Home    Forums    Feature Requests    Beta Issues    SysAid Resources    Documentation    Support
Hello Guest,  Login   
        
DOWNLOAD FREE EDITION
    
     Recent Topics    Hottest Topics    Online Members    Member Listing    Advanced Search
Do you disable AD user accounts before complete deletion  XML
Forum Index » General IT Discussions
 
Poll
Do you disable AD user accounts before complete deletion
Yes, I disable the user for a while before deleting 83% [ 15 ]
No, I delete the user straight away 6% [ 1 ]
Sometimes, depending on the chance of re-hiring the employee 11% [ 2 ]
I don't have Active Directory... :-( 0% [ 0 ]
Total Votes : 18
Author Message
Joseph Zargari
VP Customer Relations


Meet me in Vegas - SysAid technology Conference - 28-30/4/2010
Joined: 26/03/2006
Messages: 516
Offline

Hello,

We are having a bit of a brainstorming about administrators' habits.
When an employee leaves (quits, gets fired, retires, etc), we want to know if you disable the user account for some period before completely deleting it or if you delete the user straight away.

This is something that we are very interested about to guide us in future development...
techguy
SysAid Mod


SysAider from release 4 United Kingdom Pathfinder Meet me in Vegas - SysAid technology Conference - 28-30/4/2010
Joined: 11/06/2008
Messages: 1506
Location: England
Offline

Yes I always disable for a while first as we often get incorrect leaving dates or the employee stays on a few extra days, or their manager suddenly needs to refer to something they worked on.

Need help? Try the SysAid wiki first! - http://sites.google.com/site/sysaidwiki
Lev
SysAid Mod


SysAider from release 5.5 Israel Pathfinder
Joined: 18/08/2008
Messages: 508
Location: Haifa, Israel
Offline

We keep the user disabled for a while (long while).
Users got mails, network folder with files ... .
Maybe to his mail come some important data and you want to redirect for a while ...

DONT !!! DONT TOUCH THE KEYBOARD !!!
CCSO IT
Super SysAider


SysAider from release 5.1 United States SysAid Certified
Joined: 05/09/2008
Messages: 54
Offline

We usually kill off the username right away so that we dont go in and wonder why the account was disabled, etc. Also the sensitive nature of law enforcement data and all, we would rather be 100% sure they are no longer in the system.

Thanks,
Thomas Hardin
Microcomputer Specialist
Clackamas County Sheriff's Office
Roadblockx
SysAider

SysAider from release 5.6 United States
Joined: 03/01/2009
Messages: 25
Offline

Great question.

As the Sr. Engineer for a gov agency (state prosecutors), security is the top priority. When our dept receives an account to be deleted, the first step is always to disable it first. To ensure that the account isn't left in that state, we add in the account's comment/description field "To be deleted > POC xxxx" where POC is the point of contact and xxx is the name of the person handling the deletion. The ticket is assigned to someone on the security team which becomes the POC. After two weeks (10 business days), the requestor of the account is notified that the account will be deleted (last chance). At that point, if no response is received to stop the deletion, the user's account is backed up and deleted.

A lot of steps but it was implemented after a couple of "opps" and I didn't want to see my name as the admin that lead to a data breach!
Roadblockx
SysAider

SysAider from release 5.6 United States
Joined: 03/01/2009
Messages: 25
Offline

I failed to mention one other step. When the account is disabled, the tech adds a date to the dept's calendar for the user account to be deleted. That way if the tech is not there that day, the manager or I will be notified and we can kill the account ourselves. We had to add this step after doing an audit and finding 30+ accounts with "to be deleted > POC xxx" and the tech assigned was no longer there!

This message was edited 1 time. Last update was at 18/01/2009 16:16:18

rascal
SysAider

SysAider from release 3.1 Italy
Joined: 17/06/2008
Messages: 11
Location: Brixen, Italy
Offline

Yes, we disable the user account.
We have a checklist with various tasks (Export Mail to an *.pst file, disable account, change password, etc.)
After 60 Days the user account will be deleted.
Tim Sutton
Super SysAider

SysAider from release 2.5 United Kingdom
Joined: 15/07/2008
Messages: 64
Offline

our "leaving user" policy runs something like this on the IT side:

1. User account is removed from any sec groups, password changed and a e-mail out of office set up with who to contact instead. User account is moved into a "retired users" OU which has a really restrictive GPO applied.
2. User's machine is imaged off, image is archived onto DVD / archive server, machine is then reimaged with the company standard and apps deployed ready for reissue to someone.
3. after 2 weeks the account is completely disabled and their e-mail account is exmerged and then stored on DVD / archive server
4. a further 2 weeks down the line and the account is deleted.

that's the plan at least lol
Forum Index » General IT Discussions
Go to:   
Help Desk Software
Free Help Desk Software
Free Asset Management Software
SysAid Helpdesk Software
Web Based Help Desk Software
SysAid Help Desk Forum
General IT Discussion Forum
SysAid CSS Customer Service Software
Customer Support Software
   SysAid Technologies Ltd.
   Toll-Free phone center (U.S.): 1-800-686-7047
   Offices - U.S.617-231-0124
   Israel:+972-3-533-3675
   Email:helpdesk@sysaid.com
   Optimized by SEO Israel
   SysAid logos and other SysAid Technologies marks
   are trademarks or registered trademarks of
   SysAid Technologies Ltd.
   All Rights Reserved by SysAid Technologies Ltd.
   2002-2011
   Live Support Hours
   07:00 AM - 09:30 PM (UK)
   03:00 AM - 05:30 PM (EDT)

   We provide worldwide services, and we do our best
   to match the working times of customers from
   different time zones.

   SysAid Help Desk Software and Asset Management Software
Privacy Policy © Terms Of Use