Office 365 - Teams/365 Groups

Groups are created in the associated systems, Active Directory Domain Services (AD DS) and Entra ID, or alternatively in other systems relevant to your organization.

Security groups, distribution lists from Exchange Online and Office 365 groups are handled in the same way in Compliance Suite. Groups can be linked to one or more roles, which means that all persons in the role become members of the group in the associated system.

You can find all active Office 365 groups in your system under "Office 365 Groups" in the "Connectors" sub-area.

15645502670236

Compliance Suite automatically imports new groups and group memberships from AD DS and Entra ID. These are updated regularly.

On each group in Compliance Suite, you can select the "Keep Access" or "Remove Access" option.

15645502670876

Keep Access: If you add users directly in the external system, the membership is imported to the group. The group now has the members from the role as well as the manually added members.

Remove Access: If you add users directly in the external system outside the role, they will be removed again by Compliance Suite. Thus, the "Remove Access" option ensures that the group only has members with the associated role.

For Office 365 groups, you can select roles for both "Owner" and "Member". To add an existing role, click on the three dots next to either "Members" or "Owners" directly on the Office 365 group and select "Add Existing Role".

15645502671260

Delayed removal of user

The field "Delay removal of persons for x minutes" is added to the following memberships (for Office 365 groups, this applies to both owners and members):

  • User group

  • Shared mailbox

  • Distribution list

  • Microsoft365 group

Example of User Group:

New Status:

  • "Plan for removal"

New field on the membership unit:

  • "Removal time"

How it works
When the access granting access to the group is removed and the group has a value in "Delay removal of persons for x minutes", the assignment status is set to "Schedule removal" and the removal time to UTC. Now plus the value of "Delay removal of persons for x minutes".
The timer function D365MembershipSchedulerFunction checks every 15 minutes if there are any memberships to be removed now. If so, the preparation status is set to "Removal" and the membership calculation continues as before.