActiveRoles Server Console, navigate to Configuration | Policies | Administration. 
- From the Action menu, select New | Deprovisioning Policy. 
- When the New Deprovisioning Policy Object Wizard starts, click Next. 
- On the Name and Description page, enter Disable Unix accounts for deprovisioned groups in the Name box and click Next. 
- On the Policy to Configure page, locate the Safeguard Authentication Services Integration Pack and select the Deprovision Unix Group policy type and click Next. 
- On the Policy Parameters page, select the UnixDisable parameter and click Edit. 
- On the Edit Parameter page, open the Value: drop-down menu, select True and click OK. 
- On the Policy Parameters page, click Next. 
- On the Enforce Policy page, click the Add button. 
- On the Select Objects page, click Browse, select Active Directory (to apply this policy to all new groups), and then click OK. 
- On the Select Objects page, select the Active Directory item at the top of the list, click Add and click OK. 
- On the Enforce Policy page, click Next. 
- Click Finish to create the new policy object and close the wizard. 
When you de-provision a group account, the Integration Pack automatically clears the group's Unix attributes rendering it Unix-disabled.