cancel
Showing results for 
Search instead for 
Did you mean: 
Highlighted

ePO 5.3 AD disabled objects

Jump to solution

Hi, 

we are having problems with disabled AD objects (computer accounts) not being removed from ePo. According to KB79470 disabled AD accounts should be removed automatically.

Nay ideas or settings that should be set for this to work?

Thank you in advance

 

Tags (2)
1 Solution

Accepted Solutions
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 7

Re: ePO 5.3 AD disabled objects

Jump to solution

That setting should remove both deleted and disabled accounts.  The sync should do a comparison with what is in epo vs AD and if previous AD systems exist in epo but not AD (disabled systems are not seen by the AD sync), then it should be removing them.  If it is not, I would suggest opening a ticket with McAfee.  You can also run the inactive agent maintenance server task.  That will remove systems that have not communicated in the defined inactive period under server settings, detected system compliance, inactive setting.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

View solution in original post

6 Replies
Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 2 of 7

Re: ePO 5.3 AD disabled objects

Jump to solution

In your AD sync point settings, there is an option to delete systems that are no longer in AD (or disabled).  Ensure that is checked, but don't check the box to remove agent as they will never get that command.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Highlighted

Re: ePO 5.3 AD disabled objects

Jump to solution

Thank you for the fast answer. Unfortunately that setting is enabled in our case but it says only "When systems are deleted from the synchronization point:", not disabled.

Is there a way to remove disabled accounts automatically or this setting should remove both deleted and disabled items in AD?

 

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 4 of 7

Re: ePO 5.3 AD disabled objects

Jump to solution

That setting should remove both deleted and disabled accounts.  The sync should do a comparison with what is in epo vs AD and if previous AD systems exist in epo but not AD (disabled systems are not seen by the AD sync), then it should be removing them.  If it is not, I would suggest opening a ticket with McAfee.  You can also run the inactive agent maintenance server task.  That will remove systems that have not communicated in the defined inactive period under server settings, detected system compliance, inactive setting.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

View solution in original post

Highlighted

Re: ePO 5.3 AD disabled objects

Jump to solution

Just out of curioisity, when you say "That will remove systems that have not communicated in the defined inactive period under server settings, detected system compliance, inactive setting."...where is that setting?  I just went through every setting in the ePO Server Settings and cannot find detected system compliance or inactive setting.  Just wondering if I'm missing something.  Thank you.

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 6 of 7

Re: ePO 5.3 AD disabled objects

Jump to solution

Do you have a section called detected system compliance?  If so, it is in the first section for detected system definition - inactive by default is 45 days.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

Highlighted
McAfee Employee
McAfee Employee
Report Inappropriate Content
Message 7 of 7

Re: ePO 5.3 AD disabled objects

Jump to solution

If it is not there, the default is still 45 days.  There is a server task you can set up to run called inactive agent cleanup task.

Was my reply helpful?
If this information was helpful in any way or answered your question, will you please select Accept as Solution in my reply and together we can help other members?

You Deserve an Award
Don't forget, when your helpful posts earn a kudos or get accepted as a solution you can unlock perks and badges. Those aren't the only badges, either. How many can you collect? Click here to learn more.

Community Help Hub

    New to the forums or need help finding your way around the forums? There's a whole hub of community resources to help you.

  • Find Forum FAQs
  • Learn How to Earn Badges
  • Ask for Help
Go to Community Help

Join the Community

    Thousands of customers use the McAfee Community for peer-to-peer and expert product support. Enjoy these benefits with a free membership:

  • Get helpful solutions from McAfee experts.
  • Stay connected to product conversations that matter to you.
  • Participate in product groups led by McAfee employees.
Join the Community
Join the Community