Disabled AD users still showing in People Search - LDAP query already filtering

We are running MOSS 2007 on Windows Server 2008 R2 Standard. In the past couple of weeks we have noticed that our disabled Active Directory users are no longer being removed from SharePoint. On my import connection I have an LDAP query of "(&(objectCategory=Person)(objectClass=User)(!userAccountControl:1.2.840.113556.1.4.803:=2)(mail=*ca)(sn=*)(department=*)(!(!givenName=*)))",
which among other things is filtering out disabled users. This has been this way for 5 years now and always worked fine. Now it has stopped doing its job and I can't figure out why. I have performed a complete reindex of the search as well as multiple full
profile imports all to now avail.
Can anyone shed some light on this for me?
TIA
Sandra

Create the filter in AD connection 
Open Edit connection filters screen from that you can see Exclusion filter for users.
In Exclusion filter for users enter the below values.
Attribute : userAccountControls (Select from dropdown)
Operator: Bit on Equal (Select from dropdown)
Filter : 2
Once you enter the required values click on Add button and it will show the
below details in Exclusion filter for users.
Do the full crawl after this. 
Check for details
http://support.microsoft.com/kb/827754?wa=wsignin1.0

Similar Messages

  • I deleted some of my text message histories to get rid of 'other' space (6.33 gb). They were gone from iMessage, but they still showed up in search, so they were still taking up space on my phone. I synced my iPhone (4s) but the messages are still there.

    I deleted some of my text message histories to get rid of 'other' space (6.33 gb). They were gone from iMessage, but they still showed up in search, so they were still taking up space on my phone. I synced my iPhone (4s) with iTunes but the messages are still there. How can I get rid of these texts for good and have more space on my phone? 6.33 gb of other space is way too much, thats almost half of my overall available space (13.5 gb.) I don't want to reset my phone and lose all my other texts/ app progress/ photos. I do have backups, but when I restore from the backup the other space comes back along with everything else. What can I do to get rid of this other space and the 'deleted' text messages? (I'm running iOS 6.1.3 if that helps)

    But once again, I do not want to lose my other texts, app progress, and photos. I could sync the photos but i would still lose the app progress and texts. I would only restore if it was the only option left, but the other space, as already stated, isnt the main concern. The main concern is those 'deleted' texts. If they go, then a good size chunk of the other space goes. I know you CAN delete texts for good. It worked fine before. All i want to know is why its not working for me now, and how to fix it.
    I also know that when you delete texts on your iphone, they get marked for deletion, however they stay on your device (thats why they show up when you search for them.) then when you sync your device with itunes, the texts marked for deletion should disappear. When i synced they didnt disappear. Thats what i need an explanation/solution for. Why the texts marked for deletion didnt get fully deleted after the sync.

  • RH 11: Conditional Build tags applied: Content still showing up in search

    Hello. I am generating WebHelp using conditional build tags using RH 11.
    I have marked books in the TOC with a CBT of Not in 6.1.
    I generated help and excluded content marked with the CBT Not in 6.1.
    When the Web Help is generated, the books marked with the CBT  do not display in the TOC. However, if I do a search, topics that are under the books and therefore should not be included in the output have search results returned.
    Is there a scenario in which topics that have been excluded from the generated help would still show up in search?
    Your help is greatly appreciated.
    Jenny

    Hi Jenny
    Indeed there are a few reasons this may happen.
    First, simply excluding a topic or a book in the TOC simply makes sure that the TOC doesn't have a link pointing to the topic. Normally, I'll just tag the topic itself and ignore tagging the TOC. If a topic has been excluded, it won't appear in the TOC.
    In the WebHelp SSL recipe, click to expand the Content Categories section and look at the settings on the right. You might try ensuring the following option is enabled. It's named Exclude Unreferenced Topics from Output. As long as nothing else is linking to the topic, ensuring it is removed from the TOC *SHOULD* cause it to no longer be included.
    Cheers... Rick

  • I delete my browser history but websites visited still show up in Search mode. Why?

    How can the browser history really be deleted so nothing shows up when a search is being done?  When I follow the traditional steps to delete the browser history, it shows the history as being cleared, but any letter typed in Search mode will show any websites visited with that letter in the name...  So how do I really delete the browser history, so nothing shows up under search?  And yes, I know you can take the browser info off the search mode, but that doesn't clear the info.  If you put the browser back on search, it's all still there.

    Don't wipe your phone!!!  its a pain in the back side re-installing everything back

  • Name/Password radio clicked -- users still show

    We're tightening security on our macs and have been changing login options from showing a list of users to showing Name and password.
    On one particular machine, I logged into the admin account to make the switch and the panel in System Prefs-->Accounts-->Login Options where you would normally choose a radio button under Display Login Window As: ... was grayed out. I though that odd, so I enabled the root user, logged in as root, was able to choose the appropriate radio button and logged out.
    When I came back, I was presented with what I wanted -- Name and Password boxes. But when I log in as the local user (or admin user) and Log Out (or Restart), I'm presented with the list of users again, NOT the Name/Password boxes.
    Looking again at the selections as the admin, the correct selection is chosen, but the options are grayed out and I couldn't change them if I wanted.

    OK, found it. I recalled this happened just after I bound the machine to Active Directory. I had chosen to allow administration by enterprise admins, and I guess somewhere up the line, somebody has turned on showing List of Users as the preference. I unbound, unchecked, restarted and now all is well.
    Now I have to track down the network admin up the line to make sure that doesn't happen again down the road.

  • CVI 2013: All warnings are disabled but it still shows one warning

    Hi,
    You missed this one:
    warning: second parameter of 'va_start' not last named argument
    It also doesn't have a "warning flag" like "warning: will never be executed [-Wunreachable-code]".
    And it can't be disabled.
    Just noticed.
    /* Nothing past this point should fail if the code is working as intended */

    Hello CVI-User,
    I have created bug report #430712 to track this issue. We will fix it in a future release.
    Best regards,
    Nelu F. || National Instruments.

  • MySite Deletion Emails, UPS, People Search Results

    SharePoint 2013
    We exclude disabled accounts from the UPS for a number of reasons - we don't want the overhead of non-employees, we don't want (requirement) these users to show in people search results, etc.
    Problem - Managers who receive the MySite Deletion email cannot access the account because the account does not exist.
    How do we solve this problem?
    If we include disabled accounts in the UPS, can we filter that information so that only accounts disabled within the last X number of days are included? And if that's attainable, how do we then filter out disabled accounts from people search results
    for those users who were imported?
    Is there a better way to accomplish this?
    There seem to be a large number of threads on this topic, but no real definitive answer or best practice, other than just saying 'import disabled accounts into the ups', which isn't a blanket resolution and will not work for us.
    Thanks
    SPNoob

    Not sure what you mean by "manager cannot access the account..." When you filter disabled accounts in UserProfile Sync the following things happen
    The disabled user will be missing from the next User Profile Sync.  They will be marked as "Missing from Import".
    When the MySite CleanUp job runs users who are missing from IMport will have their profiles deleted.  Their mySite will also be added to a list which will delete the site after 14 days.  Their manager in AD will also be made the secondary site
    collection admin of the mysite and sent an email with a link to that mysite.  The manager won't be able to login to the mysite home page, but will be able to access all the lists and libraries on the mySite to retrieve any IP stored there.
    After 14 days the MySite will be deleted.
    The user's information will remain in the UserInfo table of each site collection where they contributed content.  That way their name will still show for CreateBy and ModifiedBy entries on content.
    That's how the process works.  If you can explain what you mean by manager cannot access the account I'll try to help and explain further.
    Paul Stork SharePoint Server MVP
    Principal Architect: Blue Chip Consulting Group
    Blog: http://dontpapanic.com/blog
    Twitter: Follow @pstork
    Please remember to mark your question as "answered" if this solves your problem.

  • User has been deleted from UPS, however its getting display in People Search in search site - why ?

    Hello,
    I have deleted user into UPS, however its still being display in people search.
    I believe search crawl will delete the information from people search - However I am not sure whether its correct approach to run delete information from people search.
    If user is not available in UPS then why user's information is being display in site ? and by when it may delete automatically?
    Thanks and Regards,
    Dipti Chhatrapati

    Hello Both, Thank you for your response !
    Kindly consider following points where I am confusing.
    Incremental Crawl is scheduled every 30 minutes - I have rechecked after 15 hours of deleting the user and still this user is available in People search.Few days back I ran the incremental crawl manually in order to delete the users from
    people search that has worked - that means - incremental scheduler is not working as per the expectation ???
    Full Crawl is scheduled on weekly basis - so user information will be deleted automatically when full increment will run next time ? 
    Also, there is My site clean up job that keeps user data for 14 days even though user has been deleted from UPS.that means user information will be deleted only after 14 days of deleting user from UPS ?
    It will be much appreciated if this will be clear from my head !!!
    Note: UPS doesn't sync disabled account since it has been specified in connection filter.
    Thanks and Kind Regards,
    Dipti Chhatrapati

  • Images are not being display in people search for few users - why ?

    Hello,
    In my farm, users having profile picture in UPSA and they are able to see in My Profile page as well.
    However when I find user in People search - images are not being display for few users while for others it works.
    I have checked picture property which is indexed and then I run full crawl still its same issue.
    Following are the settings for Picture Property - would you please let me know why its still not being display in people search ?
    Dipti Chhatrapati

    Dipti,
    Hope below urls will help you,
    https://littletalk.wordpress.com/2010/12/10/people-search-result-doesnt-have-images-in-sharepoint-2010/
    https://social.technet.microsoft.com/Forums/office/en-US/eea8aa10-4565-41bf-98ec-dc93fb600021/some-users-pictures-are-not-showing-in-people-and-groups-but-are-viewable-in-the-thumbnail-and-my?forum=sharepointgeneralprevious
    http://westerdale.biz/sharepoint-2010/display-active-directory-profile-thumbnail-photo-and-other-attributes-in-sharepoint-2010?doing_wp_cron=1421939809.4895009994506835937500
    Sudip
    Please 'propose as answer' if it helped you, also 'vote helpful' if you like this reply.

  • Users still able to sign into Lync 2010 even though their Lync accounts are disabled

    I have 2 users who are still able to sign into Lync 2010 even though I disabled their Lync accounts. They no longer show up in the Lync console or when you use get-csuser. Their Lync account were associated somehow with their AD accounts in an old domain
    that we just decommissioned. I wanted to delete Lync accounts and recreate to see if that fixed their issue. After deleting the Lync account, they are still able to login. So, I guess I need to edit the Lync database to get rid of them and start fresh?.
    HDL

    Hi Winterthur,
    Agree with Tek-Nerd,
    this user certificate is valid for a period of 180 days, and is automatically renewed one month prior to expiration regardless of whether the user is connected internally or externally.
    Jeff Guillet’s article Disabling a User in AD Does Not Disable the User in Lync provides
    a good background about revoking this certificate and properly disabling the user from accessing Lync services when their Active Directory user account is disabled.
    For more details,
    http://blogs.technet.com/b/nexthop/archive/2012/11/28/lync-2010-client-authentication.aspx
    Best regards,
    Eric

  • Disabled users still in address book

    We are running Exchange 2000 on a Windows 2003 / AD platform. Disabled users are still appearing in the Outlook 2003 address book. Shouldn't they be automatically hidden? Users are accessing these addresses and creating emails, but of course can't get to the users.
    Firstly, how do I make a list of all users that were disable but are still in the address list. Secondly, what's the best method to hide them (without having to access each one separately) ?
    Thanks.

    Well, just disabling user account doesn't remove the user name from address book. You need select an option "Hide from Exchange address lists" available in Exchange Advance tab of user properties.
    I used to get the list of disabled users which are not hidden in GAL with below custom LDAP query in Exchange 2003.
    Open ADU&C, Right click on Domain & click on Find, in Find select "custom search", select Advance tab and in "Enter LDAP Query" paste below ldap query and click on Fiind Now.
    (mailNickname=*)(userAccountControl=66050)(!msExchHideFromAddressLists=True)
    You may need to verify the value of an attribute "userAccountControl" of any disabled user with ADSIEdit.msc and give that value instead of 66050 because that one I used in Exchange 2003 and Windows 2003 environment.
    Amit Tank | MVP - Exchange | MCITP:EMA MCSA:M | http://ExchangeShare.WordPress.com

  • Disabled fonts still showing up in programs

    I have over 1700 fonts and most of them are disabled through Font Book.
    However, all of them still show up in programs like Photoshop and Illustrator.
    It's murder having to scroll through the whole list, esp. when most of them shouldn't even be visible.
    Am I getting this wrong? What's the point of Disabling a font in Font Book? Why are they still showing up?

    • Yes, I asked on the Adobe forums as well. No luck there.
    • Can't strip down to a nucleus of fonts. I'm a graphic designer and I'm often font matching.
    • No, it's not just a Snow Leopard thing. I first noticed this at work and I haven't upgraded there yet.
    • I'll tackle the bad fonts next.
    Anyway, I finally got it working as it should!
    Thing is, i'm not quite sure what I did as I was trying so many things.
    If this is happening to you, this is what I did:
    1. Search for AdobeFnt.lst files and zap them. (Make sure you don't delete similarly named db files.)
    2. Zap everything in the /Library/Cache/... All of it!
    3. This "undid" all of my "disabling" in Font Book. Had to do it all over again.
    4. Reboot.
    And make sure no Adobe apps get opened at all during this process. Not sure about this but I wanted to prevent them from attempting to cache fonts before I was through disabling.
    ...Whew!

  • BI Auth - user still can search & execute for not authorized query

    Hello All,
    need your help here.
    For BI security,
    I've configured menu role (for example ZBEX_FIN) in order for the end users to see only specific queries/workbook inside the menu folder that assigned to him/her.
    And I've made a function role for end user, copy from the template S_RS_RREPU with the modification:
    1. I delete 0BI_ALL
    2. add S_USER_AGR and put my menu role above (ZBEX_FIN) for field ACT_GROUP
    3. add S_RS_FOLD to disable the infoarea button in BEx.
    currently the user can see and execute report assigned in the role menu folder, this is correct.
    But the problem is there's a find button in the BEx, when the user try to search other query (non authorized query,the one that supposed he can't see), he still can display the query, then can execute the query. This is not acceptable.
    Anyone can suggest whether I can disable the find button in the BEx
    or any other restriction in the role that I missed, so the user can only execute and display the query/workbook under the role menu only.
    Thanks in advance.

    So it means that we need to do it twice restrictring the query in the role menu and then inside the S_RS_COMP ?
    so later when the user wants to add more queries in his role, we need to add those in the role menu as well inside the S_RS_COMP. is this correct ?
    When you add queries/workbook to role menu, you are not restricting the access. Its just that user menu would list those queries/workbooks. Users can search for other queries and workbook and run them with proper authorizations in S_RS_COMP. You may consider maintaining query naming convention with wild cards for example YRZ* etc to give access to all queries/workbooks starting with YRZ. This would save your effort to update role too freqeuntly.
    And if I have a workbook, how I put it inside the S_RS_COMP ? because the component of S_RS_COMP is query only.
    S_RS_COMP can restrict queries as well as workbooks with field RSZCOMPTP= REP

  • Disabling Minimal Download Strategy from PowerShell but still shows feature as "Activated".

    I have an interesting issue with the Minimal Download Strategy feature in SharePoint 2013. I have a script in place which will disable this feature on all sites in all site collections on our Farm. The script has been working fine and we schedule it to run
    daily at 8PM so that any new sites that get created will have this feature shut off, in case the person who created it forgot to disable it.
    As of recently, I've noticed while the script appears to be working fine, we are seeing that new sites are still showing the feature as activated in the "Manage Site Features" page. If I re-run the script, it shows that the feature is disabled
    and won't do anything. The script basically steps through all sites of all site collections in our default web application and if the MDS feature is enabled it disables it. Simple enough.
    So why am I now seeing sites that show the feature is Activated even though it is disabled? I've checked this by noting the URL that the site uses and it does not load pages from the "_layouts/15/" location. 
    The reason we have to turn this feature off on all sites is because we allow external users to access our SharePoint through a secure proxy. With this feature enabled, we have constant problems with pages not loading properly or generating javascript errors.
    Anyone have any insight into this?

    Here is the script we are using. As I mentioned, it works fine. It disables the the "Minimal Download Strategy", however when you go to the site settings it shows the feature is activated. 
    # This PowerShell script will check all sites of each site collection in
    # the default Web Application to see if the MDS (Minimal Download Strategy) 
    # feature is enabled and if so it will turn it off.
    # This script should be scheduled to run once a day to ensure this feature
    # is always disabled.
    # Register SharePoint Snap-In
    $ver = $host | select version
    if ($ver.Version.Major -gt 1)  {$Host.Runspace.ThreadOptions = "ReuseThread"}
    Add-PsSnapin Microsoft.SharePoint.PowerShell
    Set-location $home
    Write-Host "Script Running at "(Get-Date);
    $Default_WebApp = "http://vmsp2k13app.phs.org"
    # Get all Site Collections in the default Web Application
    $SPSites = Get-SPSite -WebApplication $Default_WebApp
    #Cycle through each Site Collection and its Webs (sub-sites)
    ForEach($Site in $SPSites){
    Write-Host "";
    Write-Host "Checking Site-Collection: " $Site.Url;
    ForEach($Web in $Site.AllWebs)
    Write-Host "";
    Write-HOst "    Checking Sub-Site: " $Web;
    If($Web.EnableMinimalDownload -eq 1)
    Write-Host "        Minimal Download Strategy is Enabled for this site!";
    Write-Host "        Disabling....";
    $Web.EnableMinimalDownload = 0;
    $Web.Update();
    Else
    Write-Host "";
    $Web.Dispose();
    $Site.Dispose();

  • Disabled Top Hits, but new ones still show up

    I have disabled "preload top hits" in safari, cleared history, have no bookmarks or favorites and yet random websites I visit once still show up a a a top hit when I type into the text box. Why is this happening and how can I get it to stop?

    Not other than parental oversight. On the computer you can implement Parental Controls on a separate user account that they would use. You can then block certain websites. But you cannot do that on the iPad.
    You could change your iTunes account such that they cannot access it in order to buy or download apps.

Maybe you are looking for