When an Employee account is disabled in Identity Manager (both permanently and temporarily), the corresponding Active Directory (AD) account is removed from the target system and the ADSAccount is deleted in the database.
Can this behaviour be overridden? For example, disable the ADSAccount instead of deleting it?
This is the default behaviour, but it can be changed. You can define the desired behaviour in the settings of the account definition, e.g.:
If the Employee is disabled permanently or temporarily then the Account definition will remain associated with the Employee and the ADSAccount will be disabled, but not removed from the database or AD.
© 2025 One Identity LLC. ALL RIGHTS RESERVED. Terms of Use Privacy Cookie Preference Center