To prevent a particular user from logging on, you can block the user account as a security measure instead of deleting it. You can block and unblock Active Directory user accounts with the Active Roles Console.
To block a user account
-
In the Console tree, locate and select the folder that contains the user account you want to block.
-
In the details pane, right-click the user account and click Disable Account.
NOTE: Consider the following when blocking a user account:
-
To prevent particular users from logging on for security reasons, the administrator can block user accounts instead of deleting user accounts.
-
The Disable Account command appears if the account is enabled and thus can be used for login; otherwise, the Enable Account command appears on the menu. By using the Enable Account command the administrator can change the status of the blocked account to allow the user to log in with that account.
-
To locate user accounts for blocking, use the Find function of Active Roles. Once you found the users, block them by selecting the accounts in the list of search results, right-clicking the selection, and clicking Disable.
-
Since the Copy function ensures that the copy of a user account belongs to the same groups as the original user account, you can create a blocked user account that belongs to certain groups, then make copies of that account to simplify the creation of user accounts with common group memberships.
You can unblock a blocked user account with the Active Roles Console. The Enable Account command only appears for deactivated accounts, marked with the icon.
To unblock a blocked user account
-
In the Console tree, locate and select the folder that contains the user account you want to unblock.
-
In the details pane, right-click the user account and click Enable Account.
NOTE: Consider the following when unblocking a user account:
-
The Enable Account command appears if the account is blocked and cannot be used for login; otherwise, the Disable Account command appears in the menu. To prevent particular users from logging in for security reasons, block user accounts with the Disable Account command.
-
To locate user accounts for unblocking, use the Find function of Active Roles. Once you found the users, unblock them by selecting the accounts in the list of search results, right-clicking the selection, and clicking Enable Account.