Sync time for disabled account

Narayan Kumar Gupta 1 Reputation point
2019-12-12T11:27:15.96+00:00

Hi There,

If I disable any account in on-premises DC, does this syncs immediately like passwords?

If not, how can I make sure it does?

Cheers,
NG

Microsoft Security | Microsoft Entra | Microsoft Entra ID
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Vasil Michev 122.7K Reputation points MVP Volunteer Moderator
    2019-12-12T12:10:56.47+00:00

    No, it syncs like any other attribute, 30 mins by default. You can force a sync as detailed here: https://free.blessedness.top/en-us/azure/active-directory/hybrid/how-to-connect-sync-feature-scheduler#start-the-scheduler

    Start-ADSyncSyncCycle -PolicyType Delta  
    
    1 person found this answer helpful.
    0 comments No comments

  2. Narayan Kumar Gupta 1 Reputation point
    2019-12-12T13:30:17.267+00:00

    Hi @Vasil Michev .

    But this is a security risk, isn't it? If we disable an account and it's still enabled in AzureAD so the leaver can still access the cloud resources especially when we have synced the password.

    Cheers,
    Narayan


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.