Hello,
I have MPRs and sync rules in FIM to disable AD accounts for users who are inactive in ERP and to enable them when they are active. To enable them I flow 512 to useraccountcontrol. Today I turned FIM on for the first time against my production AD and when it was time ran an export to AD. It did what I expected; active users got the "enable active users" ERE and 512 flowed out to AD but LOTS (not all) of my AD accounts got disabled. My own normal account was locked out so I logged in with my admin account and checked out my non-privileged account. Sure enough it had 512 in the uac value. I've worked in directories a long time including ten years at Microsoft and I can't understand what happened. Can anyone explain why flowing 512 disabled the account? A small clue maybe; the accounts were set to 544 previously. Maybe moving from 544 to 512 doesn't work?
Thanks,
Lee