Action Plan When Deletion Protection Threshold Is Triggered in SpanVA
search cancel

Action Plan When Deletion Protection Threshold Is Triggered in SpanVA

book

Article ID: 405474

calendar_today

Updated On:

Products

CASB Advanced Threat Protection CASB Gateway CASB Gateway Advanced CASB Security Advanced CASB Security Advanced IAAS CASB Security Premium CASB Security Premium IAAS CASB Security Standard CASB Securlet SAAS With DLP-CDS

Issue/Introduction

During an Active Directory (AD) Sync cycle, SpanVA has detected that the number of deletions exceeds the configured threshold. As a result, the deletion protection feature is triggered, preventing the deletions from occurring automatically. The administrator receives an email alert and must take appropriate action to assess and respond.

Environment

  • SpanVA with Active Directory Sync enabled
  • At least one active synchronization profile configured

Resolution

Step-by-Step Response Plan:

  1. Log in to SpanVA.
  2. Navigate to the impacted Sync Profile.
  3. Review the number of users flagged for deletion to determine if the deletions are valid (monitoring logs).
  4. If the deletions are legitimate:
    • Temporarily increase the deletion protection threshold percentage, or disable deletion protection.
    • Run the AD Sync manually to apply the deletions.
    • After syncing, reset the deletion protection percentage to its original value to maintain safeguards.
  5. If the deletions are NOT legitimate:
    • Investigate the root cause (e.g., incorrect OU scoping, sync filters, upstream changes in AD).
    • Correct the issue before attempting another sync cycle.

 

Important: Always verify the legitimacy of deletion events before modifying protection settings to avoid unintended data loss.