Is there a way to remove users from
certain groups, instead of
ALL of them via the Disable Policy? I ask because we're not ready to move to Template-based user permissions (yet) and we need to leave Security groups on each disabled user's account. (believe me, I know the risk in that).
Would there be some kind of an on-demand deprovisioning that we could create that would remove groups we designate? I could simply fill the removal list with all of our Distribution Lists, and if any of the groups matched the user's groups, they would be removed.
There's obviously a powershell method to call in order to accomplish this, but I was hoping for a graphical way.