This article covers how to configure automated rules for user account handling based on changes in Active Directory, plus the scheduling and review steps that complete setup.
Settings overview
Setting | | Options |
Password Notifications | Decide how new users get their initial passwords
| - Send email OTP to user - The new user receives an OTP directly at their registered email.
- Send email OTP to admin - Admin receives the OTP/setup info to forward manually.
- Don't notify - No automatic notification; admin must notify the user manually through another medium.
|
| Choose how to reflect a user's AD account status changes in Zoho Directory | - Reflect - If disabled in AD, the Zoho Directory account is also disabled (and re-enabled if restored).
- Do nothing - Ignore AD status changes.
|
Mail Notifications | Choose whether to notify synced users
| - Send - Sends emails to newly synced users and resends invite links to pending users.
- Don't send - No email notifications.
|
When User Leaves Selected OU | Define what happens in Zoho Directory when a user is moved out of a selected/synced AD OU | - Disable - The user's Zoho account is auto-disabled.
- Do nothing - The account remains active but is no longer included in future sync operations.
|
Important: the Status Sync ↔ OU-departure dependency
There is a crucial interaction between Setting 2 and Setting 4. "When User Leaves Selected OU" is only available if Status Sync is set to Reflect. If you choose Do nothing for Status Sync, the system cannot manage user status based on OU membership, and the "When User Leaves Selected OU" setting will become disabled and unavailable.
Example
Assume user Dexter is moved out of their synced OU in Active Directory:
| When Dexter Leaves OU setting | | |
| | Dexter is removed from OU but still active in AD | Dexter's Zoho account is disabled (OU rule applies) |
| (field disabled - no choice available) | Dexter is removed from OU | Dexter's Zoho account remains active but is no longer synced |
Hard deletion propagation from Active Directory
When Identity Connect is enabled, Active Directory acts as the primary source for user discovery. If a user is deleted or disabled in Active Directory, the resulting action in Zoho Directory depends on your Status Sync setting:
When Status Sync is set to Reflect, users disabled or removed in Active Directory are disabled (not deleted) in Zoho Directory by default.
If your organization requires users to be
completely deleted from Zoho Directory instead of just disabled, contact
Zoho Directory Support to get this particular configuration enabled. Enabling deletion propagation will
permanently remove users in Zoho Directory when they are disabled/deleted in Active Directory.
For step-by-step instructions on deleting users and handling ownership transfers, see
How to Delete a User
Note on admin deletion: Each Identity Connect configuration is tied to a Zoho Directory admin. To ensure uninterrupted sync, the system will not allow deletion or disablement of an owner-admin. You must first use Change Ownership in the tray app to transfer dependencies to another admin before the original account can be removed. Attempting deletion directly will be blocked, and the account will be placed in a "delete-pending" state until dependencies are cleared.Deleting a directory-synced user from Zoho Directory
Deleting a user in Zoho Directory does not remove the user from Active Directory.
Warning on data loss: If "Delete in ZD" is enabled, removing a user from Active Directory will permanently erase their Zoho mail, files, and service data. This cannot be recovered even if the user is re-synced later from Active Directory.
Common sync scenarios after user deletion
Scenario | | | | |
| User deleted | User exists & meets criteria
| User appears in "Users to Create" | User is automatically recreated |
Complete removal | | | | No re-provisioning (user remains deleted) |
Mixed Zoho & AD actions (or) Conflicting actions | | User disabled/moved out of synced OU | Depends on Status Sync setting | Depends on Status Sync setting |
This table illustrates typical outcomes. Actual results depend on your specific sync criteria and status settings.
Schedule sync
Set frequency (Daily/Weekly/Monthly) and time of sync. Click Save and Next.
Changes in Active Directory are reflected based on the configured sync schedule and may not appear immediately in Zoho Directory.
Review and finalize sync
- Review and select users from the imported list to add to Zoho Directory, using these filters:
- New Users - Found in your directory but not yet in Zoho Directory.
- Users to Update - Existing Zoho Directory users whose info will be updated from your directory in the next sync.
- Marked for Activation/Disable - Users who will be activated or disabled based on their directory status. Review this category carefully before syncing to avoid unintended access changes.
- Ignored - Users who don't meet the defined sync criteria.
- Click Add and Continue, review the summary, and click Finish to complete setup.
Setup is now complete. Active Directory users and groups will sync automatically based on the rules you've defined. To check on agent health or sync status going forward, see
Monitoring and Troubleshooting.