Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

Is their Active Directory account still active (enabled)?

In order for an account to be active enabled in Active Directory, it must have an Active logon status in the EID system AND . If it is disabled or flagged to require a password change in the EID system, it will be disabled in Active Directory.
If the account has one of the Affiliations or Entitlements mentioned here, its Primary Group will be Domain Users; otherwise its Primary group will be Domain Guests. By default, Domain Guests can not log onto computers joined to the domain.

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

Can they still authenticate using Enterprise Authentication?Enterprise Authentication EntAuth? (EntAuth is backed by Austin Active Directory.abcxyzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz. Consider 2FA (Duo) as well………………………….)

As long as their Active Directory account is still enabled they will be able to authenticate using EntAuth, regardless of whether or not they have one of the Affiliations or Entitlements mentioned here that sets their Primary Group to Domain Users. For example: former employees will still be able to log in to review their tax forms for their last year of employment.

The configurations of specific applications behind EntAuth may or may not have further requirements to use them.

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

When does their account get removed from Active Directory?

An automated process removes Active Directory accounts based on conditions specified here. This process is in place to remove any accounts that are no longer needed. If a user’s Active Directory account has been removed, it will be re-created if/when they obtain one of the Affiliations or Entitlements mentioned here. Because the re-created account is a new object in Active Directory, it will not be a member of any groups they remained in at the time of removal.

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

Are they automatically removed from Active Directory groups?

Users are not automatically removed from groups when they leave the University, even when their Active Directory account is disabled.

For the most part, groups in Austin Active Directory are owned and managed by the Department that created them. Departments are responsible for maintaining the memberships of their groups, removing any members that are no longer necessary.
A user may need to be removed from a group if:

  • They are no longer at the University

  • They remain at the University but no longer fall under the intended scope of the group (for example, an employee who leaves your department and is still a current employee working for another department should be removed from groups that give them access to your department’s resources)

...

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

If they are still in an email distribution group, will they continue to get emails addressed to the group?

As long as they still have a M365 mailbox, they will receive emails addressed to any email distribution groups they are a member ofWhat happens to their M365 Mailbox?

Refer to Eligibility for M365 : What Happens After I leave the University.

panelIconText
Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

What happens if they were a Department OU Owner?

At this time, no action is automatically taken to remove them as owners. Another Department OU Owner should remove them using the Department User Tools (📑 Documentation).

Audit reports are emailed to Department OU owners monthly. One of the items that appear in this audit is ineligible owners that should be removed.

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:

:question_mark:
bgColor#F4F5F7

Q

A

Departmental (DEPT-) Active Directory Accounts

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

Are their departmental user accounts disabled or deleted when they leave the University?

At this time, no action is automatically taken on departmental accounts when the assignee leaves the University.
Department OU Owners are responsible for disabling or deleting departmental accounts when they are no longer needed.

...

Q

A
Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7
Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

What about Service AccountsWhat about departmental service accounts?

Service accounts can be assigned to more than one person at a time (although they can only be claimed by one person at a time).
When an assignee has left the University, a Department OU Owner should remove them from the list of assignees of their service accountsaccount(s), and another assignee should claim the account(s). This prevents them from having control over these service accounts if they ever do return to the University (a former employee in your department may later return as an employee in another department or a student).

...