Repositories will do a periodic sync. A user is deleted from an AA repository if they are not returned in the result set of a repository sync. Deleting a user from AA is drastic in that it removes all enroll authenticators and it is not possible to restore that user.
It should be configurable that if a repository sync would result in more than X number of users being deleted, abort the sync (or at least do not delete!) and notify an administrator (per email, log event at least, etc.)
by: Tim S. | over a year ago | Configuration
Comments
We will investigate some options and come back to you. We may be able to disable the user then execute a clean-up process on administratively set window (30, 60 days or whatever).