Why are disabled accounts synchronized to AAD

I used the Azure AD Connector to set up WAAD Synchronization.
I used the defaults.  Everything seemed to work fine.
After synchronization I see that all of my AD disabled accounts exist in WAAD.
Based on the default rules setup particularly the "In from AD - User AccountEnabled" rule I wouldn't have expected this.  Can someone explain to me why this is?  And how to remove disabled user accounts from WAAD synchronization.
Thanks! 

"In from AD - User AccountEnabled" is a rule that only applies to accounts with the ACCOUNTDISABLE flag set to off, it does nothing to decide whether to sync the object. If you want to exclude disabled user accounts, you need to create a new
rule (or edit some existing one) following the instructions here:
http://msdn.microsoft.com/en-us/library/azure/dn801051.aspx#BKMK_ConfigureAttributeBasedFiltering
For example, this should filter out all the Disabled accounts:
Log on to the computer that is running AADSync by using an account that is a member of the ADSyncAdmins security group.
Open Synchronization Rules Editor by finding it in the Start Menu.
Make sure Inbound is selected and click Add New Rule.
Give the rule a descriptive name, such as "Filter
out disabled accounts", select the correct forest under Connected system, User as the Connected system object type, and Person as the Metaverse object type. In Link Type select Join and
in precedence type a value currently not used by another Synchronization Rule, e.g. 50. Click Next.
In Scoping filter click Add Group, click Add Clause and in attribute select
userAccountControl. Make sure the Operator is set to ISBITSET
and type in the value 2 in the Value box. Click Next.
Leave the Join rules empty and click Next.
Click Add Transformation, select the FlowType to Constant, select the Target Attribute cloudFiltered and in the Source text box, type in True. Click Add to save the rule.
Perform a full sync: on the Connectors tab, right-click SourceAD, click Run, click Full Synchronization, and then click OK.
Here's how the rule looks in PowerShell:
PS C:\> Get-ADSyncRule -Identifier '860a523a-bcb0-4aef-b58e-7d17cb6fbd35'
Identifier : 860a523a-bcb0-4aef-b58e-7d17cb6fbd35
Name : Filter out disabled accounts
Version : 1
Description :
ImmutableTag :
Connector : df4655c7-dcf6-4010-8b39-68306199b0e8
Direction : Inbound
SourceObjectType : user
TargetObjectType : person
Precedence : 50
PrecedenceAfter : 00000000-0000-0000-0000-000000000000
PrecedenceBefore : 00000000-0000-0000-0000-000000000000
LinkType : Join
JoinFilter : {}
ScopeFilter : {Microsoft.IdentityManagement.PowerShell.ObjectModel.ScopeConditionGroup}
AttributeFlowMappings : {Destination:cloudFiltered FlowType:Constant Expression: ValueMergeType: Update}
SoftDeleteExpiryInterval : 00:00:00
SourceNamespaceId : df4655c7-dcf6-4010-8b39-68306199b0e8
TargetNamespaceId : cc31d470-9786-447f-8594-40abe13f9f78
PS C:\> (Get-ADSyncRule -Identifier '860a523a-bcb0-4aef-b58e-7d17cb6fbd35').scopefilter.ScopeConditionList
Attribute ComparisonValue ComparisonOperator
userAccountControl 2 ISBITSET
PS C:\> (Get-ADSyncRule -Identifier '860a523a-bcb0-4aef-b58e-7d17cb6fbd35').AttributeFlowMappings
Source : {True}
Destination : cloudFiltered
FlowType : Constant
ExecuteOnce : False
Expression :
ValueMergeType : Update
MappingSourceAsString : True

Similar Messages

  • HT4898 why are mail accounts no longer available with migration to  icloud

    I can't get my macbook to update past OS X 10.5.8 and don't understand why so I have only updated my mail to update to icloud however when I read the detail it says mail accounts won't update to icloud.  I guess there are two questions here I don't understand what to do about either issue the inability to update to a high enough version to go to icloud and why the mail account won't update

    If you have chosen the 'email only' option nothing will happen until the end of June. At that point your email will be migrated to the iCloud server and will of course not be accessible at the MobileMe server settings.
    As Apple say, you can then access it at http://icloud.com - what they don't say is that you can manually set the Mail application up to access it -
    Entering iCloud email settings manually in Snow Leopard or Leopard

  • Why are many accounts conected to my email address

    My skype name changes...
    Why are the so many user name connected to my one email address? Why can't I find a way to direcly talk with skype?

    report those unknown accounts to [email protected], and request them to unlink them from your email address.  
    IF YOU FOUND OUR POST USEFUL THEN PLEASE GIVE "KUDOS". IF IT HELPED TO FIX YOUR ISSUE PLEASE MARK IT AS A "SOLUTION" TO HELP OTHERS. THANKS!
    ALTERNATIVE SKYPE DOWNLOAD LINKS | HOW TO RECORD SKYPE VIDEO CALLS | HOW TO HANDLE SUSPICIOS CALLS AND MESSAGES

  • Why are my system services disabled for Admin accounts?

    Hi all,
    I noticed that pretty much all services are disabled in my main (administrator) account. ("make new stickie note" from selection, Grab, import image, look up in dictionary, mail, font etc... Everything is a no go.
    I set up a regular account as a test and they all seem to work. I just bought my mac recently and installed 160 gigs worth of documents/profedssional apps and I'm dreading having to go through all that again just so I can have a fully functional os!
    Is there an easy way to copy all my settings from my admin account to another account? Or even better, is there a way to turn on all the fun services in the admin account?
    Thanks for any info!
    J. Wallace
    iMac Mac OS X (10.4.8) new Mac user

    Welcome to Apple Support Communities
    Try deleting the Desktop settings file. Open a Finder window, select the Go menu (on the menu bar) > Go to Folder, and type:
    ~/Library/Preferences
    Then, delete "com.apple.desktop.plist" and "com.apple.systempreferences.plist", and restart. Finally, open System Preferences > Desktop & Screen Saver, and change the desktop wallpaper

  • I have 2 phones on my iTunes account, why are text messages showing on the second phone when sent from the first

    I have 2 phones on my iTunes account, why are text messages showing on the second phone when sent from the first phone?

    it's meant to work like that
    so if you receive a message on your iphone you also get it on your ipad or ipod touch
    to avoid it use separate appleID for each device
    or turn off imessage on 1 or both devices in their settings
    but that will not fix the issue that 2 devices using the same appleID will never be able to facetime eachother
    the appleID is a unique handle for 1 user only

  • Why are there so many more choices on the USA iTunes Store? Surely having an iTunes account should let you access all itunes availability the world over? Also how do you request films/tv series to the UK itunes?

    Why are there so many more choices on the USA iTunes Store? Surely having an iTunes account should let you access all itunes availability the world over?
    Also how do you request films/tv series to the UK itunes? There's tv series I'd like but they're incomplete like The Batman & Xena Warrior Princess. And films theta aren't available for download but you can purchase in a store like HMV?  Apple isn't doing itself any favours by secluding countries by their store. They'd make billions if you could just select the iTunes Store you want to search & purchase from just by signing in! If anything what they're doing is putting themselves into a corner, other companies like Samsung & HTC are already on too of them for innovation & ease of use. The people they're attracting are predominantly existing Apple users not new customers. What do you guys think?

    It's not Apple's choice, they can only sell a particular item where the content provider/rights-holder has granted them a license to sell them. Content is licensed by the rights-holders to Apple on a country-by-country basis, each country therefore has to have its own store, and you have to be in a country to use its store - they want control over where their content is available.
    You can try requesting that an item be added to the UK store via this page, but unless the rights-holder agrees to then Apple won't be able to sell it here : http://www.apple.com/feedback/itunes.html

  • How can I disable the automatic hiding of known file attachments, and why are always about 10 internet pages where I have to download something if i use firefo

    How can I disable the automatic hiding of known file attachments, and why are always about 10 internet pages where I have to download something when I use mozila firefox?
    Windows Computer

    1) If you are talking about the file names on the computer, there is a
    setting to turn off known file types. Open your file browser. Then
    just under the location bar, press '''Tools,''' then '''Folder Options.'''
    A new window will open. Select '''View.''' Look for
    '''Hide Extensions For Known File Types.'''
    2) Never NEVER '''NEVER''' download anything unless you know what
    it is. If a web site claims it needs to download something, what is it?
    It could be something like the flash player, '''or a virus ! !'''
    Ask questions, or go somewhere else.

  • Why are iTunes, View, Window, and Help menu items disabled?

    I am frequently encountering an issue in iTunes 10.5 (141) where all the menu items in the iTunes, View, Window, and Help menus are disabled (greyed out). Why is this happening and can it be stopped?
    I've seen this issue on different Mac OS X 10.7.2 machines. It seems to occur during playlist manipulation, where I'm making new playlists, adding items to them and editing them and the items. In the worst cases, I'm forced to quit and restart iTunes, although I have to quit by using the context menu option in the Dock as the Quit option is disabled in the application.
    I'd appreciate any advice on workarounds for this that don't involve quitting and restarting iTunes.

    I'm also having the same issue.  It was happening with 10.5.1 and now still with 10.5.2.  I'm using a 2008 iMac running 10.6.8.  I do not use iTunes Match.  This seems to happen for no apparent reason i/o/w, I can't determine a pattern as to when it happens, but it occurs about once in every 10 times that iTunes is open and it seems to happen after it's been open for a while, but again, no particular pattern. 
    Sometimes, all the menu items are grayed out, and other times, 70% of the menu items are grayed out.  I can still use the other functionality in iTunes, but must must Quit from the dock (it quits gracefully and no Force Quit is necessary).  Relaunching restores eveything to normal for about a week. 
    I work with technical diagnostic issues and can usually pinpoint a problem, isolate an issue, or determine a pattern, but this one has me stumped. I thought 10.5.2 might fix it, but no.  Maybe 10.5.3?

  • Why are my five websites not showing up in my CC browser window - CC Account Panel?

    Why are my five websites not showing up in my CC browser window - CC Account Panel?
    I have a full account!
    g

    Gmpulaski which web sites are you referring too?  Is it the five Business Catalyst sites included with your membership?

  • Why are my bookmarks not being saved locally if the save to cloud feature is disabled?

    Why are my bookmarks not being saved locally on my ipad mini if the save to cloud feature is disabled?

    They should be. If you have lost bookmarks try restarting Safari:
    1. Press the Home button
    2. Double click the Home button to bring up the "Recent Apps" tray.
    3. Touch and hold on the Safari icon in the "Recent Apps" tray until a "-" appears.
    4. Touch the "-" to terminate Safari.
    5. Restart Safari and see if your Bookmarks are back.

  • Why are there itunes store charges on my credit card statement but there are no purchases under my itunes account?

    Why are there itunes store charges on my credit card when there are no purchases under my itunes account?

    Have you added or changed your card details on your account and they are temporary store holding charges ?
    Unknown charges : How iTunes Store charges might look on credit and debit card statements

  • I have two facebook accounts availible when I click the facebook icon in aperture it tries to log into the disabled account. It doesn't give me any option to continue making an album for the enabled account. Why?

    I have two facebook accounts availible when I click the facebook icon in aperture it tries to log into the disabled account. It doesn't give me any option to continue making an album for the enabled account. Why?

    I suppose I could delete it, but the whole point of multiple accounts is so I can post to either. One is mine, one is my wife's. If it is not enabled why would I need to log into it to post to my own account. The system has no problem associating existing albums with my account, I is only failing to allow me to choose only my account to create an new one. It is clearly designed to handle multiple accounts, but seems to have a bug directing it to ask for the password for a disabled account instead of allowing selection of and posting to the enabled one.

  • Why are my player buttons disabled on my Captivate 8 skin when I add a quiz. If I remove the quiz, my buttons return on the skin.

    It would really save me time to use the quiz feature of Captivate 8, but so far I'm not able to because every time I add a quiz, the player buttons are completely gone from my skin. I cannot add them again because they are disabled!!
    In preferences I turned off the option to hide player buttons.
    Does anyone know why this happens?? Can I use a quiz and still have my back/forward buttons visible??

    By preferences I am assuming you mean skin editor under the project tab? 
    - Yes
    Do you have Show Playback Control checked (otherwise the box you refer to is lowlighted anyway), and I am assuming that you have Hide Playbar in Quiz checked?
    - No, I do not have Hide Playbar in Quiz checked, but whether it is checked or not doesn't matter
    Is you quiz in the middle of the project or at the end?
    - My quizzes are throughout after each course section as a self assessment
    I am speculating that perhaps you have turn playbar off in quiz which turns it off in captivate, I would assume it would automatically turn back on when quiz is over but maybe not, just betting a hunch as I need more info to do more.
    - It's not just in the quiz area that they playbar is disabled. Once I add ANY quiz, the playbar is not shown at all throughout the entire course and I cannot turn any playbar items that I need on (previous/next).
    So if playing with those settings dont help then try this on slide 1, go to properties for the slide then actions----> On Enter: Show Playbar. (It will be set to No Action by default)
    - I will try this thanks

  • How to turn off "find my iphone" when all the buttons are disable about on/off in my icloud account?

    MY APPLE ID AND ICLOUD ACCOUNT HAVE BEEN HACKED COUPLE OF MONTHS AGO. ALL THE CONTENTS OF MY IPHONE HAS REMOVED. SO I HAVE RESTORED MY IPHONE BY USING MY OLD BACKUP. AND MY OLD ICLOUD ACCOUNT HAS RESTORED TO MY IPHONE AGAIN BUT THERE WAS NO ICLOUD ACCOUNT WITH MY EMAIL BECAUSE IT'S BEEN HACKED AND MY APPLE ID HAS BEEN SWITCHED TO HACKER'S EMAIL. SO I WAS NOT ABLE TO DELETE ICLOUD ACCOUNT, TO TURN OFF FIND MY IPHONE OR TO ERASE MY IPHONE. SO I M NOT STILL ABLE. I MEAN ALL THE BUTTONS IN MY ICLOUD ACCOUNT ARE DISABLE TO TAP. I WANNA ERASE MY IPHONE OR ERASE THE ICLOUD ACCOUNT.
    PLEASE HELP ME!!!!
    WAITING FOR YOUR RECOMMENDATIONS...

    According to Apple support, you cannot remove the phone on the device list under "find my iphone" until you turn it off and it goes offline.  (It also says the device will go back on "find my iphone" when it goes online again, which seems to mean you can successfully remove it, but as soon as you turn it back on it will be back on the list, and thus you will not be able to restore it.)  It's a bit of a conundrum.  In my case I couldn't for some reason turn off my phone  with the home/sleep buttons - nothing happens, the phone stays on.  While on a chat with Apple support, they got my iphone offline (I was able to turn it off by pressing the sleep button and swiping where the red "turn off iphone" arrow would have appeared) and removed it from "find my phone", but when I reconnected to itunes it turned on and reappeared in the "find my phone" list.  Luckily, the screen suddenly appeared (it had done this several times yesterday, just briefly), so I was able to turn off "find my device" from the phone.  I was then able to restore.  Unfortunately, this does not answer the question of how to remove the device from "find my iphone" and keep it off while connecting with itunes to restore (unless you have my good fortune of having the screen suddently reappear).  Apple support seemed puzzled that it had reappeared on the device list under "find my iphone".  Time will tell whether the restoration fixes the blank screen issue.

  • Rules are disabled after disabling/enabling account.

    Hi,
    I have an applescript that enables or disables my work account depending on whether or not I have a VPN connection. My problem occurs when:
    1. The work account is disabled
    2. Mail is restarted
    3. The work account is enabled again
    At this point all of my rules associated with the work account are disabled. I can't imagine that this is the intended behavior.
    I can re-enable all of the rules with Applescript, but it seems like I shouldn't have to.
    The problem can be reproduced without using Applescript by disabling/enabling the account in Mail preferences.

    A little more info on the subject of rules, monitors, and alerting:
    Alerts based off of Rules will not close themselves, they will always need to be closed manually. If they were alerts based off of Monitors they would (in most cases) close themselves after disabling them. If you don't want to script closing the alerts based
    off the rules you can always filter or sort your alerts in the console and select all or selectively select the ones you want to close all at once and then right click and close the alerts based off rules. One other thing, for alerts based off monitors
    it is usually best to reset the health of an object and let the monitor close itself rather than close an alert based of a monitor if you have a need to close it. That is unless something funky happened where the health of the object changed to healthy
    and for some reason the alert didn't close in which case you can close it. The reason you dont want to just close an alert based off a monitor is because it wont reset the health of the object being monitored and will therefore not re-alert if the issue returns.

Maybe you are looking for

  • MS 6156 Memory Upgrade

    I have been trying to complete the most simplist of task's or so I am told, which is to update my Intel 440 BX MS 6156 VER 1 BX7 64MB memory to 256MB by using two 128MB memory cards. Twice I have been given the wrong cards, the last two were labeled

  • Multi plot graph - auxiliary curves

    I am in trouble with a multi plot graph. There is a wave chart that I have to plot an auxiliary line when the user clicks on the graphic. I know how to get the initial point and the final point of the auxiliar line. But I don´t know how can I plot th

  • Missing font in one file, but not another?

    In one document, I changed a section of type to Helvetica, then it turned pink. It says Helvetica is missing. I opened another document and used Helvetica with no problem. I closed InDesign, checked my fonts and used Helvetica in other programs. Reop

  • Query abt XCELSIUS ENGAGE SERVER

    Hi Gurus, I want to make dashBoard reports using our SAP BI 7.0 as source system. What is the BO product I have to download? Is it XCELSIUS ENGAGE SERVER?? What is the prerequisites? Kind Regards Biswarup

  • Need new I/O Front panel Cable

    Hey all, I was sleeving my I/O Front Panel cable and when managed to mess it up. So bassically what I need is a new cable. Do you guys no any way I can go about getting me a new one? I believe the cable is called AD_Link cable.