# LDAP User Sync - Influence deletion of users

**URL:** <https://forum.keycloak.org/t/ldap-user-sync-influence-deletion-of-users/8446>\
**Category:** Getting advice\
**Created:** [April 12, 2021, 7:59am UTC](https://forum.keycloak.org/t/ldap-user-sync-influence-deletion-of-users/8446 "2021-04-12T07:59:23Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![jap](https://avatars.discourse-cdn.com/v4/letter/j/898d66/32.png) [@jap](https://forum.keycloak.org/u/jap)\
**Post date:** [April 12, 2021, 7:59am UTC](https://forum.keycloak.org/t/ldap-user-sync-influence-deletion-of-users/8446/1 "2021-04-12T07:59:23Z")

</div>

Hi,

I have a user federation via LDAP configured. Users are only synchronized into my Keycloak realm when they have a certain group in Active Directory. There is a daily full sync and hourly partial sync for new/updated users.

If that group is revoked in AD, the user will no longer be synced. Additionally I found, it will even be deleted from the Keycloak realm.

Is that behavior something I can influence? Can I make the user “disabled” instead of deleting him?

Thanks
