AD Bridge Sync Does not Terminate / Revoke Deleted AD Users in IDCS
(Doc ID 2514748.1)
Last updated on FEBRUARY 04, 2020
Applies to:Identity Cloud Service (IDCS) - Version N/A and later
Information in this document applies to any platform.
On : N/A version, Identity Bridge
AD Bridge sync does not terminate deleted AD users in IDCS
A user is sync'd into IDCS from AD via the AD Bridge and later terminated / deleted on the AD side. The user is put into the deleted objects container on the AD side, but later imports / syncs via the Bridge fail to remove the user on the IDCS side.
Terminated / deleted users should be revoked from IDCS groups and also removed from the Users page, once they are sync'd in from the AD Bridge.
The issue can be reproduced at will with the following steps:
1. User is a member of a group and imported into IDCS from the AD Bridge
2. User is terminated and thus moved into the deleted objects container on the AD side
3. Run an Import sync from the AD Integration on the IDCS Admin Console
4. Check and see that the user is still listed on the Users page as a Federated user
5. Check one of the Groups on the IDCS side and find the terminated user is still shown as a member
To view full details, sign in with your My Oracle Support account.
Don't have a My Oracle Support account? Click to get started!
In this Document