Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

Best practice for when a user leaves the company concerning their achive.

Created: 09 Sep 2010 | 10 comments
burtos's picture
0 0 Votes
Login to vote

Just like to know is their a guide as to when a user leaves a company.  In what to do when they do leave.

As i would like to archive all their emails off and than remove them from the provisioning group that they are in.  But still access their emails in the future if required.

Comments

Mohawk Marvin's picture
09
Sep
2010
1 Vote +1
Login to vote

Please see below for

Please see below for instructions on creating a new Mailbox policy for archiving all items on a 0 day policy(Leavers Policy) in targeted users mailboxes once they have left the company.

 

Normally it is best practice to create a separate policy for people who have left the company and have a different Provisioning Group which targets Leavers OU/Users. Please see the following steps:

1.       Create Leavers policy with Archiving rule set to archive items older than 0days

2.       Create Leavers provisioning group

3.       Run the Provisioning Task in Normal mode

4.       Run Auto archiving manually or leave the Auto archiving to happen at the scheduled time.

 

See below for screenshots on the steps you need to take.

Log on EV server and open Admin console, navigate to Targets->Exchange->right click and select Display Policies assigned to Mailboxes

 

image001.png@01C9974F.23536BD0

 

Please type in the display name for the user’s mailbox that has left the company and click find

 

Now create new Exchange Mailbox policy and configure the setting as desired with archiving rules set to archive items older than 0 days 

image003.png@01C9974F.23536BD0

 

Please make sure the correct Message classes have been checked and click OK

 

image004.png@01C9974F.23536BD0

 

Next step is creating a new Provisioning Group, Navigate to Targets->Exchange ->Domain -> Provisioning Group -> ‘right click’ New and add the user/Group as a Target,

 

 

If it is for more than one user you can add a group or OU as a Target. Once the new Provisioning group has been created. The new Provisioning group will be lower in ranking and it needs to be moved up, please right click the Provisioning Group Folder ‘right click’ properties and move the Leavers policy up.

 

 

image006.png@01C9974F.23536BD0

 

image007.png@01C9974F.23536BD0

 

After moving the Provisioning group higher on the ranking, run the provisioning Task in Normal mode and check the policy assigned to the mailbox after provisioning task has finished processing the mailboxes. 

image001.png@01C9974F.23536BD0

 

Once the correct policy has been assigned to the user’s mailbox, you can do a Run Now to archive all items immediately or wait for the scheduled archiving task to run and archive the items as part of its run. Once all items have been archived from the user’s mailbox, please disable the user’s mailbox from archiving. For more details please refer to Symantec KB article: http://seer.entsupport.symantec.com/docs/316843.htm

 

If the users who have left the company are not archive enabled, target them in the Leavers Provisioning Group, and archive enable them. When the archiving Task would run overnight all emails will be archived for the user’s as they are assigned Leavers Policy.

Batmanfail's picture
09
Sep
2010
0 Votes 0
Login to vote

3361 & 3172

"i would like to archive all their emails off and than remove them from the provisioning group that they are in.  But still access their emails in the future if required."

If you don't disable a user for archiving properly (either via the "Disable mailboxes for archiving" wizard in the VAC or EVPM) then you will constantly recieve events 3361 & 3172 in your EV event logs on your server when the provisioning task runs. 

Do as Mohawk says, then once you know all is archived, use the "Disable mailboxes for archiving" wizard in the VAC or EVPM to disable them properly.   If you logon to the mailbox they will still have the Search and AE buttons available.  If you want rid of those buttons too then ZAP the hidden message with EVPM.   As long as you give yourself "Manually set" permissions to the archive (via the VAC) then you can access their archive from your Search pages etc.

Over and Out

BTW I am no longer lesbian! I have failed.... 

Mohawk Marvin's picture
09
Sep
2010
0 Votes 0
Login to vote

If you delete the mailbox you

If you delete the mailbox you could still access the archived items via Search and Archive Explorer

burtos's picture
09
Sep
2010
0 Votes 0
Login to vote

Does the user accunt need to

Does the user accunt need to be enabled for this to work , as i have them disabled at the moment in Active Directory

burtos's picture
09
Sep
2010
0 Votes 0
Login to vote

Once the correct policy has

Once the correct policy has been assigned to the user’s mailbox

How can i check this is so

Mohawk Marvin's picture
09
Sep
2010
0 Votes 0
Login to vote

Display policies assigned to

Display policies assigned to user(s)

Log on EV server and open Admin console, navigate to Targets->Exchange->right click and select Display Policies assigned to Mailboxes

image001.png@01C9974F.23536BD0

Archiving from disabled mailboxes is possible a quick forum or KB search will yield the desired results

Batmanfail's picture
09
Sep
2010
0 Votes 0
Login to vote

Disabled user accounts

The user's AD account must not be disabled as EV does not archive from disabled AD accounts (by default), unless of course one of the following registry values has been set ;)

Disabled Mailboxes
http://seer.entsupport.symantec.com/docs/336978.htm

 

BTW I am no longer lesbian! I have failed.... 

burtos's picture
09
Sep
2010
0 Votes 0
Login to vote

Also have done this now, so

Also have done this now, so shall wait until it does its archiving and see the results

Log on EV server and open Admin console, navigate to Targets->Exchange->right click and select Display Policies assigned to Mailboxes

i have this set as in the document already.

Disabled Mailboxes
http://seer.entsupport.symantec.com/docs/336978.htm

burtos's picture
09
Sep
2010
0 Votes 0
Login to vote

5. Perform a manual "Run now"

5. Perform a manual "Run now" of the Mailbox Archiving Task for the Specified User.
- Under Tasks, right-click the Mailbox archiving task for the user(s)
- Select Run Now
- Run the Task against "Select mailboxes" and "Archive all items".
- Select Ok and select the user(s) to run the task against.

When i try to select the individual mailbox, they arent in the list

Mohawk Marvin's picture
09
Sep
2010
0 Votes 0
Login to vote

Is the user enabled for

Is the user enabled for archiving?