Repositories will do a periodic sync. A user is deleted from an AA repository if they are not returned in the result set of a repository sync. Deleting a user from AA is drastic in that it removes all enroll authenticators and it is not possible to restore that user.

It would be helpful to configure a grace period before a user is deleted from a repository after not returning in a repository sync's result set. For example, "Only remove users that have not been found in the last X days of repository sync results."

Comments