Sync time for disabled account

NK 1 Reputation point
2019-12-12T11:27:15.96+00:00

Hi There,

If I disable any account in on-premises DC, does this syncs immediately like passwords?

If not, how can I make sure it does?

Cheers,
NG

Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,389 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Vasil Michev 94,911 Reputation points MVP
    2019-12-12T12:10:56.47+00:00

    No, it syncs like any other attribute, 30 mins by default. You can force a sync as detailed here: https://learn.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-feature-scheduler#start-the-scheduler

    Start-ADSyncSyncCycle -PolicyType Delta  
    
    1 person found this answer helpful.
    0 comments No comments

  2. NK 1 Reputation point
    2019-12-12T13:30:17.267+00:00

    Hi @Vasil Michev .

    But this is a security risk, isn't it? If we disable an account and it's still enabled in AzureAD so the leaver can still access the cloud resources especially when we have synced the password.

    Cheers,
    Narayan