Hi,
we are having problems with disabled AD objects (computer accounts) not being removed from ePo. According to KB79470 disabled AD accounts should be removed automatically.
Nay ideas or settings that should be set for this to work?
Thank you in advance
Solved! Go to Solution.
That setting should remove both deleted and disabled accounts. The sync should do a comparison with what is in epo vs AD and if previous AD systems exist in epo but not AD (disabled systems are not seen by the AD sync), then it should be removing them. If it is not, I would suggest opening a ticket with McAfee. You can also run the inactive agent maintenance server task. That will remove systems that have not communicated in the defined inactive period under server settings, detected system compliance, inactive setting.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
In your AD sync point settings, there is an option to delete systems that are no longer in AD (or disabled). Ensure that is checked, but don't check the box to remove agent as they will never get that command.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Thank you for the fast answer. Unfortunately that setting is enabled in our case but it says only "When systems are deleted from the synchronization point:", not disabled.
Is there a way to remove disabled accounts automatically or this setting should remove both deleted and disabled items in AD?
That setting should remove both deleted and disabled accounts. The sync should do a comparison with what is in epo vs AD and if previous AD systems exist in epo but not AD (disabled systems are not seen by the AD sync), then it should be removing them. If it is not, I would suggest opening a ticket with McAfee. You can also run the inactive agent maintenance server task. That will remove systems that have not communicated in the defined inactive period under server settings, detected system compliance, inactive setting.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Just out of curioisity, when you say "That will remove systems that have not communicated in the defined inactive period under server settings, detected system compliance, inactive setting."...where is that setting? I just went through every setting in the ePO Server Settings and cannot find detected system compliance or inactive setting. Just wondering if I'm missing something. Thank you.
Do you have a section called detected system compliance? If so, it is in the first section for detected system definition - inactive by default is 45 days.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
If it is not there, the default is still 45 days. There is a server task you can set up to run called inactive agent cleanup task.
Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?
Corporate Headquarters
6220 America Center Drive
San Jose, CA 95002 USA