Step 1: Creating and configuring the Policy Object
Step 1: Creating and configuring the Policy Object 
You can create and configure the Policy Object you need by using the New Deprovisioning Policy Object wizard. For information about the wizard, see Creating a Policy Object in the Policy Object management tasks section earlier in this chapter.
To configure the policy, click User Account Permanent Deletion on the Select Policy Type page of the wizard. Then, click Next.
On the Deletion Options page, click Delete the object after retention period. Then, in the box beneath that option, type 90.
When you are done, click Next and follow the instructions in the wizard to create the Policy Object.
 
    Step 2: Applying the Policy Object
Step 2: Applying the Policy Object 
You can apply the Policy Object by using the Enforce Policy page in the New Deprovisioning Policy Object wizard, or you can complete the wizard and then use the Enforce Policy command on the domain, OU, or Managed Unit where you want to apply the policy. 
For more information on how to apply a Policy Object, see Applying Policy Objects and Managing policy scope earlier in this chapter.
 
    Group Object Deprovisioning
Group object deprovisioning policy specifies the changes to make to the group object in Active Directory in order to prevent the use of the group. It is intended to perform the following tasks when deprovisioning a group:
- Hide the group from the Global Address List (GAL) to prevent access to the group from Exchange Server client applications such as Microsoft Outlook. 
- Change the type of the group from Security to Distribution to revoke access rights from the group. 
- Rename the group, to distinguish deprovisioned groups by name. 
- Remove members from the group to revoke user access to resources controlled by the group. This task has the option to specify the members that should not be removed from the group. 
In addition, the policy can be configured to change or clear any other properties of a group, such as the pre-Windows 2000 name, e-mail addresses, or description.
 
    How this policy works
When processing a request to deprovision a group, Active Roles uses this policy to modify the group object in Active Directory so that once the group has been deprovisioned it cannot be used.
A policy can also be configured to update individual properties of groups. Depending on the policy configuration, each policy-based update results in the following:
- Certain portions of group information, such as information about group members, are removed from the directory. 
- Certain properties of groups are changed or cleared. 
A policy can be configured so that new property values include:
- Properties of the group being deprovisioned, retrieved from the directory prior to starting the process of the group deprovisioning 
- Properties of the user who originated the deprovisioning request 
- Date and time when the group was deprovisioned 
Thus, when deprovisioning a group, Active Roles modifies the group object in Active Directory as determined by the Group Object Deprovisioning policy that is in effect.