Scenario: Removing deprovisioned users from all groups
The policy described in this scenario, removes the deprovisioned users from all groups, both security and distribution.
To implement this scenario, you must perform the following actions:
- Create and configure the Policy Object that defines the appropriate policy.
- Apply the Policy Object to a domain, OU, or Managed Unit.
As a result, when deprovisioning a user account in the container you selected in Step 2, Active Roles removes the user account from all groups.
The following two sections elaborate on the steps to implement this scenario.
Step 1: Creating and configuring the Policy Object
Step 1: Creating and configuring the Policy Object
You can create and configure the Policy Object you need by using the New Deprovisioning Policy Object wizard. For information about the wizard, see Creating a Policy Object in the Policy Object management tasks section earlier in this chapter.
To configure the policy, click Group Membership Removal on the Select Policy Type page of the wizard. Then, click Next and follow these steps:
- On the Removal from Security Groups page:
- Click Remove from all security groups, with optional exceptions.
- Verify that the Keep the user account in these security groups check box is cleared.
- Click Next.
- On the Removal from Mail-enabled Groups page:
- Click Remove from all mail-enabled groups, with optional exceptions.
- Verify that the Keep the user account in these mail-enabled groups check box is cleared.
- Click Next.
- Click Next and follow the instructions in the wizard to create the Policy Object.
Step 2: Applying the Policy Object
Step 2: Applying the Policy Object
You can apply the Policy Object by using the Enforce Policy page in the New Provisioning Policy Object wizard, or you can complete the wizard and then use the Enforce Policy command on the domain, OU, or Managed Unit where you want to apply the policy.
For more information on how to apply a Policy Object, see Applying Policy Objects and Managing policy scope earlier in this chapter.
Exchange Mailbox Deprovisioning
Policies of this category are intended to automate the following tasks on deprovisioning Microsoft Exchange resources for deprovisioned users:
- Hide deprovisioned users from address lists.
- Prevent non-delivery reports from being sent.
- Grant designated persons full access to deprovisioned mailboxes.
- Redirect e-mail addressed to deprovisioned users.
- Force the mailbox of the deprovisioned user to send automatic replies (requires Exchange 2013 or later).
When configuring a policy of this category, you specify how you want Active Roles to modify the user’s account and mailbox upon a request to deprovision a user. The purpose is to reduce the volume of e-mail sent to the mailbox of the deprovisioned user, and to authorize designated persons to monitor such e-mail.