Some background
There is a confluence install (5.1.3) configured to use two directories:
- Internal: storing service accounts, and other administrative users
- Microsoft Active Directory (Read Only, with Local Groups): pointing to the IT MS-AD servers
IT guys in our organization are using Active Directory to manage about 5-10k users.
The problem
Some user -let's say user John Smith "jsmith"- left the company some time ago. He wrote some content in confluence and when the IT people locked and delete his account, the content appeared as written by "jsmith" (instead of "Smith, John" while the user was still active in LDAP).
After some time, a new user called "Jack Smith", with login (=samAccountName) jsmith joined the company. Now, we have a problem ... All the content generated by John Smith some years ago is shown as generated by Jack Smith. There are no email notifications in our confluence install, but Im pretty sure that if they were active, the emails would be sent to Jack (despite Jack can't log in because jsmith was removed from confluence-users when John left the company).
In one sentence: confluence is telling us (incorrectly) that some content is authored by Jack Smith.
Open questions
How can we work around this weird behaviour? I think that is a conflict between the confluence ldap config and the IT user management policies ...
Can we (confluence admins) change the User Directories config to avoid this?
Should they (LDAP admins) leave the users locked and NOT recycle it-s username when a person leave the company?
Is there any best practice to manage this scenario?
Thanks.