You can control how Workspace ONE UEM reacts when user accounts are removed or deactivated in your directory service by using auto sync in the User tab of Directory Services. Auto sync monitors user statuses in Directory Services and when a user is removed from Directory Services, they are also removed from the associated UEM user group and unenrolled from the UEM console.
If you want to deactivate a user in UEM manually, regardless of what happens to their status in Directory Services, you can delete their UEM console user account. Navigate to Accounts > Users > List View then locate the account you want to delete, select the account by clicking the check box to the left of its entry, select the More Actions button, select Delete, and then select Save at the Bulk Action Message screen, which serves as a delete confirmation.
Conversely, users that are deactivated and then reactivated in your directory service reactivate in the UEM console automatically.
When users deactivated in your directory service are later reactivated, Workspace ONE automatically reactivates their UEM console account. This feature is always on and requires no console setting. Also, the event log captures this event which you can use for troubleshooting purposes.
You can automatically perform an enterprise wipe when users are removed from user groups. This check occurs at the same frequency as the Sync LDAP Groups scheduler task.
Note:
You can automatically perform an enterprise wipe when users are removed from user groups. This check occurs at the same frequency as the Sync LDAP Groups scheduler task.
The Restrict Enrollment To Configured Groups option means that enrollment is limited in the following ways.
For more information, refer to the Enabling Directory Service-Based Enrollment section of the VMware AirWatch Mobile Device Management Guide, available on docs.vmware.com.
You can enable Workspace ONE UEM to detect when a user account is deactivated in your directory service and automatically set its associated Workspace ONE UEM user account to inactive.
Enable the Automatically Sync Enabled Or Deactivated User Status slider.
If you select this option, then Workspace ONE UEM administrators set as inactive in your directory service cannot log in to the UEM console. In addition, enrolled devices assigned to users who are set as inactive in your directory service are unenrolled automatically.
You can enable Workspace ONE UEM and Workspace ONE Express to detect when a directory service user account is removed and automatically remove its associated user account from the associated group.
Parent topic: Managing Directory User Group Integration in Workspace ONE UEM