Skip to main content

Why does a deactivated user keep coming back?

A deactivated user becomes active again when an automated user source, such as Azure AD automatic import, Okta, an integration or the SalesScreen API, re-enables the user. To stop this, remove or deactivate the user in the source system as well.

Written by Emil Lindblom

Overview

This article explains why a user you deactivated in SalesScreen can become active again, and how to stop it from happening.

The article is for Company Admins, User Admins and IT users who manage users in SalesScreen or in a connected user provisioning system.

This article covers user status (active or inactive). It does not cover how to buy or manage licenses.

Who can do this?

Action

Required access

Deactivate or reactivate a user in SalesScreen

Company Admin or User Admin

Set up Azure AD import in SalesScreen

Admin privileges in both SalesScreen and your Azure AD tenant

Remove the user from Azure AD, Okta or another source system

Admin of that system, usually your IT department

Activate a pending user

Account Owner, Company Admin or User Admin

Order more licenses

Account Owner only

Confirm which system reactivated a user

SalesScreen Support

Which plans include this?

Deactivating, reactivating and syncing users is available on all plans.

Requirements

Before you start, make sure that:

  • You have Company Admin or User Admin access in SalesScreen.

  • The user is already deactivated in SalesScreen.

  • You know, or can find out, whether the user is managed manually or through an integration.

  • You have access to the source system, or you can contact the person who manages it.

  • For Azure AD: you have admin privileges in your Azure AD tenant, or you can contact your Azure AD admin.

When this matters

Use this article when:

  • A former employee becomes active again after being deactivated.

  • A user is re-enabled after each sync.

  • A user is activated or deactivated and nobody in your company made the change manually.

  • You use Azure AD automatic import, Okta, an API integration or another automated user source.

  • You are unsure whether a user is managed manually or synced from another system.

How it works

Manually managed users stay deactivated

A user who was created and managed manually in SalesScreen stays deactivated until someone reactivates the user.

Synced users follow the source system

If an integration or provisioning tool controls the user, that system decides whether the user is active. Deactivating the user only in SalesScreen can be temporary, because the source system can re-enable the user.

API changes cannot be overwritten in SalesScreen

If a user is activated through the SalesScreen API, you cannot override the change in SalesScreen. The system that sends data through the API must stop sending the user as active.

Which source controls the user?

Source

What it means

Where to fix it

A person (email address)

Someone changed the user manually in SalesScreen

SalesScreen

Microsoft Azure AD

Azure AD automatic import controls the user

Azure AD, usually managed by IT

Okta

Okta can activate users in SalesScreen

Okta, usually managed by IT

Integration API

A user provisioning tool that your company controls manages the user

That provisioning tool, usually managed by IT

SalesScreen API

User data is sent to SalesScreen through the API

The system or integration that sends the data

You can check which source activated or deactivated a user in User Logs under Manage › Users. User Logs show the action, the source and who or what made the change. If the source is still unclear, contact SalesScreen Support.

How Azure AD automatic import works

Azure AD automatic import keeps SalesScreen users in sync with the Azure AD groups you select.

  • Any user in a selected group is added to SalesScreen automatically.

  • SalesScreen checks the selected groups for membership changes.

  • The sync runs once every hour.

  • The integration is read-only. SalesScreen never writes data back to Azure AD.

Automatically disable users is an optional setting:

  • When the setting is on: users removed from the selected Azure AD groups are also disabled in SalesScreen.

  • When the setting is off: users removed from the groups are not disabled in SalesScreen automatically.

How Okta works with SalesScreen users

SalesScreen supports Okta for single sign-on (SSO), and Okta can activate users in SalesScreen.

  • Users activated through Okta are not added to a team automatically. Assign the user to a team, otherwise activities cannot be logged to the user.

Users vs. licenses

A user and a license are two different things. Changing licenses does not stop a synced user from coming back. The difference is described in the table under 3.2.1.

Configuration or setup

Step 1: Find out what controls the user

1. Click Manage in the bottom-left corner.

2. Under Company, click Users.

3. Click User Logs.

4. Find the latest activation of the user, and check the source.

If the source is a person's email address, the user was changed manually. If the source is Microsoft Azure AD, an integration or the SalesScreen API, the change must be made in that system. If the source is unclear, contact SalesScreen Support.

Step 2: Remove the user at the source

Remove the user from the source system or from the group or list that feeds SalesScreen.

  • Azure AD: remove the user from every Azure AD group selected for the SalesScreen import.

  • Okta or another provisioning tool: ask your IT admin to remove or deactivate the user there.

  • SalesScreen API or another integration: ask the integration owner to stop sending the user as active.

If the user is still included at the source, the user can become active again on the next sync.

Step 3: Turn on Automatically disable users (Azure AD only)

  1. Go to Users › Add users › Import users from Azure AD.

  2. Open Automatic Import.

  3. Turn on Automatically disable users.

Step 4: Wait for the next sync and check the user

Then go to Manage › Users › Deactivated and confirm that the user is still listed there.

Expected result

  • The user stays deactivated after the next sync.

  • The user is listed on the Deactivated tab under Manage › Users.

  • You can reactivate the user later if needed.

Technical details

3.2.1 Data, fields or objects

Field / object

Description

Active user

A user who can log in to SalesScreen

Inactive user

A user who can no longer log in, but is still listed on the Deactivated tab

Pending user

A user who was added without an available license and cannot log in yet

License

A paid seat that allows a user to be active

Azure AD group

A group selected in Azure AD automatic import. Members are added to SalesScreen

Okta

Identity provider used for SSO. Okta can activate users in SalesScreen

SalesScreen API

Sends user data to SalesScreen from an external system

3.2.2 Configuration parameters

Setting

Where to configure it

Default

Notes

Azure AD automatic import

Users › Add users › Import users from Azure AD › Automatic Import

Off

Click Enable to turn it on

Selected Azure AD groups

Automatic Import page

None selected

Users in the selected groups are added to SalesScreen

Automatically disable users

Automatic Import page

Off (optional setting)

Disables users in SalesScreen when they are removed from the selected groups

Azure AD sync frequency

System-controlled

Once every hour

Cannot be changed by the customer

Okta SSO

Set up in Okta by your IT admin, then completed by SalesScreen

Not set up

Your IT admin creates the SalesScreen app in Okta and shares the Client ID, Client Secret and Okta domain with SalesScreen

3.2.3 Limits and behaviour

Area

Behaviour

Manually managed users

Stay deactivated until someone reactivates them

Azure AD synced users

Can become active again if they remain in a selected Azure AD group

Okta users

Can be activated by Okta. Are not added to a team automatically

API-managed users

API changes cannot be overwritten in SalesScreen

Provisioning tools and teams

Provisioning tools activate or deactivate users. They do not control teams

Pending users

Deactivated automatically by SalesScreen if not activated within 2 weeks

Reactivation

Requires an available license

Users without a team

Cannot have activities logged to them

Viewing the activation source

Admins can check the source in User Logs under Manage › Users

3.2.4 Error codes and typical issues

Error or symptom

Likely cause

How to fix it

A deactivated user becomes active again after an hour

The user is still in a selected Azure AD group

Remove the user from all selected Azure AD groups

A user was removed from Azure AD but is still active in SalesScreen

Automatically disable users is turned off

Turn on the setting, or deactivate the user manually

A user is re-enabled and nobody changed it in SalesScreen

Okta, another provisioning tool, an integration or the API is sending the user as active

Ask your IT admin or the integration owner to update the user at the source

A user was deactivated without anyone doing it manually

The user was removed from the source system, or the user was pending for more than 2 weeks

Check the source system and whether the user was pending

A user is pending instead of active

No available licenses

Ask an Account Owner to add licenses

A synced or reactivated user has no data

The user is not assigned to a team

Assign the user to a team

What if this doesn't work?

Check the following:

  1. Check User Logs under Manage › Users to see who or what activated the user again.

  2. The user is removed from the source system, not only deactivated in SalesScreen.

  3. The user is not in another Azure AD group, Okta assignment or source list connected to SalesScreen.

  4. The integration or API no longer sends the user as active.

  5. You have waited for the next sync.

  6. The issue is about user status, not license availability.

If the user still comes back, contact SalesScreen Support and include:

  • Company name

  • Name and email address of the user

  • Source system, for example Azure AD, Okta, CRM or API

  • The Azure AD group, Okta assignment or source list the user belonged to

  • When the user was deactivated

  • When the user became active again

  • Whether the user is active, inactive or pending

  • Steps you have already tried

Related articles

Did this answer your question?