This discussion has been locked.
You can no longer post new replies to this discussion. If you have a question you can start a new discussion

AD membership sync - particular group - syncs also account outside that group

Hello,

as the subject says, I have an issue with AD group sync. There is one user account that have been a member of the group I am syncing from AD in the past but now it is not - it's been verified by at least 2 pairs of eyes.

When I trigger manual sync from AD, sophos writes to log which accounts have been synced. Obviously, the account in question is not in the list (i.e. Sophos did not write a single line into log about it while syncing).

My question would be - why is that user still in my Sophos and how come Sophos boldly shows that it is still member of said group? See attached image.

Manual sync has been triggered like 15times already and automatic runs every day. Also, the user is not a member of the group since months if not years.

Thank you for any hint in advance, take care.



This thread was automatically locked due to age.
Parents
  • Ahoj,

    A user object is not deleted from the UTM if the user is deleted in AD.  How do you know that the UTM still considers this user to be a member of the AD Backend Group - what do you see that leads you to that conclusion?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Reply
  • Ahoj,

    A user object is not deleted from the UTM if the user is deleted in AD.  How do you know that the UTM still considers this user to be a member of the AD Backend Group - what do you see that leads you to that conclusion?

    Cheers - Bob

     
    Sophos UTM Community Moderator
    Sophos Certified Architect - UTM
    Sophos Certified Engineer - XG
    Gold Solution Partner since 2005
    MediaSoft, Inc. USA
Children