AD Sync suddenly deactivating all users

AD Sync suddenly deactivating all users

Comments

  • Hello, I recently updated our Dev environment to version 6.10 and since that update our AD sync has not been working properly. All of the users that are granted access via AD are marked as Active - False. I can manually activate them and grant temporary access, but within a few minutes they are flipped back to False.

  • Ah, this is a common issue with AD Sync. In your AD settings, can you confirm whether or not you have "sync only users" set to true?
    "[img]att1[/img]"

    If it is set to true, we will need to confirm your Synchronization Option under Synchronization Settings. If you are using anything other than [b]"EntireDomain" [/b](i.e sync groups or sync org units), then this behavior is expected. With this configuration, You are basically giving the Sync instructions conflicting data by saying "I want to sync these groups (sync groups)" but also saying "I only want to sync users no groups (sync only users)." Because decisions doesnt know how to handle the request, it just brings in the users and then deactivates them.

    If this is your current set up, and you want to keep using your sync groups, just go up to the top and deselect the option to "sync only users". Once you do, save your settings, and navigate back to the Settings page. Right-click your AD settings and hit "reset sync info". From here you can choose to manually re-run your sync, or let it run on the next AD sync job.

Sign In or Register to comment.