One of our users recently switched roles to a new position where they will not need computer access anymore, except for checking emails. I need to disable their AD account while not removing their Outlook login or mailbox.
My first thought was to remove the proxyAddress
attribute value in AD, do a sync, then disable the user in AD. But what I've read is that you need to disable the user in AD, or move them into a unsynched OU, then go into 365 admin portal and re-enable their account, and delete the immutable ID. I'd love to get confirmation if this is right.
I can't find a consistent answer on google and don't want to risk losing their mailbox.