org-wide removed user gets added again

%3CLINGO-SUB%20id%3D%22lingo-sub-1670037%22%20slang%3D%22en-US%22%3Eorg-wide%20removed%20user%20gets%20added%20again%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1670037%22%20slang%3D%22en-US%22%3E%3CP%3EHello%20all%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20have%20been%20doing%20some%20testings%20with%20org-wide%20teams%20and%20faced%20myself%20with%20a%20wird%20thing%20when%20removing%20and%20adding%20users.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20create%20an%20org-wide%20Team%20as%20a%20Global%20Admin%20directly%20from%20Teams%20client%20(Web).%20After%20the%20team%20creation%20I%20saw%20that%20all%20users%20in%20the%20tenant%20got%20added%20to%20that%20org-wide%20Team.%20Until%20now%20everything%20as%20expected.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EDeleted%20one%20member%20directly%20from%20the%20team%20-%20Diego%20Siciliani.%20Created%20a%20new%20user%20in%20M365%20Admin%20Center%20(Ricardo%20Mendes).%20After%20some%20minutes%20I%20found%20that%20Diego%20Siciliani%20was%20added%20again%20(no%20change%20was%20made%20to%20that%20user%20in%20M365%20Admin%20Center).%20Did%20some%20other%20testings%20and%20this%20did%20not%20happen%20again.%20No%20dynamic%20membership%20was%20used%20for%20this.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAnyone%20had%20seen%20something%20like%20this%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERgs%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERM%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1670037%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EMicrosoft%20Teams%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESettings%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1670597%22%20slang%3D%22en-US%22%3ERe%3A%20org-wide%20removed%20user%20gets%20added%20again%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1670597%22%20slang%3D%22en-US%22%3EThere%20is%20some%20obfuscated%20magic%20when%20it%20comes%20to%20the%20group%20membership%20of%20an%20Org%20Wide%20Team.%20Believe%20me%20I%20have%20looked%20as%20initially%20I%20was%20just%20expecting%20it%20to%20be%20a%20pre%20configured%20dynamic%20membership%20group.%3CBR%20%2F%3E%3CBR%20%2F%3ENot%20sure%20about%20the%2C%20you%20did%20some%20more%20testing%20and%20it%20didn't%20happen%20again%20bit%20but%20what%20you%20described%20is%20what%20I%20would%20expect.%3CBR%20%2F%3E%3CBR%20%2F%3ESo%20you%20removed%20a%20user%20from%20the%20Team%20but%20not%20Azure%20AD%20or%20it%20was%20not%20set%20as%20inactive%20in%20Azure%20AD.%20So%20it%20is%20still%20an%20account%20and%20therefore%20it%20will%20get%20added%20back%20in.%3CBR%20%2F%3E%3CBR%20%2F%3EIf%20this%20is%20not%20desirable%20then%20you%20might%20be%20better%20off%20creating%20a%20Team%20with%20dynamic%20group%20membership%20configured%20to%20your%20hearts%20content.%3CBR%20%2F%3E%3CBR%20%2F%3EAlso%20refer%20to%20this%3A%3CBR%20%2F%3E%3CBR%20%2F%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoftteams%2Fcreate-an-org-wide-team%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fmicrosoftteams%2Fcreate-an-org-wide-team%3C%2FA%3E%3CBR%20%2F%3E%3CBR%20%2F%3EKey%20bit%20being%3A%3CBR%20%2F%3E%3CBR%20%2F%3EThese%20types%20of%20accounts%20won't%20be%20added%20to%20your%20org-wide%20team%3A%3CBR%20%2F%3E%3CBR%20%2F%3EAccounts%20that%20are%20blocked%20from%20sign%20in%3CBR%20%2F%3EGuest%20users%3CBR%20%2F%3EService%20accounts%3CBR%20%2F%3ERoom%20or%20equipment%20accounts%3CBR%20%2F%3EAccounts%20backed%20by%20a%20shared%20mailbox%3CBR%20%2F%3E%3CBR%20%2F%3EThanks%3CBR%20%2F%3E%3CBR%20%2F%3EHenry%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1672159%22%20slang%3D%22en-US%22%3ERe%3A%20org-wide%20removed%20user%20gets%20added%20again%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1672159%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F693840%22%20target%3D%22_blank%22%3E%40henryarphillips365%3C%2FA%3E%26nbsp%3Bthanks%20for%20your%20feedback.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegarding%20the%20testings%20done%20they%20were%20all%20with%20the%20same%20assumptions.%20Deleted%20some%20users%20from%20the%20org-wide%20team%20using%20the%20Teams%20client.%20And%20by%20doing%20this%2C%20only%20the%20first%20one%20to%20be%20deleted%20got%20readded%20again%2C%20all%20the%20other%20were%20not.%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3ERegarding%20the%20link%20you%20shared%20that%20was%20exactly%20what%20seems%20strange%2C%20because%20according%20the%20documentation%2C%20if%20you%20remove%20a%20user%2C%20they%20should%20not%20be%20readded%3A%3C%2FP%3E%3CH3%20id%3D%22toc-hId-1231160079%22%20id%3D%22toc-hId-1231160079%22%3E%22Remove%20accounts%20that%20might%20not%20belong%3C%2FH3%3E%3CP%3EEven%20though%20members%20can't%20leave%20an%20org-wide%20team%2C%20as%20a%20team%20owner%2C%20you%20can%20manage%20the%20team%20roster%20by%20removing%20accounts%20that%20don't%20belong.%3CSPAN%3E%26nbsp%3B%3C%2FSPAN%3E%3CSTRONG%3EMake%20sure%20you%20use%20Teams%20to%20remove%20users%20from%20your%20org-wide%20team%3C%2FSTRONG%3E.%20If%20you%20use%20another%20way%20to%20remove%20a%20user%2C%20such%20as%20the%20Microsoft%20365%20admin%20center%20or%20from%20a%20group%20in%20Outlook%2C%20the%20user%20might%20be%20added%20back%20to%20the%20org-wide%20team.%22%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Contributor

Hello all,

 

I have been doing some testings with org-wide teams and faced myself with a wird thing when removing and adding users.

 

I create an org-wide Team as a Global Admin directly from Teams client (Web). After the team creation I saw that all users in the tenant got added to that org-wide Team. Until now everything as expected.

 

Deleted one member directly from the team - Diego Siciliani. Created a new user in M365 Admin Center (Ricardo Mendes). After some minutes I found that Diego Siciliani was added again (no change was made to that user in M365 Admin Center). Did some other testings and this did not happen again. No dynamic membership was used for this.

 

Anyone had seen something like this?

 

Rgs,

 

RM

5 Replies
Highlighted
There is some obfuscated magic when it comes to the group membership of an Org Wide Team. Believe me I have looked as initially I was just expecting it to be a pre configured dynamic membership group.

Not sure about the, you did some more testing and it didn't happen again bit but what you described is what I would expect.

So you removed a user from the Team but not Azure AD or it was not set as inactive in Azure AD. So it is still an account and therefore it will get added back in.

If this is not desirable then you might be better off creating a Team with dynamic group membership configured to your hearts content.

Also refer to this:

https://docs.microsoft.com/en-us/microsoftteams/create-an-org-wide-team

Key bit being:

These types of accounts won't be added to your org-wide team:

Accounts that are blocked from sign in
Guest users
Service accounts
Room or equipment accounts
Accounts backed by a shared mailbox

Thanks

Henry
Highlighted

@henryarphillips365 thanks for your feedback. 

 

Regarding the testings done they were all with the same assumptions. Deleted some users from the org-wide team using the Teams client. And by doing this, only the first one to be deleted got readded again, all the other were not. 

 

Regarding the link you shared that was exactly what seems strange, because according the documentation, if you remove a user, they should not be readded:

"Remove accounts that might not belong

Even though members can't leave an org-wide team, as a team owner, you can manage the team roster by removing accounts that don't belong. Make sure you use Teams to remove users from your org-wide team. If you use another way to remove a user, such as the Microsoft 365 admin center or from a group in Outlook, the user might be added back to the org-wide team."

 

 

Highlighted

Hi @Ricardo Mendes ,

 

Sorry completely glossed over that point.

 

I know you have probably checked this anyway but is there a big difference account wise between the account that got added back in and the one that didn't. So say Role wise as an example?

 

Thanks

 

Henry

Highlighted

Hi @Ricardo Mendes ,

 

This might also highlight the fact that a Team with its Membership populated by way of a dynamic group might be the way to go as at least that way you are in more control, especially if you need it for a not quite all Org purposes.

 

Thanks

 

Henry

Highlighted
nop. same user settings, roles, licenses.