To configure a Home Folder Deprovisioning policy, select Home Folder Deprovisioning on the Policy to Configure page in the New Deprovisioning Policy Object wizard or in the Add Deprovisioning Policy wizard. Then, click Next to display the Options to Deprovision Home Folder page.
Figure 79: Options to Deprovision Home Folder
The names of the first four options are self-explanatory. These refer to the policy options summarized in the table above:
- Remove the user’s permissions on the home folder.
- Grant the user’s manager read-only access to the home folder.
- Grant these users or groups read-only access to the home folder.
- Make this user or group the owner of the home folder.
Select check boxes next to the options you want to be applied.
The third option requires that you click the Select button to choose users or groups. The users or groups you select will be authorized to view and retrieve data from the home folders of the deprovisioned users.
The fourth option requires that you click the Select button to choose one user or group. The user or group you select will be authorized to control permissions on the home folders of the deprovisioned users.
You can also configure the policy to delete home folders. If you select the Delete the home folder when the user account is deleted check box, the policy causes Active Roles to delete the home folder once the user account associated with that folder is deleted. You can refine this behavior by selecting one of these options from the list beneath the check box:
- If home folder is empty. Prevents Active Roles from deleting not empty home folders. If a given home folder contains any data, the policy does not delete that folder.
- Always. Allows Active Roles to delete both empty and not empty home folders. Regardless of whether a given home folder contains any data, the policy deletes that folder upon user account deletion.