Re: disable users while user is logged into the domain



in fact i case of account disable the DC does not wait for 15 seconds for
change notification if triggers immidiate replication to all dc is the same
site

user might have loged in to other site and the exchange server might be
using the servers from other site where relication has not yet converged
check event id 2080 in the exchange server app logs to see which dc is
beeing used

regards


"Meinolf Weber [MVP-DS]" wrote:

Hello JR,

How long did you wait for testing. When the account is disabled, by default
in windwos 2003 all 15 seconds in windows 2000 all 300 seconds, the intra-site
replication will start. For inter-site replication depending on your AD sites
and services replication, default 180 minutes, minimum 15 minutes.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm


I have about 20 DC's all over the US. I tested disabling an account
that had a outlook web session open. Once I disabled the account it
could still send mail. Not sure if they can still access folder shares
when logged in and account gets disabled. I think they can or at least
can until the DC's sync. Any way I can get immediate lockout or
disable function for users who are logged into the domain and webmail?

"Meinolf Weber [MVP-DS]" wrote:

Hello JR,

Is that only for OWA or can the user also access shared folders from
servers without problem? How may DC's do you have and is the
disabling replicated to all of them?

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties, and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
No it is exchange 2003... Is it different?

"Meinolf Weber [MVP-DS]" wrote:

Hello JR,

Do you mean OWA with webmail? Is it exchange 2007, then you have
also to disable the mailbox.

Best regards

Meinolf Weber
Disclaimer: This posting is provided "AS IS" with no warranties,
and
confers
no rights.
** Please do NOT email, only reply to Newsgroups
** HELP us help YOU!!! http://www.blakjak.demon.co.uk/mul_crss.htm
Im noticing the users who are logged into webmail can still send
mail if there account gets disabled when they are logged into
webmail. I want to be able to disable accounts and instantly stop
them from accessing company resources even if they are logged into
the domain at the time they are disabled. Any suggestions please?




.



Relevant Pages

  • Re: AD Replication Questions
    ... If you fire someone and you have multiple Sites then disabling the user ... account object will be subject to the Intrasite as well as Intersite ... Glad that you added a second DC in Dallas. ... > events would cause replication immediatly. ...
    (microsoft.public.windows.server.active_directory)
  • RE: Scavanging retired machine accounts
    ... Here's a script I wrote a while back that does exactly what you want. ... 'pull back a list of every user's account name and distinguished name ... we're probably only interested in the disabled computer accounts ... 'There is no point disabling PCs based on how many weeks it's been since the ...
    (microsoft.public.windows.server.scripting)
  • Re: Site Links
    ... > You are correct in that replication will be every 30 min. ... > password changes and account disabling are immediate though. ... > immediate replication, you can put them into the same site and encaps ...
    (microsoft.public.win2000.active_directory)
  • Re: disable users while user is logged into the domain
    ... Do you have a link where "disabling" an account falls under urgent replciation? ... Best regards ... This posting is provided "AS IS" with no warranties, ...
    (microsoft.public.windows.server.active_directory)
  • Re: "Enabling" an already enabled user account?
    ... Is that user having problems in all machines or just that one? ... (Logon failure: account currently disabled. ... see Help and Support Center at ... > I've tried actually disabling the account and then re-enabling and with ...
    (microsoft.public.windows.server.active_directory)