AD Account Deletion After 30 Days

Hello,

We have a requirement from the client to delete leavers AD users after 30 days instead of disabling them and moving them to leavers OU then to be deleted by gpo.

Also they need the deletion to be approved from the line manager before deleting the account after 30 days.

Is that possible and how can we achieve that ?

Best Regards,
Ahmed Nasr

I’m assuming a workflow would be the best option. Shooting from the hip, generate a task for the manager when the lifecycle state changes for accounts that have reached 30 days after a termination. When task is showed as completed, write an IDN value to the account. Have a lifecycle state for that IDN value that allows the deletion.

I’m sure others may have a better process, but this would get you in the right direction.

This topic was automatically closed 60 days after the last reply. New replies are no longer allowed.