Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations gkittelson on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

Windows AD Authentication - AD user is deleted

Status
Not open for further replies.

weikfan

Programmer
May 4, 2005
46
US
Hi All,

We are on CE 10 using Windows AD authentication. My question is: When a user is deleted from the Windows AD group, what happens to the CE user and its favorite folder that were created on CE when the user was added to the AD group? Does the Administrator need to manually delete the user in CE or will the user and their folder be dropped after sometime?

Could you also please let me know if it works the same way in BOXI? We are planning to migrate to BOXI.

Thanks.
Fan
 
Each time a user logs-in to CE-10 or BOE-XI it authenticates the user against WinAD to confirm that they have active-rights.

If they do not then they are denied access to CE-10 or BOE-XI. That user disappears for the CE-10 or BOE-XI user list.

We don't allow the use of user-folders, so I don't know if that user has a user-folder with contents if they are auto-deleted - or orphaned.

My guess would be that folders without contents are auto-deleted, folders with contents are orphaned.

Similar to what happens to SCHEDULED INSTANCES that have been scheduled by a deleted user. The next time the instance tries to run, it errors-out with an access error - but the recurring instance does not go away.

Best thing to do would be to test it.
 
Hi,
I believe that the CMS will poll the AD groups periodically and will alter the membership in BOE as needed, based on the current members in that group
( not sure about folders, however)

If, however, an entire AD group is deleted from the Domain Tree, it can cause a failure to authenticate ANY AD account user...Be sure your AD administrator lets you know before deleteing Groups used by your BOE system..

.

[profile]

To Paraphrase:"The Help you get is proportional to the Help you give.."
 
Hey Guys,

we are also using AD groups and turkbear is right in saying that the cms polls for the AD groups periodically.
The period can be set somewhere in the registry. Don't know the actual position in the registry right know.
You can also update the groups manually in the tab where you set new AD - Groups.

Unfortunatelly, the private folder from a deleted User is also deleted by the system. We had a lot of trouble with changes usernames (marriage)...
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top