web
You’re offline. This is a read only version of the page.
close
Skip to main content
Community site session details

Community site session details

Session Id :
Microsoft Dynamics CRM (Archived)

Can a CRM user account still be misused after being disabled at Active Directory?

(0) ShareShare
ReportReport
Posted on by

Just curious.

Appreciate if someone could share incidences or examples if the answer is "yes".

*This post is locked for comments

I have the same question (0)
  • Suggested answer
    Biplab Singha Profile Picture
    on at
    RE: Can a CRM user account still be misused after being disabled at Active Directory?

    Hi William,

    It is enough disabling user from AD. After Disabling the user He/She will not be able to Log into CRM System. But here is a Catch If you don't disable the users from CRM they it will Continue to access "CAL" License which will cost your company. Instead if you disable the user You can use the Same CAL license for other user. and there will not be any extra cost.

    But in CRM Online there is a synchonisation between o365 and CRM so if you disable from in O365 synchronisation will disable user from CRM

    Mark the As Verified if it answers your Question

  • wtoh Profile Picture
    on at
    RE: Can a CRM user account still be misused after being disabled at Active Directory?

    Thanks Karsten and Yawer.

    But these best practice to disable in CRM and remove roles etc, wouldn't it show the lack of confidence on the CRM-AD security model?

    You see, I have people insisting disabling in AD is not good enough. But just imagine the workload on user administrator if especially there is high volume of staff and turnover?

  • Suggested answer
    Haansi Profile Picture
    1,433 Moderator on at
    RE: Can a CRM user account still be misused after being disabled at Active Directory?

    Disabling in AD and CRM should be enoungh, no need to delete teams and roles in my opinion.

  • Suggested answer
    Karsten Wirl Profile Picture
    4,477 on at
    RE: Can a CRM user account still be misused after being disabled at Active Directory?

    Hello William.

    The basic of the security model is the Active Directory. Wenn you diable the AD Account of one user, he has no longer the chance to get inside CRM. The AD is the main front for your CRM-Security.

    If you want to play it safe it's a good thing to disable the user in CRM as well... and to delete all Teams and SecRoles related to the user.

    Kind regards,

    Karsten

  • wtoh Profile Picture
    on at
    RE: Can a CRM user account still be misused after being disabled at Active Directory?

    Thanks for your response Yawer.

    My environment is on-premise.

    In my context, i wish to ascertain the security aspect of this user account on CRM in relation to disabling only at AD.

    of course, it make sense to disable the users at CRM so i can release the license, but the question here is urgency in view of security.

  • Suggested answer
    Haansi Profile Picture
    1,433 Moderator on at
    RE: Can a CRM user account still be misused after being disabled at Active Directory?

    "no", if a user account is disabled properly.

    To disable a user account steps are different depending you are in CRM online or on premise.

    This article gives a summary of steps on how to disable a user in CRM, please see this to verify.  

Under review

Thank you for your reply! To ensure a great experience for everyone, your content is awaiting approval by our Community Managers. Please check back later.

Helpful resources

Quick Links

Responsible AI policies

As AI tools become more common, we’re introducing a Responsible AI Use…

Andrés Arias – Community Spotlight

We are honored to recognize Andrés Arias as our Community Spotlight honoree for…

Leaderboard > 🔒一 Microsoft Dynamics CRM (Archived)

#1
Aric Levin - MVP Profile Picture

Aric Levin - MVP 2 Moderator

#2
MA-04060624-0 Profile Picture

MA-04060624-0 1

Last 30 days Overall leaderboard

Featured topics

Product updates

Dynamics 365 release plans