Remove Office 365 Pro Plus Remotely from Personal Device After Employment Ends

%3CLINGO-SUB%20id%3D%22lingo-sub-829020%22%20slang%3D%22en-US%22%3ERemove%20Office%20365%20Pro%20Plus%20Remotely%20from%20Personal%20Device%20After%20Employment%20Ends%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-829020%22%20slang%3D%22en-US%22%3E%3CP%3EWith%20Office%20365%20Pro%20Plus%20and%20the%20E3%20license%2C%20we%20are%20able%20to%20deploy%205%20copies%20of%20the%20Pro%20Plus%20suite.%20This%20includes%20personal%20device.%20Once%20employment%20ends%2C%20how%20do%20we%20go%20about%20removing%20the%20Pro%20Plus%20suite%20from%20someone's%20personal%20device%20so%20they%20cannot%20access%20any%20corporate%20data%20that%20might%20be%20downloaded%20to%20their%20system%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAn%20example%20would%20be%20someone%20is%20using%20the%20Outlook%20desktop%20app%20from%20their%20personal%20device%20and%20they%20leave%20the%20company.%20They%20would%20still%20have%20access%20to%20those%20files.%20Another%20example%20would%20be%20someone%20is%20working%20on%20a%20spreadsheet%20from%20their%20device%20vs.%20from%20OneDrive%20or%20SharePoint.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20do%20we%20as%20M365%20admins%20protect%20the%20corporate%20data%20and%20retrieve%20it%20from%20a%20personal%20device%3F%20How%20do%20we%20stop%20that%20employee%20from%20downloading%20it%20to%20their%20personal%20device%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-829020%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20Apps%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EProPlus%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-829333%22%20slang%3D%22en-US%22%3ERe%3A%20Remove%20Office%20365%20Pro%20Plus%20Remotely%20from%20Personal%20Device%20After%20Employment%20Ends%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-829333%22%20slang%3D%22en-US%22%3E%3CP%3EAfter%20the%20user%20is%20terminated%20and%20the%20account%20disabled%2Fremoved%2C%20he%20cannot%20activate%20Office%20anymore%2C%20so%20he%20will%20not%20be%20able%20to%20add%20to%20the%20numbers%20of%20active%20installs.%20For%20users%20that%20are%20still%20active%2C%20you%20can%20go%20to%20the%20O365%20admin%20portal%2C%20select%20the%20user%20and%20manage%20the%20office%20installs%20from%20there%20(remove%20devices%20that%20you%20don't%20recognize).%20Unfortunately%2C%20there%20is%20no%20programmatic%20way%20to%20do%20this%2C%20despite%20of%20us%20asking%20Microsoft%20for%20years...%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EIf%20you%20want%20to%20tightly%20control%20who%20can%20install%20where%2C%20you%20will%20have%20to%20use%20some%20MDM%20solution%20(Intune)%20or%20disable%20the%20download%20altogether.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-829347%22%20slang%3D%22en-US%22%3ERe%3A%20Remove%20Office%20365%20Pro%20Plus%20Remotely%20from%20Personal%20Device%20After%20Employment%20Ends%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-829347%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3EVery%20true%20that%20they%20cannot%20activate%20more%20licenses%2C%20but%20that%20does%20not%20stop%20them%20from%20using%20the%20applications%20without%20the%20license.%20They%20can%20still%20access%20anything%20in%20Outlook%20that%20was%20downloaded%20to%20their%20personal%20computer.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-830729%22%20slang%3D%22en-US%22%3ERe%3A%20Remove%20Office%20365%20Pro%20Plus%20Remotely%20from%20Personal%20Device%20After%20Employment%20Ends%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-830729%22%20slang%3D%22en-US%22%3E%3CP%3EThat's%20a%20different%20issue%20altogether.%20If%20you%20have%20concerns%20about%20them%20keeping%20mails%20and%20files%20on%20personal%20devices%2C%20you%20should%20disable%20external%20access%20from%20the%20get%20go%20via%20CA%20policies%20or%20Client%20Access%20Rules%20in%20Exchange.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-836367%22%20slang%3D%22en-US%22%3ERe%3A%20Remove%20Office%20365%20Pro%20Plus%20Remotely%20from%20Personal%20Device%20After%20Employment%20Ends%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-836367%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F58%22%20target%3D%22_blank%22%3E%40Vasil%20Michev%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThat%20was%20my%20thought%2C%20but%20leadership%20believes%20there%20are%20other%20ways%20to%20secure%20the%20information%20without%20disabling%20the%20ability%20for%20end%20users%20to%20not%20use%20the%20applications%20on%20their%20personal%20computers.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EPersonally%2C%20we%20should%20be%20using%20all%20of%20the%20web%20based%20applications%20when%20not%20using%20company%20devices.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-836945%22%20slang%3D%22en-US%22%3ERe%3A%20Remove%20Office%20365%20Pro%20Plus%20Remotely%20from%20Personal%20Device%20After%20Employment%20Ends%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-836945%22%20slang%3D%22en-US%22%3E%3CP%3EYeah%2C%20that's%20why%20they%20are%20leaders%2C%20they%20don't%20care%20about%20minor%20details%20%3ADRemoving%20Outlook%20on%20its%20own%20doesn't%20really%20solve%20anything%20here%2C%20I%20can%20easily%20export%20all%20the%20content%20of%20the%20mailbox%20and%20keep%20it%20on%20my%20device%2C%20or%20wherever%20I%20see%20fit.%20RMS%2FAIP%20can%20help%20by%20protecting%20individual%20messages%2C%20but%20I'm%20yet%20to%20see%20a%20company%20that%20does%20this%20for%20every%20single%20message%20received.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Contributor

With Office 365 Pro Plus and the E3 license, we are able to deploy 5 copies of the Pro Plus suite. This includes personal device. Once employment ends, how do we go about removing the Pro Plus suite from someone's personal device so they cannot access any corporate data that might be downloaded to their system?

 

An example would be someone is using the Outlook desktop app from their personal device and they leave the company. They would still have access to those files. Another example would be someone is working on a spreadsheet from their device vs. from OneDrive or SharePoint.

 

How do we as M365 admins protect the corporate data and retrieve it from a personal device? How do we stop that employee from downloading it to their personal device?

5 Replies

After the user is terminated and the account disabled/removed, he cannot activate Office anymore, so he will not be able to add to the numbers of active installs. For users that are still active, you can go to the O365 admin portal, select the user and manage the office installs from there (remove devices that you don't recognize). Unfortunately, there is no programmatic way to do this, despite of us asking Microsoft for years...

 

If you want to tightly control who can install where, you will have to use some MDM solution (Intune) or disable the download altogether.

@Vasil Michev 

Very true that they cannot activate more licenses, but that does not stop them from using the applications without the license. They can still access anything in Outlook that was downloaded to their personal computer.

That's a different issue altogether. If you have concerns about them keeping mails and files on personal devices, you should disable external access from the get go via CA policies or Client Access Rules in Exchange.

@Vasil Michev 

 

That was my thought, but leadership believes there are other ways to secure the information without disabling the ability for end users to not use the applications on their personal computers.

 

Personally, we should be using all of the web based applications when not using company devices.

Yeah, that's why they are leaders, they don't care about minor details :D Removing Outlook on its own doesn't really solve anything here, I can easily export all the content of the mailbox and keep it on my device, or wherever I see fit. RMS/AIP can help by protecting individual messages, but I'm yet to see a company that does this for every single message received.