Skip to content

[Bug]: Unable to disable AD-synced users via CIPP API #473

Description

@Tomasrieck

Required confirmations before submitting

  • I can reproduce this issue on the latest released versions of both CIPP and CIPP-API.
  • I have searched existing issues (both open and closed) to avoid duplicates.
  • I am not requesting general support; this is an actual bug report.

Issue Description

Hi,

We're using the CIPP API to disable compromised users.

When attempting to disable an AD-synced user, we receive the following response:

Failed to set sign-in state ... WARNING: User ... is AD Sync enabled. Please enable/disable in the local AD.

Our AD synchronization setup is configured so that the account status can be synchronized/written both ways, so we don't need to manually disable the user in the local AD first.

Is there a way to disable an AD-synced user through CIPP/API without this check blocking the operation? Alternatively, is there another endpoint or setting intended for this scenario?

Environment Type

Sponsored (paying) user

Front End Version

API

Back End Version

API

Relevant Logs / Stack Trace


Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't working

    Type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions