지금 지원 담당자와 채팅
지원 담당자와 채팅

Active Roles 8.1.1 - Administration Guide

Introduction Getting started Rule-based administrative views Role-based administration
Access Templates as administrative roles Access Template management tasks Examples of use Deployment considerations Windows claims-based access rules
Rule-based autoprovisioning and deprovisioning
Provisioning Policy Objects Deprovisioning Policy Objects How Policy Objects work Policy Object management tasks Policy configuration tasks
Property Generation and Validation User Logon Name Generation Group Membership AutoProvisioning Exchange Mailbox AutoProvisioning AutoProvisioning in SaaS products OneDrive Provisioning Home Folder AutoProvisioning Script Execution Microsoft 365 and Azure Tenant Selection E-mail Alias Generation User Account Deprovisioning Office 365 Licenses Retention Group Membership Removal Exchange Mailbox Deprovisioning Home Folder Deprovisioning User Account Relocation User Account Permanent Deletion Group Object Deprovisioning Group Object Relocation Group Object Permanent Deletion Notification Distribution Report Distribution
Deployment considerations Checking for policy compliance Deprovisioning users or groups Restoring deprovisioned users or groups Container Deletion Prevention policy Picture management rules Policy extensions
Using rule-based and role-based tools for granular administration Workflows
Key workflow features and definitions About workflow processes Workflow processing overview Workflow activities overview Configuring a workflow
Creating a workflow definition for a workflow Configuring workflow start conditions Configuring workflow parameters Adding activities to a workflow Configure an Approval activity Configuring a Notification activity Configuring a Script activity Configuring an If-Else activity Configuring a Stop/Break activity Configuring an Add Report Section activity Configuring a Search activity Configuring CRUD activities Configuring a Save Object Properties activity Configuring a Modify Requested Changes activity Enabling or disabling an activity Enabling or disabling a workflow Using the initialization script
Approval workflow Email-based approval Automation workflow Activity extensions
Temporal Group Memberships Group Family Dynamic groups Active Roles Reporting Management History Entitlement profile Recycle Bin AD LDS data management One Identity Starling Join and configuration through Active Roles Managing One Identity Starling Connect Configuring linked mailboxes with Exchange Resource Forest Management Configuring remote mailboxes for on-premises users Azure AD, Microsoft 365, and Exchange Online Management
Configuring Active Roles to manage Hybrid AD objects Managing Hybrid AD users
Creating a new Azure AD user with the Web Interface Viewing or updating the Azure AD user properties with the Web Interface Viewing or modifying the manager of a hybrid Azure user Disabling an Azure AD user Enabling an Azure AD user Deprovisioning of an Azure AD user Undo deprovisioning of an Azure AD user Adding an Azure AD user to a group Removing an Azure AD user from a group View the change history and user activity for an Azure AD user Deleting an Azure AD user with the Web Interface Creating a new hybrid Azure user with the Active Roles Web Interface Converting an on-premises user with an Exchange mailbox to a hybrid Azure user Licensing a hybrid Azure user for an Exchange Online mailbox Viewing or modifying the Exchange Online properties of a hybrid Azure user Creating a new Azure AD user with Management Shell Updating the Azure AD user properties with the Management Shell Viewing the Azure AD user properties with the Management Shell Delete an Azure AD user with the Management Shell Assigning Microsoft 365 licenses to new hybrid users Assigning Microsoft 365 licenses to existing hybrid users Modifying or removing Microsoft 365 licenses assigned to hybrid users Updating Microsoft 365 licenses display names
Unified provisioning policy for Azure M365 Tenant Selection, Microsoft 365 License Selection, Microsoft 365 Roles Selection, and OneDrive provisioning Microsoft 365 roles management for hybrid environment users Managing Microsoft 365 contacts Managing Hybrid AD groups Managing Microsoft 365 Groups Managing cloud-only distribution groups Managing cloud-only dynamic distribution groups Managing Azure security groups Managing cloud-only Azure users Managing cloud-only Azure guest users Managing cloud-only Azure contacts Changes to Active Roles policies for cloud-only Azure objects Managing room mailboxes Managing cloud-only shared mailboxes
Modern Authentication Managing the configuration of Active Roles
Connecting to the Administration Service Managed domains Using unmanaged domains Evaluating product usage Creating and using virtual attributes Examining client sessions Monitoring performance Customizing the Console Using Configuration Center Changing the Active Roles Admin account Enabling or disabling diagnostic logs Active Roles Log Viewer
SQL Server replication Using regular expressions Administrative Template Communication ports Active Roles and supported Azure environments Integrating Active Roles with other products and services Active Roles Language Pack Active Roles Diagnostic Tools Active Roles Add-on Manager

Policy report items

This topic lists the Change History report items specific to the polices that are applied by using Policy Objects in Active Roles. When running a given policy, Active Roles adds a report section to describe the actions performed by that policy. The report section identifies the policy category and the Policy Object containing the policy, and informs about success or failure of the policy action.

The following tables list the possible report items, one table per section. The items in each section describe the results of the actions that were taken in accordance with the respective policy. Report items also inform about success or failure of the policy action. In the event of a failure, the report item includes an error description.

Not all the listed items must necessarily be present in a report. An actual report only includes the report items corresponding to the policies that Active Roles performed when processing the operation request.

NOTE: This topic covers the Active Roles provisioning policies. The report sections specific to deprovisioning policies are listed in the Report on deprovisioning results and Report on results of undo deprovisioning.

Policy report sections

User Logon Name Generation policy
Table 66: User Logon Name Generation policy

Report Item (Success)

Report Item (Failure)

The user logon name (pre-Windows 2000) is set to value.

Not applicable

E-mail Alias Generation policy
Table 67: E-mail Alias Generation policy

Report Item (Success)

Report Item (Failure)

The e-mail alias is set to alias.

Not applicable

Property Alias (mailNickName) is removed from the operation request as no Exchange tasks were requested.

Not applicable

Exchange Mailbox AutoProvisioning policy
Table 68: Exchange Mailbox AutoProvisioning policy

Report Item (Success)

Report Item (Failure)

The mailbox database is set to database name.

Not applicable

The option to create the mailbox is selected by default.

Not applicable

The option to create the mailbox is not selected by default.

Not applicable

Changing the option to create the mailbox is allowed.

Not applicable

Changing the option to create the mailbox is not allowed.

Not applicable

Group Membership AutoProvisioning policy
Table 69: Group Membership AutoProvisioning policy

Report Item (Success)

Report Item (Failure)

The object is added to the following groups.

  • List: Group names

Unable to add the object to the following groups.

  • List: Group names and error description

The object is not added to the following groups as it is already a member of those groups.

  • List: Group names

Not applicable

The object is removed from the following groups.

  • List: Group names

Unable to remove the object from the following groups.

  • List: Group names and error description

The object is not removed from the following groups as it is not a member of those groups.

  • List: Group names

Not applicable

Home Folder AutoProvisioning policy
Table 70: Home Folder AutoProvisioning policy

Report Item (Success)

Report Item (Failure)

The home folder is mapped to letter letter and connected to path UNC path in Active Directory.

Not applicable

Home folder name is to be created on the file server.

Not applicable

Home folder name is created on the file server.

Unable to create home folder {0} on the file server.

Details: Error description

User permissions on the home folder are set by copying permissions from the parent folder.

Unable to set user permissions on home folder name on the file server.

Details: Error description

The home folder user is set as the owner of the home folder.

Unable to set user permissions on home folder name on the file server.

Details: Error description

User permission option Grant Change Access is applied to the home folder.

Unable to set user permissions on home folder name on the file server.

Details: Error description

User permission option Grant Full Access is applied to the home folder.

Unable to set user permissions on home folder name on the file server.

Details: Error description

Home folder name is to be renamed to name on the file server.

Not applicable

Home folder name is renamed to name on the file server.

Unable to rename home folder name to name on the file server.

Details: Error description

Home share name is to be created on the file server.

Not applicable

Home share name is created on the file server.

Unable to create home share name on the file server.

Details: Error description

The user limit is set to allow no more than name users to connect to the home share at a time.

Not applicable

The user limit is set to allow the maximum number of users to connect to the home share at a time.

Not applicable

Property Generation and Validation policy
Table 71: Property Generation and Validation policy

Report Item (Success)

Report Item (Failure)

Property name is set to value.

Not applicable

Property name is removed (cleared).

Not applicable

Running policy script <name>
Table 72: Policy script <name>

Report Item (Success)

Report Item (Failure)

Policy script <name> completed successfully.

  • Error message returned by the policy

    Details: Error description

The default error message reads as follows:

  • The Script Execution policy encountered an error when running the script name.

    Details: Error description

Active Roles internal policy report items

The Active Roles internal policies are mainly intended to perform Exchange recipient management tasks, such as the task of creating a mailbox or the task of establishing an email address for a group. These policies are triggered by Active Roles’ internal logic, and cannot be configured by the administrator. Active Roles performs its internal policies as appropriate to the given operation request. For example, when processing a request to create a mailbox-enabled user account, Active Roles triggers an internal policy that carries out all the actions needed to create the user mailbox on the Exchange Server.

The following tables list the possible report items, one table per report section. The items in each section describe the results of the actions that were taken in accord with the respective internal policy. Report items also inform about success or failure of the policy action. In the event of a failure, the report item includes an error description.

Not all the listed items must necessarily be present in a report. An actual report only includes the report items corresponding to the policies that Active Roles performed when processing the operation request.

Active Roles internal policy report sections

Creating user mailbox
Table 73: Creating user mailbox

Report Item (Success)

Report Item (Failure)

User mailbox name is created.

Unable to create user mailbox name.

Details: Error description

Legacy mailbox name is created.

Unable to create legacy mailbox name.

Details: Error description

Mailbox alias is set to alias.

Not applicable

Mailbox database is set to database name.

Not applicable

The following mailbox properties are set.

List: Property names and values

Unable to set the following properties of the mailbox.

List: Property names and error description

Creating linked mailbox
Table 74: Creating linked mailbox

Report Item (Success)

Report Item (Failure)

Linked mailbox name is created.

Unable to create linked mailbox name.

Details: Error description

Legacy mailbox name is created.

Unable to create legacy mailbox 'name'.

Details: Error description

Mailbox alias is set to alias.

Not applicable

Mailbox database is set to database name.

Not applicable

The mailbox is linked to external account name.

Not applicable

The following mailbox properties are set.

List: Property names and values

Unable to set the following properties of the mailbox.

List: Property names and error description

Creating equipment mailbox
Table 75: Creating equipment mailbox

Report Item (Success)

Report Item (Failure)

Equipment mailbox name is created.

Unable to create equipment mailbox name.

Details: Error description

Mailbox alias is set to alias.

Not applicable

Mailbox database is set to database name.

Not applicable

The following mailbox properties are set.

List: Property names and values

Unable to set the following properties of the mailbox.

List: Property names and error descriptions

Report section: Creating room mailbox
Table 76: Creating room mailbox

Report Item (Success)

Report Item (Failure)

Room mailbox name is created.

Unable to create room mailbox name.

Details: Error description

Mailbox alias is set to alias.

Not applicable

Mailbox database is set to database name.

Not applicable

The following mailbox properties are set.

List: Property names and values

Unable to set the following properties of the mailbox.

List: Property names and error descriptions

Creating shared mailbox
Table 77: Creating shared mailbox

Report Item (Success)

Report Item (Failure)

Shared mailbox name is created.

Unable to create shared mailbox name.

Details: Error description

Mailbox alias is set to alias.

Not applicable

Mailbox database is set to database name.

Not applicable

Shared mailbox is configured to allow the following users to use this mailbox.

List: User names

Not applicable

The following mailbox properties are set.

List: Property names and values

Unable to set the following properties of the mailbox.

List: Property names and error description

Moving mailbox
Table 78: Moving mailbox

Report Item (Success)

Report Item (Failure)

The following items apply to mailbox move operation on Exchange 2013 or later

The mailbox move request for mailbox name is created.

Unable to create the mailbox move request for mailbox name.

Details: Error description

The mailbox is being moved from database database name to database database name.

Not applicable

Deleting mailbox
Table 79: Deleting mailbox

Report Item (Success)

Report Item (Failure)

Mailbox name is deleted.

Not applicable

Removing Exchange attributes
Table 80: Removing Exchange attributes

Report Item (Success)

Report Item (Failure)

The following Exchange attributes are removed from name.

List: Attribute names

Not applicable

Enabling mailbox for Unified Messaging
Table 81: Enabling mailbox for Unified Messaging

Report Item (Success)

Report Item (Failure)

Mailbox name is enabled for Unified Messaging.

Not applicable

The following Unified Messaging mailbox policy is assigned to the mailbox: policy name

Not applicable

The following Unified Messaging mailbox properties are set.

List: Property names and values

Not applicable

Disabling Unified Messaging for mailbox
Table 82: Disabling Unified Messaging for mailbox

Report Item (Success)

Report Item (Failure)

Unified Messaging is disabled for mailbox name.

Not applicable

Resetting Unified Messaging PIN
Table 83: Resetting Unified Messaging PIN

Report Item (Success)

Report Item (Failure)

The Unified Messaging PIN is reset for mailbox name.

Not applicable

Establishing email address for group
Table 84: Establishing email address for group

Report Item (Success)

Report Item (Failure)

An e-mail address is established for group name. The group is now mail-enabled.

Unable to establish an e-mail address for group name.

Details: Error description

E-mail alias is set to alias.

Not applicable

The following properties of the group are set.

List: Property names and values

Not applicable

Creating query-based distribution group
Table 85: Creating query-based distribution group

Report Item (Success)

Report Item (Failure)

Query-based Distribution Group name is created.

Unable to configure Query-based Distribution Group name.

Details: Error description

E-mail alias is set to alias.

Not applicable

The following properties of the group are set.

List: Property names and values

Not applicable

Establishing e-mail address for user
Table 86: Establishing e-mail address for user

Report Item (Success)

Report Item (Failure)

An e-mail address is established for user name. The user is now mail-enabled.

Unable to establish an e-mail address for user name.

Details: Error description

E-mail alias is set to alias.

Not applicable

The following properties of the user account are set.

List: Property names and values

Not applicable

Establishing e-mail address for contact
Table 87: Establishing e-mail address for contact

Report Item (Success)

Report Item (Failure)

An e-email address is established for contact name. The contact is now mail-enabled.

Unable to establish an e-mail address for contact name.

Details: Error description

E-mail alias is set to alias.

Not applicable

The following properties of the contact are set.

List: Property names and values

Not applicable

Deleting e-mail address for group
Table 88: Deleting e-mail address for group

Report Item (Success)

Report Item (Failure)

The e-mail address for group name is deleted. The group is no longer mail-enabled.

Not applicable

Deleting e-mail address for user
Table 89: Deleting e-mail address for user

Report Item (Success)

Report Item (Failure)

The e-mail address for user name is deleted. The user is no longer mail-enabled.

Not applicable

Deleting e-mail address for contact
Table 90: Deleting e-mail address for contact

Report Item (Success)

Report Item (Failure)

The e-mail address for contact name is deleted. The contact is no longer mail-enabled.

Not applicable

Converting user mailbox to linked mailbox
Table 91: Converting user mailbox to linked mailbox

Report Item (Success)

Report Item (Failure)

User mailbox name is converted to a linked mailbox.

Not applicable

The mailbox is linked to external account name.

Not applicable

Converting linked mailbox to user mailbox
Table 92: Converting linked mailbox to user mailbox

Report Item (Success)

Report Item (Failure)

Linked mailbox name is converted to a user mailbox.

Not applicable

The mailbox is un-linked from external account name. The external account can no longer access the mailbox.

Not applicable

관련 문서

The document was helpful.

평가 결과 선택

I easily found the information I needed.

평가 결과 선택