cancel
Showing results for 
Search instead for 
Did you mean: 

Disabled Users

Dan_Lynch
Level 3
Hi,
I've read through other people's strategies for handling terminated/disabled users and there's just a few things I was still wondering.
We are using EV 6.0 SP3 (Exchange and FSA). Right now we have a 'Disabled' OU that is targeted by an archive everything policy .
How can I disable their AD account once their entire mailbox is archived? It is my understanding that the user has to be enabled for their mailbox to be archived. I understand that we could set a policy whereby they could not log in once they are in the "disabled" ou, but our security folks prefer to have that Account Disabled bit set in AD for readability/auditor purposes. My thought initially would be to give them 2 weeks for good measure and disable the account based on the "whenChanged" property (being moved to the Disabled ou being the last change).
Many thanks in advance.
2 REPLIES 2

Alan_M
Level 6
Disable the account in AD as per current policy, EV should still be able to access the mailbox if the user account is disabled (assuming you have this hotfix http://support.microsoft.com/kb/916783/en-us) Move the account to the disabled OU. Archive mailbox. Disable within EV.

Dan_Lynch
Level 3
Ah
Thank you very much.

Unfortuately we are not on SP2 yet but this should help expedite that...