You can use the Active Roles Web Interface to create and view and modify the Exchange Online properties of the new cloud-only Azure Contacts.
To view the Exchange Online properties of a cloud-only Azure Contacts
- On the Active Roles Web Interface navigation bar, click Directory Management.
-
On the Views tab in the Browse pane, click Azure > <Azure tenant> > Azure Contacts.
The Azure Contacts page is displayed and lists the Azure cloud-only contacts available in Azure.
-
Select the specific cloud-only Azure contacts for which you want to view the properties.
-
In the Command pane, click Exchange Online Properties.
The Exchange Online Properties wizard displays the following Exchange Online properties for the cloud-only Azure contact.
-
Use the tabs in the Exchange Online Properties dialog to view the following Exchange Online properties of the cloud-only Azure contact:
-
General
In the Alias field, enter an Exchange Online alias name. You can also choose to hide the alias name from the organizational address list.
-
Mail tip
In the Mail tip text field, enter an optional mail tip.
NOTE: When creating a new cloud-only Azure contact or updating an existing one, it may take up to 15 minutes for the changes to appear on the Active Roles Web Interface. This is due to a replication delay present between PowerShell and the Microsoft Graph API.
You can use the Active Roles Web Interface to view the change history and user activity for cloud only Azure contacts.
To view the change history and user activity of cloud only Azure contacts
- On the Active Roles Web Interface navigation bar, click Directory Management.
-
On the Views tab in the Browse pane, click Active Directory.
The list of Active Directory domains is displayed.
-
To view the history, select the Azure contact.
-
In the Command pane, click Change History or User Activity.
The information on changes that were made to the contact through Active Roles is displayed.
You can use the Active Roles Web Interface to delete an Azure contact.
To delete an Azure contact
- On the Active Roles Web Interface navigation bar, click Directory Management.
-
On the Views tab in the Browse pane, click Azure > <Azure tenant> > Azure Contacts.
The Azure Contacts page is displayed and lists the Azure cloud-only contacts available in Azure.
-
Select the Azure contact that you want to delete.
-
In the Command pane, click Delete.
A message prompts you to confirm the action.
-
Click Yes to continue.
The Azure contacts that you have selected are deleted.
Active Roles 7.4.4 introduced support for cloud-only Azure objects: Azure users, guest users and contacts. To support the management of these cloud-only Azure objects, the existing Active Roles policies received the following updates:
-
The Property Generation and Validation policy now supports specifying object property rules for cloud-only Azure objects. To get started with provisioning cloud-only Azure properties, Active Roles contains a new built-in policy for provisioning cloud-only Azure properties. Find the policy in the following node of the Active Roles MMC console:
Configuration > Policies > Administration > BuiltIn > Azure CloudOnly Policy - Default Rules to Generate Properties
-
The Group Membership AutoProvisioning policy now supports specifying group membership rules to automatically assign (or unassign) cloud-only Azure users and guest users to (or from) O365 Groups located in the same Azure tenant as the provisioned Azure objects.
In the New Provisioning Policy Wizard of the Active Roles MMC console, the cloud-only Azure objects supported for provisioning are listed in the Object Type Selection > Select Object Type dialog, while the O365 Groups can be selected in the Group Selection > Browse for Container dialog.
-
Script Execution policies now also support PowerShell and other custom scripts for provisioning cloud-only Azure objects. As part of this change, Active Roles contains a new built-in script module that you can use to configure policies for generating cloud-only Azure user passwords complying with Azure AD password generation policies. This built-in script module is available at the following node of the Active Roles MMC console:
Configuration > Script Modules > BuiltIn > Generate User Password - Azure only