Symantec VIP - How to automate removal/deletion of inactive users from VIP Manager
search cancel

Symantec VIP - How to automate removal/deletion of inactive users from VIP Manager

book

Article ID: 275516

calendar_today

Updated On:

Products

VIP Service

Issue/Introduction

There may be situations whereby inactive users need to be removed from VIP Manager without going through an LDAP Synchronization

Environment

VIP Manager

Resolution

The VIP Manager’s 'Automatically Delete Users' policy (Policies tab > Account tab > Users section) can delete users that have not been active in the configured time range.

For user deletion to take place, the following criteria must be met:

  • No credentials or devices are bound to the user, and
  • There has been no user activity for the specified number of days (from 15 to 730)
  • Users must be in an ACTIVE state. 

     VIP deletes all users that meet these criteria daily during the last data refresh (typically around 11:59:59 pm UTC).
     This operation cannot be undone.

Enable both the Automatic Delete User policy and the Credential Expiration policy (Policies tab > Account tab > Credentials section). The Credential Expiration policy will remove credentials from user and set the credential as inactive. No assigned credentials will allow the  Automatic Delete User policy to delete the user after the specified number of days. 


The cleanup activity for this policy in the VIP Manager Audit logs: