Tools
Cleanup of Inactive LDAP User Profiles Using Configurable Retention Policies in Kiwi Syslog Server NG 2026.2
First published date
Last published date
Overview
Kiwi Syslog Server NG 2026.2 introduces a new scheduled task for cleaning up inactive LDAP user profiles. The feature allows administrators to configure retention policies through the Schedule Wizard to automatically remove inactive LDAP user profiles based on the defined criteria.
Product section
Resolution
The LDAP User Cleanup feature in KSS NG 2026.2 is designed to automatically remove inactive LDAP user profiles from KSS NG. It does not delete user accounts from Active Directory; it only manages the corresponding user profiles stored in KSS NG.
You can configure the task from Setup > Schedules > Add scheduled task, and then select User Cleanup. The available settings are:
-
Inactivity Period (days): The number of days a user profile must remain inactive before it becomes eligible for cleanup. The minimum accepted value is 0. We recommend using a conservative value, such as 90 days, to avoid removing profiles that may still be needed.
-
Account Types to Clean: This feature applies to LDAP accounts only. Local KSS NG accounts are excluded by design.
-
Role Types to Clean: You can select Administrator users, User users, or both, depending on which profiles you want the task to process.
-
Enabled: Controls whether the cleanup task is active.
-
Schedule: Defines how often the task runs. You can also configure schedule exceptions if required.
Use the steps below:
- In KSS NG, open Setup > Schedules and add a scheduled task.
- Select the User Cleanup task type.
- Set the required schedule and enable the task.
- Configure the inactivity threshold in days.
- Select the LDAP account type and the applicable roles.
- Initially test with a conservative threshold and a noncritical LDAP account.
- If the task does not appear or the schedule list behaves incorrectly, please do let me know and also confirm the exact build of your environment.
For example, a task configured with an inactivity period of 90 days, account type LDAP, and role type User will clean User-role LDAP profiles that have been inactive for at least 90 days when the scheduled task runs.
For additional information, refer to the following documentation: