I'm relatively new to my current company and have been asked to clean up a lot of the manual processes they have here. The first task is with stale accounts in Active Directory. Currently they run a script to disable anything considered a stale account. They then run another script that also strips the account of all of it's AD group memberships and dumps it into a Disabled Items OU.
My question is what is the purpose of stripping the group memberships before disabling? The last company I was at we only only stripped the memberships before we deleted the account, not prior to disabling the account. So IMHO removing the groups on a disable is excess and makes it a pain to recover should the account need to reinstated (and they have a ton of subsidiaries that only log in a couple times a year for training and HR items). No one here can tell me why this is done.....am I wrong in my thinking?
=================
There are 10 kinds of people in this world, those that understand binary and those that do not.
My question is what is the purpose of stripping the group memberships before disabling? The last company I was at we only only stripped the memberships before we deleted the account, not prior to disabling the account. So IMHO removing the groups on a disable is excess and makes it a pain to recover should the account need to reinstated (and they have a ton of subsidiaries that only log in a couple times a year for training and HR items). No one here can tell me why this is done.....am I wrong in my thinking?
=================
There are 10 kinds of people in this world, those that understand binary and those that do not.