TIP: How to LDAP deny disabled AD accounts

Ironport LDAP queries will successfully lookup SMTP addresses of disabled AD accounts. For companies that disable accounts instead of deleting them, this can cause alot of junk mail to accumulate in the account's associated mailbox.
We currently move all disabled AD accounts to a DisabledAccounts OU.
By denying the AD user account used for lookups all rights to that specific OU and it's child objects, the Ironport now fails on lookups to that OU.
-Matt

Well... if I read the quoted MS article the value for a disabled user is 514
You can view and edit these attributes by using either the Ldp.exe tool or the Adsiedit.msc snap-in.
The following table lists possible flags that you can assign. You cannot set some of the values on a user or computer object because these values can be set or reset only by the directory service. Note that Ldp.exe shows the values in hexadecimal. Adsiedit.msc displays the values in decimal. The flags are cumulative. To disable a user's account, set the UserAccountControl attribute to 0x0202 (0x002 + 0x0200). In decimal, this is 514 (2 + 512).
This means that you must ask your LDAP filter to accept any value other than 514. (Or "must not be 514")
It might contain an error, I did not test it, but I think the LDAP filter
(& (|(mail={a}) (proxyAddresses=smtp:{a}) ) (!(userAccountControl=514)))
Would do the job... (At least my LDAP filter editor does not complain about syntax errors)
Steven

Similar Messages

  • Hey guys how to delete my disabled iCloud account on my iPad Air without password

    help me guys to delete my disabled iCloud account without password? Thanks.

    You will have to try to recover the password or contact Apple for help.
    https://iforgot.apple.com/
    IF you still cannot recover it, contact Apple according to the instructions here.
    Apple ID: Contacting Apple for help with Apple ID account security - Apple Support

  • How to enable a disabled admin account?

    I was testing the pwpolicy on a newly upgraded Yosemite. After rebooting, I found my local admin account was disabled.
    I ran the pwpolicy on a non-server version of Yosemite and the only support article I could find is OS X Server (Yosemite): Global policies can lock out Admin accounts - Apple Support. I tried to follow the steps in the article to clear the account policies for local admin, but once I entered "/usr/bin/pwpolicy -n /Local/Default clearaccountpolicies", the system seemed hanging there and the local admin account was still disabled. Any ideas?
    Actually once I used launchctl to load the com.apple.opendirectoryd.plist, the system started to show signs not working properly, such as some basic commands like ps, dscl, man, nano, or even ls stopping to bring up any results. However, "launchctl list" showed the daemon was launched with a number of 78.
    I tried to create new admin user account by rm /var/db/.AppleSetupDone, but the new admin account was disabled possibly immediately after birth because of the global policy settings.
    Any suggestions?

    Thanks, Linc!
    But now the issues become:
    1. How to load the launchDaemons or launchAgent in the single user mode?
    I got the status code 78 when loading the opendirectoryd.plist. While in the system log, there was an opendirectoryd error: "Bug in libdispatch: 14B25 -2004 - 0x5". This is not related to pwpolicy at all, because all my Yosemite 10.10.1 machines show the same things with or without setting the pwpolicy. Any ideas?
    2. The SUM used to be very handy and powerful in the past for troubleshooting startup issues, but now, even "passwd" generates an error saying: "The daemon encountered an error processing request." It makes me feel like running a car with the idle gear on, but I just don't know where Apple has moved the drive gear. Is there a document somewhere for using the single use mode of Yosemite?  

  • [Forum FAQ] How to disable Microsoft account default sign-in behavior when accessing Microsoft website on Windows 8.1

    Scenario
    By default it will sign in with current Microsoft account, if a user accesses Microsoft website (www.live.com, www.bing.com, etc.) with Microsoft account on Windows 8.1. This article describes how to disable this default sigh-in behavior if you want to use
    different Microsoft accounts every time. 
    Method
    To disable this default sign-in behavior, we can deny current Microsoft Account read permission of MicrosoftAccountTokenProvider.dll, please follow the following steps:
    Run Command Prompt with elevated permissions.
    Run the following command to take ownership of MicrosoftAccountTokenProvider.dll:
      takeown /f C:\Windows\SysWOW64\MicrosoftAccountTokenProvider.dll
    Run the following command to deny the read permission of the Microsoft:                                
     icacls C:\Windows\SysWOW64\MicrosoftAccountTokenProvider.dll /deny
    [email protected]:r                                                                                                                
    Note: Please replace your current Microsoft Account with the example
    [email protected]
    Change the owner of this file back to TrustedInstaller:
    Right-click MicrosoftAccountTokenProvider.dll under
    C:\Windows\SysWOW64\, choose Properties. Under
    Security tab, click Advanced.
    Click Change, in the box Enter the object name to select, type
    NT Service\TrustedInstaller.
    Click OK.
    Note: This operation would take some hours to work.
    Apply to:
    Windows 8.1
    Please click to vote if the post helps you. This can be beneficial to other community members reading the thread.

    Error: System cannot find the specified path
    I am getting this eroor
    Parashuram Singade www.distinctnotion.com

  • How to delete disabled icloud account without knowing the password/email

    Hi
    i just got a pre-used iphone 5S. It has a disabled icloud account. i tried to delete it but it asks me about the password.
    i cant reset the account cause i don't know the email for verification.
    also i can't restore using itunes because it asks to turn off find my iphone feature. and i can't turn it off because the account is disabled
    how can I restore the iphone in this case?

    You can't. There isn't a way to bypass Activation Lock: http://support.apple.com/kb/PH13695 Your only option is to return the phone if possible. If not, you have a useless device.

  • How do I unlock my iTunes account that has been disabled?

    How do I unlock my iTunes account that has been disabled?

    If changing your password does not solve, then contact itunes support

  • How can I have my iTunes account back after apple has disabled it?

    My Itunes Account has been disabled for not paying . after that I payed and they took the moeny owed.
    but still my account disable.
    How can I have my iTunes account back after apple has disabled it?

    contact iTunes support team

  • My password keeps getting hacked, how can i disable my account and start a new one and not lose all the stuff I already have?

    Hi All,
    I need help, my password keeps getting hacked, and I keep changing the password, and changing all my security questions. I have changed everything I can. How can I disable my account, but not lose everything that I already have in there? Is this possible or do I have to start all over again?

    You might have some better luck if you call your country number from http://support.apple.com/kb/HE57 and ask to speak with the Account Security Team.

  • HT5699 i am from Lebanon and they did disable my account because of authorization they did my cousin without my knowledge, and i did change the password of my account and the webcard used please can u help me to know how to get my account back

    i am from Lebanon and they did disable my account because of authorization they did my cousin without my knowledge, and i did change the password of my account and the webcard used please can u help me to know how to get my account back

    http://www.apple.com/support/itunes/

  • My iTunes account has been disabled.  How can I start another iTunes account using same email address

    My iTunes account has been disabled.  How can I start another iTunes account using same email address?

    Why would you start another account?
    This will only cause problems

  • How do you disable mobile account settings/parental controls

    My school had a one-to-one macbook program, but I switched schools. Now i have a heavily restricted computer. They had my account set to mobile and had parental controls enabled, so I used single user mode to create a new admin (remove /var/db/.applesetupdone and reboot) and remove them. However, even though no account has parental controls turned on, they are still enabled somewhere for all accounts, even admins. I have two questions: how do i disable mobile account settings, and where are the parental controls files located? I found some in /library/managed preferences/<account name here> , but editing these gives only temporary relief from parental controls, and they are reset when i restart. There has to be somewhere else that parental controls are flagged as on/set to sync on login. i removed the actual parental controls executables and stuff somewhere in /system but after that i couldnt open activity monitor and i didnt want to risk a reboot. please help me as this is very annoying. btw im on OS X 10.6.7

    HI,
    Try this..
    Open System Preferences/MobileMe and select the Sync tab.
    Deselect the box where you see: Synchronize with MobileMe. The last sync will noted at the bottom left side of the window.
    Carolyn

  • HT201320 How to disable an account from an I-Pad? (Without the I-Pad...)

         How can you disable an account from an I-Pad without it? I have an email linked to an I-Pad that I cannot get a hold of anymore because it was my school's for a required project. I've been sending and recieving anonymous mail from it occasionally. I just changed the password and allowed a vertification for my email login, but I don't want to delete it, it's my primary email. Is there anyway I can disable the account without it? PLEASE HELP!

    Hold down on the app icon until it wiggles. Then tap the X on the icon to delete it. Tap the home button when you are done.

  • How do I disable an account?  I want to start anew- mine was compromised

    How do I disable an account?  I want to start anew- mine was compromised

    contact itunes, expresslane.apple.com

  • How to disable user account

    Hi,
    How to disable user account after few failed login attempt.
    We have the password policy settings.  But we also like to disable account after 5 failed login attempt.
    thanks

    This function is not available in Connect.

  • How can I disable my account?, How can I disable my account?

    I need to disable my account in apple

    Go to "Manage Your Apple ID" here:
    https://appleid.apple.com

Maybe you are looking for