Disabling someone's account under Settings -> Users is a full, immediate stop -- not a soft warning.
- They can't do anything, no matter how they normally sign in -- Windows account, Azure AD, or a separate app-only username and password.
- If they're already logged in with a username and password, that access is cut off right away -- they don't get to keep working until they happen to log out.
- A fresh login attempt while disabled fails with the exact same message a wrong password would show, so nobody can tell from the message alone whether the account doesn't exist, the password's wrong, or the account is disabled.
- Windows and Azure AD sign-in themselves aren't something Minion Agent controls -- someone can still log in to Windows or Azure normally even while disabled here. What's guaranteed is that the instant they try to do anything inside the app, it's blocked.
- Nobody is exempt -- even a Fleet Admin account is fully blocked if it's disabled.
- Nothing gets deleted. The account, its role assignments, and its history are all left exactly as they were -- disabling is fully reversible, and re-enabling restores everything.
- Every disable and re-enable shows up in the Activity log, same as any other change.
A disabled user's name renders dimmed with "(disabled)" next to it in the Users list, visible at a glance without opening anything.