Suspend | Office 365 User and Guest rule (legacy)
IMPORTANT: Starting from the version 10.3, Suspend Tool was migrated to the Cayosoft Administrator Console with significantly improved functionality. All default suspend configuration settings are now in the new Modern Suspend Configuration node.
Use the new Microsoft 365 User Suspend configuration instead.
Rule description
This rule provides suspension possibility for Microsoft 365 users and Guests.
IMPORTANT: Microsoft 365 license is required (including an Exchange license) for Microsoft 365 user account in order for all settings in this rule to work properly.
An instance of the rule is automatically created during installation under RULES > WebAdmin Rules (Pre-configured) folder. This instance is linked to the Suspend user web action (Office 365)web action and to AD Users | Suspend Expired AD Users (Legacy), AD Users | Suspend rule, and other rules as a post-action rule in the Rules to run after section.
NOTE: On-Premises Exchange Attributes must be present in the Active Directory for future license revocation to work.
NOTE: This rule also supports mapping between the Active Directory user account and the Cloud user account by anchor attributes. For details, please see the How to map Active Directory users to Office 365 cloud users article.
When to use this rule
You typically do not need to create an instance of this rule, as it is automatically created during installation and linked to the Suspend (AD and Microsoft 365) and rules, listed above. The rule is executed when you perform Suspend on Microsoft 365 user account or Suspend\Scheduled Suspend action on Active Directory user accounts if they have corresponding Microsoft 365 user accounts.
When you perform Suspend action for an Active Directory user account and also need to suspend the corresponding Microsoft 365 account, you need to set the Suspend related Office 365 user option to Yes. You can find this option in the Suspend Active Directory user action and rules listed below:
AD Users | Process Scheduled Suspends
AD Users | Suspend Expired AD Users
AD Users | Suspend Users
Office 365 Users Inactive | Suspend Users
Text file | Suspend AD Users
Import SQL Data | Suspend AD Users
Import Oracle Data | Suspend AD Users
Rule settings
Query section
| Setting name | Description* |
|---|---|
| More options | |
Domain controller |
Select the domain controller to run the rule. |
Credentials |
Specify credentials to the selected domain controller. |
Action section
| Setting name | Description |
|---|---|
Prevent Sign-in |
Use this setting to prevent the user their access to Microsoft 365 account. |
Authentication methods and sessions |
Specify if:
|
Scramble Password |
Define whether to generate a random password for a user after suspension or not. |
Hide from GAL |
Hide a user from a Global Address List. |
Remove license, mailbox and archive mailbox |
When set to Yes, if the AD user has a remote mailbox and archive mailbox associated, both have to be removed with license removal. To preserve the user mailbox and archive mailbox data, either set this setting to No or set Convert to Shared mailbox setting to Yes. |
Assign replacement license |
If Remove license above is set to Yes, this will attempt to assign the replacement licenses listed here. Enter the SkuID of the licenses that should be assigned separated by a semicolon, e.g. NOTE: This option does not work if the Litigation Hold option is enabled for delayed license removal. |
Put mailbox on Litigation Hold |
After a mailbox is placed on litigation hold, messages can't be deleted from the mailbox. Deleted items and all versions of changed items are retained in the Recoverable Items folder. Items that are purged from the dumpster are also retained and the items are held indefinitely. If you enable litigation hold, single-item recovery quotas aren't applied. |
Litigation hold duration (days) |
Specify the number of days the mailbox items are held if the mailbox is placed on litigation hold. The duration is calculated from the date a mailbox item is received or created. |
Convert to Shared Mailbox |
IMPORTANT: Cayosoft recommends converting the user mailbox to a shared mailbox after suspending action. In this case, the mailbox data and archive data don't get lost, and it allows you to avoid errors during undo suspend operation. For information about Undo Suspend Office 365 account, please see this Undo Suspend | Office 365 User. NOTE: If a user account is converted to a shared mailbox, it must remain synced. If the Active Directory account is deleted or moved out of sync scope, then the cloud account gets deleted too. NOTE: When a linked mailbox gets suspended, the Convert to Shared mailbox step is skipped. Before running suspend for a linked mailbox be sure that Azure AD sync was run.
|
Delegates (Shared Mailbox) |
You can specify delegates who will have the access to a user mailbox after this user is suspended. For details, please see the previous setting Convert to Shared mailbox. |
Set Forward address |
|
Forward Address |
You can specify the forward address to forward emails sent to suspended users. |
AD attribute to store license remove date |
Specify Active Directory attribute to store the license removal date. |
Email Connectivity | |
|
Specify these settings to enable or disable access to the mailbox by using the corresponding protocol clients.
|
Remove Shared Mailbox permissions |
When set to Yes, shared mailbox permissions will be removed after user suspension. NOTE: This functionality works through the Cayosoft Guardian Integration extension, which needs to be configured to get per-user mailbox permissions. |
Remote Device Wipe (Exchange ActiveSync) | |
Delete all data from a mobile phone via Exchange ActiveSync |
Specify whether to wipe from a user's phone all corporate data after this user is suspended. NOTE: If you are using Intune, you should be using Intune to trigger data removal, not Exchange. Depending on the scenario, it could be accomplished via the App Protection Policy selective wipe, or Device enrollment retire/wipe commands. |
Email address for the remote device wipe confirmation (optional) |
You can specify an email address for the remote device wipe confirmation. |
Autoreply Message | |
Set Autoreply Message |
Specify whether to set an autoreply message after a user is suspended and doesn't have access to his mailbox anymore. |
Autoreply Message |
Specify autoreply message text. |
OneDrive settings | |
Change Personal Site Admin |
|
New OneDrive Personal Site owner(s) |
You can specify one or more User Principal Names separated by ";" that will be new personal site admins after a user is suspended. |
Group Membership and Ownership | |
Remove from cloud groups |
When set to Yes, the account will be removed from all Entra ID security groups, Microsoft Groups, Teams, and Distribution Lists. |
Exclude these cloud groups |
You can add group display names where the user should remain as member/owner on suspension separated by a semi-colon. Example: |
Transfer group ownership to user manager |
When set to Yes, the user manager will be added as an owner to all groups previously owned by this account. The manager account must have Teams license assigned to take ownership of a team. If the user does not have a manager, a connection account will be added as a group owner. NOTE: Transfer group ownership works only for Microsoft 365 security and unified groups. |
Output Section
This section defines the output format of this rule.
To get more information about this section, please see the Rule Output section article.
Enforce/Schedule section
This section defines the schedule for how often to run the rule.
To get more information about this section, please see the Rule Enforce/Schedule section article.
Comments
0 comments
Please sign in to leave a comment.