What will happen if I delete a user on AD?

Krbonus
Contributor

Noob question

Hello, we have LDAP integration in our Jamf instance. If I delete a user in AD assuming that there's paid apps/configurations scoped out to this user. Will this un-scope everything assigned to the said user?

Thanks

1 ACCEPTED SOLUTION

diradmin
Contributor II

@Krbonus When assets in Jamf Pro are assigned to LDAP users, a corresponding user_object is created in the database. This object is completely separate and independent of the originating LDAP object. If you delete the user in LDAP, Jamf Pro does nothing to sync these objects. Therefore, the user_object must be deleted from Jamf Pro as well (after un-assigning assets).

View solution in original post

5 REPLIES 5

awginger
Contributor

It should unstop it yes, as Jamf will no longer know of that user so it would therefore not be able to consider it within scope.

diradmin
Contributor II

@Krbonus Deleting the user in AD directly will not remove the user_object in Jamf Pro.

Krbonus
Contributor

@awginger @diradmin I'm confused. Both of you made sense. honestly..

diradmin
Contributor II

@Krbonus When assets in Jamf Pro are assigned to LDAP users, a corresponding user_object is created in the database. This object is completely separate and independent of the originating LDAP object. If you delete the user in LDAP, Jamf Pro does nothing to sync these objects. Therefore, the user_object must be deleted from Jamf Pro as well (after un-assigning assets).

Krbonus
Contributor

Thank you kind sir! @diradmin