search cancel

How to keep SpanVA AD Sync from syncing inactive users

book

Article ID: 254174

calendar_today

Updated On:

Products

CASB Security Advanced

Issue/Introduction

There are users in Active Directory that should not be synced to CloudSOC.

Environment

Release : 1.0

Resolution

In the sync filter, include !(userAccountControl:1.2.840.113556.1.4.803:=514). This is the default attribute that identifies inactive AD Users. The exclamation mark filters out inactive users

So the filter would look something like this:

(&(objectclass=user)(objectCategory=user)!(userAccountControl:1.2.840.113556.1.4.803:=514))