Howdy.
HR, from time to time, asks us to disable access in AD for users temporarily. We don’t want to field questions on employment status for these users so don’t want the LDAP sync to remove them from Openfire but it does. Our LDAP filter is pretty wide open and disabled users are not explicitly being excluded from the sync. Is there another field somewhere I need to manage to stop disabled accounts from being removed during the LDAP sync process?