We've set up a Confluence (3.5.3) instance connected to Active Directory. Active Directory is configured as read only with local groups. The default group membership is set to 'confluence-users'.
The base dn is: OU=Customer,dc=hs,dc=local
The LDAP sub-dn under which the users are stored is: OU=Default Users,OU=Users
The LDAP sub-dn under which inactive users are stored is: OU=Inactive Users,OU=Users
Now the client reports an issue with the users shown in the Confluence user list. After moving a user to the dn with inactive users, they can still find the user in Confluence. The change in AD is done from outside Confluence.
It seems that Confluence doesn't update its internal indexes correctly with the changed situation from AD. Any solutions?