For upgrade installations, the built-in Administrator account is kept enabled when there is no other active local Administrator on the computer.However, the built-in Administrator account is disabled by default for new installations and upgrades on domain-joined computers, regardless of whether there are other active local Administrators on the domain-joined computers.Also If the user is not disabled & moved to another OU which is not selected to be Sync , similar behavior is observed. Is Imported =0 Note : It is not recommended to Query any Sharepoint databases or to make changes other than ones described at .Observation: Since we are not using FIM for synchronization, there is nothing to look into Sync DB. Full import will detect the user is not getting imported and marks the field ‘Is Imported’ to 0 on DNLookup table in Profile DB for the affected user. Is Imported FROM [User Profile_Full] A (nolock) inner join [DNLookup] B (nolock) on A. Workaround: The “Share Point Active Directory Import” does not mark the profile to be deleted either with incremental or Full Import when they are disabled and only way to remove the obsolete users is as mentioned HERE .
Kerberos is the default authentication method and successful authentication results in the client receiving a Kerberos ticket that's good for 10 hours.To configure Outlook to only send or only receive messages, do the following: When you disable the send operation, Outlook will still let users create an email.Then, when they initiate the send and receive operation, Outlook will move the message from the Outbox to the Sent folder, but it won't actually send the message.Kerberos is used when users are accessing Lync Server while on the domain.NTLM is used for authentication from other locations, such as the Internet for remote access using Lync Edge servers.