The EDirectory loginDisabled attribute is a boolean and when this attribute is set to True, it disables the user account. This is used for explicit permanent disabling of an account. The loginDisabled attribute can only be manually set and cleared. Any other value than "True", including the lack of values, the account is enabled.


The orclIsEnabled attribute is used within Oracle Internet Directory denotes that a user is currently enabled to authenticate. Valid values are ENABLED (or attribute not present in the user entry) and DISABLED. A user can successfully authenticate only if the value is "ENABLED" or the attribute is not present in the entry. Defined in the Oracle Internet Directory schema as:
attributetypes	( 2.16.840.1.113894.1.1.316 NAME 'orclIsEnabled' EQUALITY caseIgnoreMatch SYNTAX '' SINGLE-VALUE )

Sample Policy To Work With OrclIsENabled#

<rule name="Override Enable in OID" next-transform="Password(Pub)-Default Password Policy.Publisher.QctOid.driverset.dirxml.services">
			<description>Override enable in OID (OID attribute orclIsEnabled is opposite of Login Disabled)</description>
					<if-class-name op="equal">User</if-class-name>
					<if-op-attr name="Login Disabled" op="changing"/>
					<if-op-attr name="Login Disabled" op="not-available"/>
					<if-dest-attr name="Login Disabled" op="equal">true</if-dest-attr>
					<if-class-name op="equal">User</if-class-name>
					<if-op-attr name="Login Disabled" op="changing"/>
					<if-op-attr name="Login Disabled" op="not-equal">DISABLED</if-op-attr>
					<if-dest-attr name="Login Disabled" op="equal">true</if-dest-attr>
				<do-set-src-attr-value name="Login Disabled">
					<arg-value type="string">
						<token-text xml:space="preserve">DISABLED</token-text>

