Deleting or Disabling Inactive User Accounts

EFT Server allows you to automatically disable or remove accounts that have been inactive for a period that you specify (1 to 365 days). The deletion of accounts is captured in the Auditing and Reporting database for reporting.

icon_info.gif

Removing a user account deletes the account from the Authentication manager, but does not delete the user home folder or its contents.

When a PCI DSS Site is created in the Site Setup wizard, the option to remove inactive user and administrator accounts after 90 days is enabled by default. If, during Site setup, EFT Server detects that one or more administrator accounts already exist, and that the option to remove administrator accounts after 90 days is not enabled or set to a value greater than 90 days, you are prompted to enable or change that setting.

If a Server administrator attempts to login from a remote system via the administration interface and the password was incorrect or the username does not exist (either because it never existed or because it was removed), when you click Apply, EFT Server does not commit the change, and a warning message appears. In the message that appears, you can accept the non-compliant setting and provide a reason for using this setting (e.g., if you are using an alternate solution), or discard the change. If you accept the change and provide a reason, a warning message and the reason that you provided appear in the PCI DSS Compliance report.

icon_info.gif

EFT Server executes cleanup procedures every day at 00:00:00 UTC and at Server Startup. This daily server cleanup removes/disables inactive administrators and user accounts and sends password reset and expiration notifications for every Site.

 

icon_info.gif

Any transition from a non-PCI DSS compliant state to a PCI DSS compliant state, or a change in any date-sensitive value, will reset all data value calculations. For example, if a Site is running in PCI DSS mode, and the administrator disables Remove inactive admin accounts after 90 days, clicks Apply, and then immediately decides to re-enable that option, the date values for all administrator accounts are reset from the time the option is enabled, even if the last login dates for those administrators was <n> days ago. The same reset also occurs if you change the password reset period from 30 days to 60 days; that is, the change itself prompts a reset of all the time-based values for that feature.

On a PCI DSS Site, if you do any of the following and then click Apply, EFT Server does not commit the change, and a warning message appears.

In the message that appears, you can discard the change or accept the non-compliant setting and provide a reason for using this setting (e.g., if you are using an alternate solution). If you accept the change and provide a reason, the warning and the reason that you provided appear in the PCI DSS Compliance report.

To specify automatic deletion or disabling of inactive user accounts

  1. In the administration interface, connect to EFT Server and click the Server tab.

  2. In the left pane, click the user or Settings Template you want to configure, then click the Security tab.

    tab_user_security.gif

    icon_info.gif

    If the check box contains a gray check mark, the user or Settings Template is inheriting permission from the parent.

  3. In the Account Security area, select the Disable/Remove account after <n> days of inactivity check box, click the list to specify Disable or Remove, then specify the number of days. You can specify from 1 to 365 days. 90 days is the default, per PCI DSS 8.5.5.

Related Topic

Deleting Inactive Administrator Accounts