Versions Compared

Key

  • This line was added.
  • This line was removed.
  • Formatting was changed.

...

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

Can they still authenticate using Enterprise Authentication?

(Enterprise Authentication is backed by Austin Active Directory.)

abcxyzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzzz. Consider 2FA (Duo) as well………………………….

...

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

Are they automatically removed from groups?

Users are not automatically removed from groups when they leave the University, even when their Active Directory account is disabled.

For the most part, groups in the Austin Active Directory are owned and managed by the Department that created them. Departments are responsible for maintaining the memberships of their groups, removing any members that are no longer necessary.
A user may need to be removed from a group if:

  • They are no longer at the University

  • They remain at the University but no longer fall under the intended scope of the group (for example, an employee who leaves your department and is still a current employee working for another department should be removed from groups that give them access to your department’s resources)

If they are still in an email distribution group, will they continue to get emails addressed to the group?

As long as they still have a M365 mailbox, they will receive emails addressed to any email distribution groups they are a member of.

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7
Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

How are group memberships managed?

If a group is located in a Departmental OU, its members can be managed by the Department’s Administrators using native tools (the Active Directory Users and Computers console, Active Directory Administrative Center, PowerShell). Others may have the necessary permissions to edit group memberships based on delegations and the group’s Managed By configuration.

If a group was created in the Department Group Tools OR its Managed By attribute is set along with the Manager can update membership list checkbox checked, its memberships can be managed in the Department Group Tools (📑 Documentation).

For email Distribution Groups, the Distribution List’s Managers can add/remove members using the Office 365 Management : My Services portal (📑 Documentation)
A department’s M365 Managers can also manage the membership of Distribution Lists using the Office 365 Management : My Users portal zzz (📑 Documentation)

Q

A
Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

If they are still in an email distribution group, will they continue to get emails addressed to the group?

As long as they still have a M365 mailbox, they will receive emails addressed to any email distribution groups they are a member of.

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

What happens if they were a Department OU Owner?

At this time, no action is automatically taken to remove them as owners. Another Department OU Owner should remove them using the Department User Tools (📑 Documentation).

Audit reports are emailed to Department OU owners monthly. One of the items that appear in this audit is ineligible owners that should be removed.

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

Q

A

...

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

How are departmental accounts managed?

Department OU Owners can manage their departmental accounts using the Department User Tools (📑 Documentation).

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

Q

A

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

What about Service Accounts?

Service accounts can be assigned to more than one person at a time (although they can only be claimed by one person at a time).
When an assignee has left the University, a Department OU Owner should remove them from the list of assignees of their service accounts. This prevents them from having control over these service accounts if they ever do return to the University (a former employee in your department may later return as an employee in another department or a student).

Panel
panelIconIdatlassian-question_mark
panelIcon:question_mark:
panelIconText:question_mark:
bgColor#F4F5F7

How are departmental accounts managed?

Department OU Owners can manage their departmental accounts using the Department User Tools (📑 Documentation).