Disabling someone's account under Settings -> Users is a full, immediate stop -- not a soft warning.

  • They can't do anything, no matter how they normally sign in -- Windows account, Azure AD, or a separate app-only username and password.
  • If they're already logged in with a username and password, that access is cut off right away -- they don't get to keep working until they happen to log out.
  • A fresh login attempt while disabled fails with the exact same message a wrong password would show, so nobody can tell from the message alone whether the account doesn't exist, the password's wrong, or the account is disabled.
  • Windows and Azure AD sign-in themselves aren't something Minion Agent controls -- someone can still log in to Windows or Azure normally even while disabled here. What's guaranteed is that the instant they try to do anything inside the app, it's blocked.
  • Nobody is exempt -- even a Fleet Admin account is fully blocked if it's disabled.
  • Nothing gets deleted. The account, its role assignments, and its history are all left exactly as they were -- disabling is fully reversible, and re-enabling restores everything.
  • Every disable and re-enable shows up in the Activity log, same as any other change.

A disabled user's name renders dimmed with "(disabled)" next to it in the Users list, visible at a glance without opening anything.