After disabling the users on O365 i found that users can still accepting mails so how i can solve this problem?
Hi @ahmed119 ,
can you please give us insight on how you are removing 0365 group ?
Thank you.
based on RBAC all the existing groups should be removed.
Have you cross-checked with the target application whether the group is actually getting removed? Also verify if the user still has a role assigned, because sometimes the RBAC criteria might be configured incorrectly.
check the log details on iq-service and what details you getting for the request.
Disabling the user is not makes the mailbox inaccessible. Ensure the license group is removed.
Please clarify when you say the user’s still accepting the mails, does it mean the user still access their mailbox or user couldn’t access, and their mailbox still accepting the mails?
If it is a first case of my question, please ensure both the O365 account is disabled, and license group is revoked. Also ensure that no other external process which may assign the license back to the user, aggregate the account after the RBAC role is revoked and ensure the license group is not assigned. Also, the user’s active sessions will not be terminated immediately, and you may also check that it terminates the sessions when the account disabled.
If it is a later case, then it may be due to the mailbox is converted to shared mailbox or mailbox delegation (anyway it requires license) where it can be access by other persons such as manager’s, all based on company policies, so ensure no other license assigned process outside the SailPoint workflow.
Please follow below steps to fix the issue. you can share workflow to see the issue detailly
====================
- Disable Azure AD account
- Remove O365 groups
- remove mailbox
- Revoke licenses
- Archive mailbox if needed
add one more condition in rbac role like if cloud life cycle state does not equal to inactive etc so it will remove that rbac role and license will get revoked and they will not get access