User leaves organization - what happens with all the files ?

%3CLINGO-SUB%20id%3D%22lingo-sub-62005%22%20slang%3D%22en-US%22%3EUser%20leaves%20organization%20-%20what%20happens%20with%20all%20the%20files%20%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-62005%22%20slang%3D%22en-US%22%3E%3CP%3EI%20haven't%20found%20any%20tech%20article%20%2C%20therefore%20i%20just%20raise%20this%20question%20in%20here.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EA%20user%20has%20uploaded%20files%20to%20onedrive.%20Some%20of%20them%20are%20shared...some%20are%20not.%3C%2FP%3E%3CP%3ESo%20what%20happens%2C%20if%20the%20user%20object%20gets%20now%20deleted%20because%20the%20user%20left%20the%20company%20%3F%3C%2FP%3E%3CP%3EI%20know%2C%20the%20onedrive%20space%20and%20its%20content%20will%20remain%20but%20the%20important%20question%20is%2C%20what%20happens%20with%20the%20content%20%3F%20they%20are%20orphaned%20now%20because%20nobody%20(excepts%20the%20Site%20Admin)%20can%20do%20anything%20with%20it...right%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ein%20addition%20to%20that....%3C%2FP%3E%3CP%3E1)%20How%20an%20admin%20manages%20this%20kind%20of%20situation%20for%20OfB%3F%26nbsp%3B%20Is%20there%20a%20kind%20of%20dashboard%20available%20where%20one%20can%20see%20which%20onedrive%20spaces%20are%20orphaned%20and%20containing%20files%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E2)%20How%20does%20it%20look%20like%20for%20a%20Team%20Site%20%3F%20Does%20the%20Site%20owner%20see's%20somewhere%20which%20documents%20are%20now%20orphaned%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei%20hope%20my%20questions%20make%20sense.%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-62005%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESharePoint%20Online%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-65725%22%20slang%3D%22en-US%22%3ERe%3A%20User%20leaves%20organization%20-%20what%20happens%20with%20all%20the%20files%20%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-65725%22%20slang%3D%22en-US%22%3E%3CP%3EWell%2C%20that%20depends%20on%20your%20definitions.%20You%20can%20run%20a%20report%20based%20on%20%22last%20modified%20date%22%20for%20example%2C%20or%20even%20%22last%20accessed%20date%22%2C%20then%20act%20upon%20it.%20Monhtly%20might%20be%26nbsp%3Ba%20bit%20too%20often%2C%20once%20or%20twice%20per%20year%20is%20more%20reasonable%20IMO.%20With%20the%20unified%20retention%20policies%2C%20you%20also%20have%20the%20option%20to%20automatically%20purge%20content%20now.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThen%20again%2C%20most%20organizations%20tend%20to%20pile%20stuff%20just%20because%20there%20might%20be%20a%20possibility%20it%20will%20be%20used%20in%20the%20future%2C%20however%20small%20that%20possibility%20is.%20That's%20why%20we%20have%20the%20issues%20with%20PST%20files%2C%20Public%20folders%20and%20pretty%20much%20every%20other%20system...%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-65574%22%20slang%3D%22en-US%22%3ERe%3A%20User%20leaves%20organization%20-%20what%20happens%20with%20all%20the%20files%20%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-65574%22%20slang%3D%22en-US%22%3E%3CP%3E%3A)%3C%2Fimg%3E%20right%2C%20for%20OfB%20i%20would%20not%20pay%20any%20additional%20money%20for%20necessary%20storage%20but%20for%20certain%20subscriptions%20you%20would%20pay%20if%20you%20want%20to%20use%20more%20than%201TB%20on%20the%20OfB%20side.%20But%20lets%20ignore%20this%20for%20the%20moment%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHow%20would%20you%20see%20the%20orphaned%20stuff%20in%20regards%20to%20SPO%20Sites%20(e.g.%20obsolete%2Finactive%20sites%2C%20a.s.o)%3C%2FP%3E%3CP%3ESPO%20sites%20counts%20to%20the%20tenant%20storage.%20If%20you%20can%20remove%20obsolete%20sites%20you%20would%20save%20tenant%20storage%20and%20therefore%20you%20would%20not%20need%20to%20buy%20additional%20storage%20for%2020cent%2FGB%2Fmonth%26nbsp%3B%20in%20case%20you%20run%20out%20of%20storage%20space%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3EDo%20you%20know%20how%20other%20organizations%20are%20handling%20this%20case%20%3F%20Do%20they%20run%20housekeeping%20tasks%20monthly%2Fyearly%20or%20do%20they%20just%20ignore%20this%20and%20buy%20storage%20as%20needed%20%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei'm%20really%20curious%20to%20your%20answers%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3Ethank%20you%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-62382%22%20slang%3D%22en-US%22%3ERe%3A%20User%20leaves%20organization%20-%20what%20happens%20with%20all%20the%20files%20%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-62382%22%20slang%3D%22en-US%22%3E%3CP%3EWell%2C%20you%20dont%20pay%20for%20ODFB%20storage%2C%20so%20you%20will%20be%20fine%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOn%20a%20more%20serious%20note%2C%20there%20isnt%20any%20%22orphaned%22%20report%20that%20I'm%20aware%20of%2C%20but%20it%20should%20be%20relatively%20easy%20to%20produce%20one.%20Just%20get%20one%20of%20the%20scripts%20that%20enumerate%20ODFB%20sites%20and%20add%20a%20column%20to%20check%20whether%20the%20user%20is%20licensed%2C%20or%20whether%20the%20user%20account%20even%20exists.%20If%20you%20mean%20something%20like%20a%20%22last%20time%20a%20file%20was%20accessed%22%20type%20of%20reprot%2C%20you%20will%20have%20to%20crawl%20the%20audit%20logs%2C%20or%20better%20yet%20get%20a%203rd%20party%20reporting%20product%20that%20monitors%20this%20type%20of%20things.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAs%20long%20as%20you%20have%20a%20proper%20%22leavers%22%20process%2C%20customized%20to%20your%20organizations'%20needs%2C%20the%20built-in%20tools%20and%20some%20scripting%20should%20be%20sufficient.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-62373%22%20slang%3D%22en-US%22%3ERe%3A%20User%20leaves%20organization%20-%20what%20happens%20with%20all%20the%20files%20%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-62373%22%20slang%3D%22en-US%22%3E%3CP%3Ethank%20you%20josh%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ei'm%20aware%20of%20this%20support%20article%20but%20it%20explains%20just%20some%20areas%20which%20an%20admin%20%22should%22%20check%20whenever%20a%20user%20leaves%20the%20organization.%3C%2FP%3E%3CP%3E%3CSTRONG%3Ei'm%20more%20interested%20in%20if%20there%20is%20a%20dashboard%20(or%20whatever)%20available%20in%20which%20you%20see%20in%20one%20view%20which%20OfB's%20are%20%22orphaned%22%20and%20which%20Files%20do%20i%20have%20across%20SPO%20where%20the%20owner%20does%20not%20exist%20anylonger.%3C%2FSTRONG%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EImagine%20the%20following%20situation%20(which%20is%20in%20my%20opinion%20very%20common)%3A%3C%2FP%3E%3CP%3Eusers%20are%20leaving%20the%20company%20but%20the%20admin%20does%20not%20find%20time%20to%20proceed%20with%20the%20mentioned%20tasks%20or%20has%20no%20information%20what%20to%20do%20all%20the%20files%20(from%20successor%2C%20department%20head...etc).%20So%20the%20process%20is%20more%20or%20less%20%22on%20hold%22.%3C%2FP%3E%3CP%3EThen%20after%20weeks%2C%20months%20he%20may%20have%20forgotten%20to%20furhter%20continue%20with%20this.%3C%2FP%3E%3CP%3EResult%20would%20be%20that%20my%20O365%20tenant%20gets%20more%20and%20more%20orphaned%20objects.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI'm%20sure%20i'm%20not%20the%20only%20one%20here%20seeing%20this%20as%20an%20important%20thing%20...hopefully%20%3A)%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20checked%20several%203rd%20Party%20tools%2C%20but%20couldn't%20find%20any%20which%20would%20cover%20this%20usecase%20here%20%3A(%3C%2Fimg%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3Ethanks%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-62008%22%20slang%3D%22en-US%22%3ERe%3A%20User%20leaves%20organization%20-%20what%20happens%20with%20all%20the%20files%20%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-62008%22%20slang%3D%22en-US%22%3E%3CP%3EHey%20Stefan%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EStart%20with%20this%20document%20located%20at%20%3CA%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FRemove-a-former-employee-from-Office-365-44d96212-4d90-4027-9aa9-a95eddb367d1%3Fui%3Den-US%26amp%3Brs%3Den-US%26amp%3Bad%3DUS%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%20noopener%20noreferrer%22%3Ehttps%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FRemove-a-former-employee-from-Office-365-44d96212-4d90-4027-9aa9-a95eddb367d1%3Fui%3Den-US%26amp%3Brs%3Den-US%26amp%3Bad%3DUS%3C%2FA%3E%20and%20see%20if%20that%20will%20help%20answer%20your%20questions.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1259291%22%20slang%3D%22en-US%22%3ERe%3A%20User%20leaves%20organization%20-%20what%20happens%20with%20all%20the%20files%20%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1259291%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F44882%22%20target%3D%22_blank%22%3E%40Stefan%20Fried%3C%2FA%3E%26nbsp%3B-%20did%20you%20get%20this%20answered%3F%26nbsp%3B%20I%20see%20it's%20a%20little%20dated%2C%20but%20wanted%20to%20check%20before%20assisting.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1260002%22%20slang%3D%22en-US%22%3ERe%3A%20User%20leaves%20organization%20-%20what%20happens%20with%20all%20the%20files%20%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1260002%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F3175%22%20target%3D%22_blank%22%3E%40Lou%20Mickley%3C%2FA%3E%26nbsp%3B%20%22%3CEM%3EA%20little%20dated%3C%2FEM%3E%22....as%20in%20almost%203%20years%20old.%26nbsp%3B%20lol%3CBR%20%2F%3E%3CBR%20%2F%3EI%20and%20others%20would%20like%20to%20hear%20thoughts%20on%20best%20practice%2Fsolutions%20for%20this%20situation.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-1296752%22%20slang%3D%22en-US%22%3ERe%3A%20User%20leaves%20organization%20-%20what%20happens%20with%20all%20the%20files%20%3F%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1296752%22%20slang%3D%22en-US%22%3E%3CP%3EWhen%20a%20user%20is%20deleted%20in%20AD%2FAAD%2C%20O365%20licensed%20revoked%2C%20the%20OneDrive%20library%20actively%20continues%20on%20INCLUDING%20existing%20sharing%20permissions%20until%20the%20tenant-wide%20OneDrive%20admin%20retention%20value%20counts%20down%20to%200%20-%20then%20all%20the%20files%20are%20deleted%20into%20recycle%20bin%2C%20and%2093%20days%20later%2C%20permanently%20deleted.%26nbsp%3B%20These%20files%20can%20only%20be%20retrieved%20from%20the%20recycle%20bin%20via%20PowerShell%20since%20the%20user%20no%20longer%20active.%3C%2FP%3E%3CP%3EIf%20you%20have%20access%20delegation%20turned%20on%20the%20Manager%20(defined%20in%20the%20AD%20attribute)%20automatically%20gets%20read%2Fwrite%20access%20and%20if%20no%20manager%20defined%2C%20the%20defined%20secondary%20admin%20can%20have%20access%20automatically%20granted.%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
Super Contributor

I haven't found any tech article , therefore i just raise this question in here.

 

A user has uploaded files to onedrive. Some of them are shared...some are not.

So what happens, if the user object gets now deleted because the user left the company ?

I know, the onedrive space and its content will remain but the important question is, what happens with the content ? they are orphaned now because nobody (excepts the Site Admin) can do anything with it...right ?

 

in addition to that....

1) How an admin manages this kind of situation for OfB?  Is there a kind of dashboard available where one can see which onedrive spaces are orphaned and containing files ?

 

2) How does it look like for a Team Site ? Does the Site owner see's somewhere which documents are now orphaned ?

 

i hope my questions make sense. :)

8 Replies
Highlighted

Hey Stefan,

 

Start with this document located at https://support.office.com/en-us/article/Remove-a-former-employee-from-Office-365-44d96212-4d90-4027... and see if that will help answer your questions.

Highlighted

thank you josh

 

i'm aware of this support article but it explains just some areas which an admin "should" check whenever a user leaves the organization.

i'm more interested in if there is a dashboard (or whatever) available in which you see in one view which OfB's are "orphaned" and which Files do i have across SPO where the owner does not exist anylonger.

 

Imagine the following situation (which is in my opinion very common):

users are leaving the company but the admin does not find time to proceed with the mentioned tasks or has no information what to do all the files (from successor, department head...etc). So the process is more or less "on hold".

Then after weeks, months he may have forgotten to furhter continue with this.

Result would be that my O365 tenant gets more and more orphaned objects.

 

I'm sure i'm not the only one here seeing this as an important thing ...hopefully :)

 

I checked several 3rd Party tools, but couldn't find any which would cover this usecase here :(

 

thanks

 

 

 

Highlighted

Well, you dont pay for ODFB storage, so you will be fine :)

 

On a more serious note, there isnt any "orphaned" report that I'm aware of, but it should be relatively easy to produce one. Just get one of the scripts that enumerate ODFB sites and add a column to check whether the user is licensed, or whether the user account even exists. If you mean something like a "last time a file was accessed" type of reprot, you will have to crawl the audit logs, or better yet get a 3rd party reporting product that monitors this type of things.

 

As long as you have a proper "leavers" process, customized to your organizations' needs, the built-in tools and some scripting should be sufficient.

 

 

Highlighted

:) right, for OfB i would not pay any additional money for necessary storage but for certain subscriptions you would pay if you want to use more than 1TB on the OfB side. But lets ignore this for the moment :)

 

How would you see the orphaned stuff in regards to SPO Sites (e.g. obsolete/inactive sites, a.s.o)

SPO sites counts to the tenant storage. If you can remove obsolete sites you would save tenant storage and therefore you would not need to buy additional storage for 20cent/GB/month  in case you run out of storage space :)

Do you know how other organizations are handling this case ? Do they run housekeeping tasks monthly/yearly or do they just ignore this and buy storage as needed ?

 

i'm really curious to your answers :)

thank you

Highlighted

Well, that depends on your definitions. You can run a report based on "last modified date" for example, or even "last accessed date", then act upon it. Monhtly might be a bit too often, once or twice per year is more reasonable IMO. With the unified retention policies, you also have the option to automatically purge content now.

 

Then again, most organizations tend to pile stuff just because there might be a possibility it will be used in the future, however small that possibility is. That's why we have the issues with PST files, Public folders and pretty much every other system...

Highlighted

@Stefan Fried - did you get this answered?  I see it's a little dated, but wanted to check before assisting.

Highlighted

@Lou Mickley  "A little dated"....as in almost 3 years old.  lol

I and others would like to hear thoughts on best practice/solutions for this situation.

Highlighted

When a user is deleted in AD/AAD, O365 licensed revoked, the OneDrive library actively continues on INCLUDING existing sharing permissions until the tenant-wide OneDrive admin retention value counts down to 0 - then all the files are deleted into recycle bin, and 93 days later, permanently deleted.  These files can only be retrieved from the recycle bin via PowerShell since the user no longer active.

If you have access delegation turned on the Manager (defined in the AD attribute) automatically gets read/write access and if no manager defined, the defined secondary admin can have access automatically granted.