Changes to Active Roles policies for cloud-only Azure objects
Active Roles 7.4.4 introduced support for cloud-only Azure objects: Azure users, guest users and contacts. To support the management of these cloud-only Azure objects, the existing Active Roles policies received the following updates:
-
The Property Generation and Validation policy now supports specifying object property rules for cloud-only Azure objects. To get started with provisioning cloud-only Azure properties, Active Roles contains a new built-in policy for provisioning cloud-only Azure properties. Find the policy in the following node of the Active Roles MMC console:
Configuration > Policies > Administration > BuiltIn > Azure CloudOnly Policy - Default Rules to Generate Properties
-
The Group Membership AutoProvisioning policy now supports specifying group membership rules to automatically assign (or unassign) cloud-only Azure users and guest users to (or from) O365 Groups located in the same Azure tenant as the provisioned Azure objects.
In the New Provisioning Policy Wizard of the Active Roles MMC console, the cloud-only Azure objects supported for provisioning are listed in the Object Type Selection > Select Object Type dialog, while the O365 Groups can be selected in the Group Selection > Browse for Container dialog.
-
Script Execution policies now also support PowerShell and other custom scripts for provisioning cloud-only Azure objects. As part of this change, Active Roles contains a new built-in script module that you can use to configure policies for generating cloud-only Azure user passwords complying with Azure AD password generation policies. This built-in script module is available at the following node of the Active Roles MMC console:
Configuration > Script Modules > BuiltIn > Generate User Password - Azure only
Managing room mailboxes
Room mailbox is a type of Exchange Online resource mailbox assigned to a physical location, such as a meeting room. Using room mailboxes that an administrator creates, users can reserve rooms by adding room mailboxes to meeting requests as an attendee or location.
In the Active Roles Web Interface, you can create, manage or delete room mailboxes in Directory Management > Tree> Azure > Resource Mailboxes. Room mailboxes created in the Active Roles Web Interface are synchronized to the Exchange admin center (admin.exchange.microsoft.com), where you can find them in Home > Resources.
For more information about room mailboxes, see Manage resource mailboxes in Exchange Online in the Microsoft Exchange Online documentation.
Creating a new room mailbox
To create a new room mailbox in the Active Roles Web Interface, follow the steps.
To create a new room mailbox
-
In the Active Roles Web Interface, navigate to Directory Management > Tree> Azure > Resource Mailboxes.
The list of resource mailboxes of the selected tenant is displayed.
Figure 139: Directory Management > Tree View > Azure > Resource Mailboxes — Listing the resource mailboxes in the tenant
-
In the right pane, click Create New Room Mailbox.
The Create New Room Mailbox window opens.
-
On the General tab, set the following general details of the room:
-
(Optional) Display name
-
Name: Enter a name for the room.
NOTE: If you enter a name that is already used, you will receive an error message and Exchange Online will not allow you creating the new room mailbox. To create a new room mailbox, enter a different name.
NOTE: To change the name of an existing room mailbox:
-
In the right pane, click Rename.
-
Display name: Enter a new display name for the room.
-
Name: Enter a new name for the room.
-
Click Finish.
-
(Optional) Primary SMTP Address (leave blank for default value)
To specify the domain, use the drop-down.
The default value of the Primary SMTP Address is the name and the domain name of the room mailbox. For example, roommailbox1@activeroles.onmicrosoft.com, where roommailbox1 is the name and activeroles.onmicrosoft.com is the domain name.
-
(Optional) Capacity
-
(Optional) Hide from global address lists
Select this check box if you do not want the room mailbox to appear in the address book and other address lists defined in your Exchange organization.
By default, this check box is not selected.
-
(Optional) On the Calendar Processing tab, set the following optional details of the room:
-
Maximum duration (hours)
-
Booking window (days)
-
Allow repeating meetings
By default, this check box is selected.
-
Allow scheduling only during work hours
By default, this check box is selected.
-
(Optional) On the Location tab, set the following optional details of the company:
-
Click Finish.
If the operation is successful, the newly-created room mailbox appears in the list of Resource Mailboxes.
In the right pane, the name of the room mailbox appears with the following available actions:
-
Room Mailbox Properties
-
Rename
-
Delete
The newly-created room mailbox also appears in the Exchange admin center, in Home > Resources.
Viewing or modifying a room mailbox
To view or modify the properties of a room mailbox in the Active Roles Web Interface, follow the steps.
NOTE: To change the name of an existing room mailbox:
-
In the right pane, click Rename.
-
Display name: Enter a new display name for the room.
-
Name: Enter a new name for the room.
-
Click Finish.
To view or modify the properties of a room mailbox
-
In the Active Roles Web Interface, navigate to Directory Management > Tree> Azure > Resource Mailboxes.
The list of resource mailboxes of the selected tenant is displayed.
Figure 140: Directory Management > Tree View > Azure > Resource Mailboxes — Listing the resource mailboxes in the tenant
-
Select the room mailbox you want to view or modify.
In the right pane, the name of the room mailbox appears with the following available actions:
-
Room Mailbox Properties
-
Rename
-
Delete
-
In the right pane, click Room Mailbox Properties.
The Room Mailbox Properties window opens.
-
On the General tab, view or modify the following general details of the room:
-
Display name
-
Object GUID: The Exchange Online GUID of the mailbox object in the Exchange Cloud. You cannot modify this value.
-
External directory ID: The Azure Active Directory (AD) object of the user object connected to the mailbox object in Azure AD. You cannot modify this value.
-
User Principal Name: The room mailbox address in User Principal Name (UPN) format. You cannot modify this value.
-
Primary SMTP Address: You cannot modify this value.
-
Capacity
-
Hide from global address lists
Select this check box if you do not want the room mailbox to appear in the address book and other address lists defined in your Exchange organization.
By default, this check box is not selected.
-
On the Calendar Processing tab, view or modify the following optional details of the room:
-
Maximum duration (hours)
-
Booking window (days)
-
Allow repeating meetings
By default, this check box is selected.
-
Allow scheduling only during work hours
By default, this check box is selected.
-
On the Location tab, view or modify the following optional details of the company:
-
To close the Room Mailbox Properties window:
-
To update the properties of the room mailbox, click Save.
-
To close the window without saving the changes, click Cancel.
If the operation is successful, the updated properties of the room mailbox appear both in the Active Roles Web Interface and in the Exchange admin center.