
564gv (564gv) asked a question.
Hi,
I have a decentralized environment where two AD instances are linked so that when an account is created from AD1, it creates an account in AD2. This is a one way process so AD2 would never translate any updates to AD1. Similarly, if I disable an account in AD1, the account is disabled in AD2.
However, I am trying to determine whether the account in AD2 can be expired instead or disabling? This is because the immediate disable is breaking some other automated processes. I know I should be addressing that issue but technical team is suggesting to expire account so that the account is still 'enabled' but not usable to allow automated process to complete (which would include disabling later). I suspect this is breaking the OKTA process but seeking advice?
We are using the OKTA AD Sync tool to disable users

I haven't come across this functionality , as okta will only deactivate the account