I’ve set up ADSync, everything works flawlessly except that when a user is removed from Active Directory in Windows the user is still left in the groups in the PAB.
ACL, Mailfile, persondocument everything else works. Except for the group part…
Seems to be the same problem when using “Delete user” from the PAB.
There’s an administration server set, with manager access and has all the roles in the PAB.
Help would be greately appreciated.
Joacim Boive
Subject: Adminp doesn’t remove user from group(s), solution?
please check your admin4 database - there should be an adminp request for deleting users from groups, and there possibly is an error messaging indicating what goes wrong.
Subject: From memory, I believe that request is “Delete user from Domain directory”
Subject: RE: From memory, I believe that request is “Delete user from Domain directory”
Thanks, but there’s no request in admin4.nsf for that kind of action.
The things listed are:
Delete in Access control list
Delete person in unread list
Delete in Reader/Author fields
Get Mailfile information for deletion
Aprove mailfile for deletion (This is done with the admin id)
Delete Mailfile
Request Mailfile deletion
Get mailfile information for deletion.
This is all that happends.
Any input?
Thanks!
Joacim boive
Subject: I meant to type “Delete person from Domino directory”
The fact that you say this request wasn’t posted suggests that you chose the option to delete the user from the NAB immediately, in which case the deletion of the person document (and removal of the username from other docs) is done while you wait in the front end instead of via adminp.
At this point, we’re back to one of these possibilities:
The administrator performing the deletion does not have edit access to the group documents in question. (In your original post, you clearly indicate that the admin server has the usermodifier role, but it doesn’t appear that the admin user does.)
The administrator performing the deletion does not have read access to the group documents in question. (since this is apparently you, this couldn’t be the case, since if you can’t see the group, then you don’t know that the user’s name is still in it.
The name in the group document(s) is different than the one being deleted.
I assume that the last two possibilities are bogus, and the first one sounds most likely from what you’ve posted so far.