When synchronizing accounts between source and target environments the disabled (enabled) account status is not synchronized. For example if you have a disabled account in the source and an enabled account in the target domain, the result of synchronization session with the direction from source to target will be enabled account.
The opposite synchronization from target to source in this example will be left as the disabled account in the source.
This behavior is by design. Synchronization jobs do not synchronize "user is disabled" flag.
The ability to synchronize disabled (enabled) status may be required depending on the migration scenario to provide coexistence between source and target environments for the extended period of time.
Due to the flexibility expected from Migration Manager for Active Directory, CR0149486 was created to provide this enhancement; it will be evaluated for a future release.
The reason for not synchronizing the account status is because in an on going migration most customer's disable the source account after the user is switched to the target. This security action is recommended.
© 2021 Quest Software Inc. ALL RIGHTS RESERVED. Feedback Terms of Use Privacy