Removing Inactive Administrator Accounts

The HSM allows you to disable or remove user accounts; however, administrator accounts can only be removed, not disabled. If you do not activate the HSM, this feature is disabled after the 30-day trial period expires.

icon_info.gif

EFT Server executes cleanup procedures every day at 00:00:00 UTC and at Server Startup. This daily server cleanup removes/disables inactive administrators and user accounts and sends password reset and expiration notifications for every Site.

For Sites defined using the "strict security settings," EFT Server enables the option to disable or remove inactive accounts automatically, and warn if you attempt to disable that setting. The option to remove administrator accounts will be enabled by default, unless during the setup process you choose not to enable this option. EFT Server prompts administrators when they login advising them of the potential removal of their account if their login failed due to unknown login name. The removal of accounts is captured in the Auditing and Reporting database for reporting.

If a user attempts to log in remotely to EFT Server with an administrator username that does not exist or an incorrect password, a warning message appears in the administration interface.

To specify automatic deletion of inactive administrator accounts

  1. In the administration interface, connect to EFT Server and click the Server tab.

  2. In the left pane, click the Server node you want to configure, then click the Administration tab.

  3. Click an EFT Server-managed administrator account, then click Account Policy. The Account Security Settings dialog box appears.

    db_accountsecuritysettings.gif

  4. Select the Remove admin accounts after check box, then specify the number of days of inactivity after which to delete the account.

  5. Click OK to close the dialog box.

  6. Click Apply to save the changes on EFT Server.

icon_info.gif

A change in any date-sensitive value resets the calculations. For example, if this feature was configured for 60 days, and you change it to 90 days, the count resets to zero, so that any inactive account that has been inactive for 59 days and was set to be deleted tomorrow, will now not be considered inactive until 90 days from today.