Looking at your documentation on this page: https://confluence.atlassian.com/display/DOC/User+Management+Limitations+and+Recommendations you state the following:
"Be careful when deleting users in remote directories. If you are connecting to an LDAP directory, a Crowd directory or a JIRA directory, please take care when deleting users from the remote directory. If you delete a user that is associated with data in Confluence, this will cause problems in Confluence."
Our sys admins have advised me that it is not good practice to keep users Active Directory once they have left the company. Their current process is to move them into a 'pending deletion' folder before deleting them permanently.
We have linked our Confluence to LDAP with read only access and local groups. We do not have incremental synchronisation but are using the method described here: https://confluence.atlassian.com/display/DOC/Synchronising+Data+from+External+Directories to keep the cache up to date.
Can you answer the following questions for me?
- What "problems" will deleting users in Active Directory actually cause Confluence?
- How do you recommend deleting ex-employees from Active Directory?
- Can you explain how Confluence uses the Deleted Objects folder? It is stated in your documentation that Confluence should have access to read this folder, but not why this is needed.
- Can Confluence be configured to disable accounts when they are removed from Active Directory rather than simply deleting them?
Thank you very much for your help