Is is possible to collect from AD the users status, such as Active=Y (we have an attribute that matches this), or Active/Inactive, etc?
We don't have a well defined off-boarding protocol at the moment (or any off boarding protocol for that matter). Users are deactivated from LDAP when they leave, but we usually don't find out about it until we find a device that has stopped reporting for extended period of time. If I could pull user status from an AD attribute, I could potentially generate a report that might be helpful.
Solved
How to collect LDAP (AD) user status?
Best answer by bentoms
@pbenware1 if this is an attribute is in AD you should be able to add it to the LDAP mappings.
To double check the attributes name: http://macmule.com/2014/05/03/how-to-use-directory-utility-to-view-an-ad-objects-attributes/
For how to get the JSS to do the LDAP lookup: http://macmule.com/2014/05/04/submit-user-information-from-ad-into-the-jss-at-login-v2/
Enter your E-mail address. We'll send you an e-mail with instructions to reset your password.
