Applies to: All versions of Centrify Identity Service, Mac Edition
Question:
What is the expected behavior when administrator manually disable the mac computer object from Active Directory during connected mode?
Answer:
If Administrator disable the computer account while the Centrify agent is still in connected mode, Centrify will no longer authenticate user login.
However if you restart the Centrify agent afterwards, the machine will fall into disconnected mode due to the status of the computer object and start to authenticate users as offline login, if the user has previously logged in.
The correct step in deactivating a mac computer when joining Centrify will be:
Running adleave command to leave the domain. If the computer already in deactivated state, please run with -f option to leave.