Disable or delete AD user object?

%3CLINGO-SUB%20id%3D%22lingo-sub-1371594%22%20slang%3D%22en-US%22%3EDisable%20or%20delete%20AD%20user%20object%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1371594%22%20slang%3D%22en-US%22%3E%3CP%3EWhat%20is%20recomended%20or%20best%20practise%20when%20an%20employee%20leaves%20the%20buisness%2C%20disable%20the%20account%20and%20keep%20it%20%22for%20ever%22%20or%20delete%20it%20after%20a%20periode%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20any%20reason%20you%20would%20want%20to%20store%20a%20User%20AD%20object%3F%26nbsp%3B%3C%2FP%3E%3CP%3EOr%20is%20it%20a%20good%20reason%20for%20why%20you%20should%20delete%20it%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAlso%20do%20GDPR%20or%20the%20privacy%20law%20enforce%20anything%20regarding%20this%20and%20the%20employees%20sensitive%20information%20regarding%20this%20user%20object%3F%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20there%20any%20difference%20regarding%20this%20on%20AD%20on-prem%20and%20Azure%20AD%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThank%20you!%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1371594%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAccess%20Management%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EActive%20Directory%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EAzure%20AD%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EIdentity%20Management%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1371806%22%20slang%3D%22en-US%22%3ERe%3A%20Disable%20or%20delete%20AD%20user%20object%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1371806%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F486430%22%20target%3D%22_blank%22%3E%40he_jac%3C%2FA%3E%26nbsp%3BHere's%20a%20general%20%22best%20practice%22%20to%20get%20started%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fsv-se%2Fmicrosoft-365%2Fadmin%2Fadd-users%2Fremove-former-employee%3Fview%3Do365-worldwide%23overview-of-all-the-steps-to-remove-an-employee-and-secure-data%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fsv-se%2Fmicrosoft-365%2Fadmin%2Fadd-users%2Fremove-former-employee%3Fview%3Do365-worldwide%23overview-of-all-the-steps-to-remove-an-employee-and-secure-data%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EGDPR%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Finfo.microsoft.com%2Fww-landing-M365EGDPR-accelerate-your-GDPR-compliance-whitepaper.html%3FLCID%3DEN%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Finfo.microsoft.com%2Fww-landing-M365EGDPR-accelerate-your-GDPR-compliance-whitepaper.html%3FLCID%3DEN%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EYou%20should%20get%20familiar%20with%20Microsoft%20Trust%20Center%20as%20well.%3C%2FP%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fservicetrust.microsoft.com%2F%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fservicetrust.microsoft.com%2F%3C%2FA%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20needs%20to%20be%20addressed%20within%20your%20own%20organization%20so%20it's%20difficult%20to%20say%20%22do%20this%20and%20do%20that%22.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

What is recomended or best practise when an employee leaves the buisness, disable the account and keep it "for ever" or delete it after a periode?

 

Is there any reason you would want to store a User AD object? 

Or is it a good reason for why you should delete it?

 

Also do GDPR or the privacy law enforce anything regarding this and the employees sensitive information regarding this user object? 

 

Is there any difference regarding this on AD on-prem and Azure AD?

 

Thank you!

1 Reply
Highlighted

@he_jac Here's a general "best practice" to get started https://docs.microsoft.com/sv-se/microsoft-365/admin/add-users/remove-former-employee?view=o365-worl...

 

GDPR https://info.microsoft.com/ww-landing-M365EGDPR-accelerate-your-GDPR-compliance-whitepaper.html?LCID...

 

You should get familiar with Microsoft Trust Center as well.

https://servicetrust.microsoft.com/

 

It needs to be addressed within your own organization so it's difficult to say "do this and do that".