Disabling an Amazon Managed Microsoft AD user
Use the following procedure to disable an Amazon Managed Microsoft AD user with user and group management or Amazon Directory Service Data in either the Amazon Web Services Management Console, Amazon CLI, or Amazon Tools for PowerShell.
Important
When you disable a user's account, the user loses any permissions to access their account and applications.
Before you begin either procedure, you need to complete the following:
- To use user and group management or Amazon Directory Service Data CLI, it must be enabled. For more information, see Enable user and group management or Directory Service Data. 
- 
      You can only enable this feature from the Primary Amazon Web Services Region for your directory. For more information, see Primary vs additional Regions. 
-         You'll need the necessary IAM permissions to use Amazon Directory Service Data. For more information, see Amazon Directory Service API permissions: Actions, resources, and conditions reference. To get started granting permissions to your users and workloads, you can use Amazon managed policies like Amazon managed policy: AWSDirectoryServiceDataFullAccess or Amazon managed policy: AWSDirectoryServiceDataReadOnlyAccess. For more information, see Security best practices in IAM.