Manage Yammer users across their life cycle from Office 365

%3CLINGO-SUB%20id%3D%22lingo-sub-41280%22%20slang%3D%22en-US%22%3EManage%20Yammer%20users%20across%20their%20life%20cycle%20from%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-41280%22%20slang%3D%22en-US%22%3E%3CP%3E%3CSPAN%3EAfter%20%3C%2FSPAN%3E%3CA%20class%3D%22ocpArticleLink%22%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FYammer-is-activated-4086681f-6de1-4d39-aa72-752b2af1cbd7%22%20target%3D%22_blank%22%20rel%3D%22noopener%20noreferrer%22%3EYammer%20is%20activated%3C%2FA%3E%3CSPAN%3E%20on%20your%20Office%20365%20tenant%2C%20you%2C%20as%20the%20Office%20365%20administrator%2C%20can%20control%20the%20life%20cycle%20for%20Yammer%20users%20from%20Office%20365.%20When%20you%20create%20users%20in%20Office%20365%2C%20they%20can%20log%20on%20to%20Yammer%20with%20their%20Office%20365%20credentials.%20When%20a%20user%20is%20deleted%20from%20Office%20365%2C%20they%20are%20automatically%20deactivated%20or%20suspended%20in%20Yammer.%20When%20a%20user%20is%20restored%20in%20Office%20365%2C%20they%20are%20reactivated%20in%20Yammer.%20Also%2C%20the%20user's%20profile%20properties%20(such%20as%20name%20and%20department)%20from%20Azure%20Active%20Directory%20will%20be%20automatically%20populated%20in%20the%20user's%20Yammer%20profile%2C%20and%20any%20changes%20to%20the%20profile%20properties%20in%20Azure%20Active%20Directory%20will%20be%20reflected%20in%20Yammer%20as%20well.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20400px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F10190i779C1A628D6F41AD%2Fimage-size%2Fmedium%3Fv%3D1.0%26amp%3Bpx%3D400%22%20alt%3D%22YammerActivate.png%22%20title%3D%22YammerActivate.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CSPAN%3ELearn%20more%20on%20how%20to%20manage%2C%20add%2C%20block%2C%20and%20delete%20users%20%3CA%20title%3D%22Manage%20Yammer%20users%20across%20their%20life%20cycle%20from%20Office%20365%22%20href%3D%22https%3A%2F%2Fsupport.office.com%2Fen-us%2Farticle%2FManage-Yammer-users-across-their-life-cycle-from-Office-365-6c4c8fff-6444-404a-bffc-f9da0bcc3039%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3Ehere%3C%2FA%3E.%26nbsp%3B%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-41280%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3EAdmin%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EYammer%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-65247%22%20slang%3D%22en-US%22%3ERe%3A%20Manage%20Yammer%20users%20across%20their%20life%20cycle%20from%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-65247%22%20slang%3D%22en-US%22%3E%3CP%3EMichael%2C%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EWe%20are%20full%200365%20cloud%20with%20no%20on-prem.%26nbsp%3B%20Yammer%20is%20fully%200365%20connected%20so%20identity%20is%20coming%20from%20AzureAD.%26nbsp%3B%20Profiles%20are%20not%20syncing%20properly%20for%20some...per%20the%20article%20%22Also%2C%20the%20user's%20profile%20properties%20(such%20as%20name%20and%20department)%20from%20Azure%20Active%20Directory%20will%20be%20automatically%20populated%20in%20the%20user's%20Yammer%20profile%2C%20and%20any%20changes%20to%20the%20profile%20properties%20in%20Azure%20Active%20Directory%20will%20be%20reflected%20in%20Yammer%20as%20well.%22%26nbsp%3B%20How%20is%20email%20address%20pulled%20into%20the%20profile%3F%26nbsp%3B%20I%20would%20think%20it%20should%20pull%20in%20the%20Primary%20SMTP%20address.%26nbsp%3B%20What%20we%20are%20noticing%20is%20that%20some%20people%20are%20getting%20one%20of%20their%20email%20alias's%20listed%20for%20email%20address.%26nbsp%3B%20The%20email%20listed%20in%20Yammer%20is%20not%20their%26nbsp%3B0365%20username%20or%20their%20ReplyTo%2FPrimary%20SMTP%20address%20but%20another%20alias%20on%20the%20account.%26nbsp%3B%20Should%20I%20just%20be%20patient%20and%20wait%20for%20this%20to%20work%20itself%20out%20as%20updates%20are%20rolled%20out%20or%20should%20I%20call%20support%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIs%20anyone%20else%20having%20these%20issues%3F%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EThanks%20in%20advance%20for%20any%20responses.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EChristine%20Stack%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-50218%22%20slang%3D%22en-US%22%3ERe%3A%20Manage%20Yammer%20users%20across%20their%20life%20cycle%20from%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-50218%22%20slang%3D%22en-US%22%3EThanks%2C%20Tom.%20We%20are%20using%20Office%20365%20Identity.%20I%20didn't%20realize%20this%20was%20%22synonymous%22%20with%20Azure%20AD.%20We%20may%20have%20that%20hybrid%20design%20your%20talking%20about.%20At%20least%20now%2C%20I%20know%20what%20to%20ask%20my%20technical%20folks.%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-49970%22%20slang%3D%22en-US%22%3ERe%3A%20Manage%20Yammer%20users%20across%20their%20life%20cycle%20from%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-49970%22%20slang%3D%22en-US%22%3E%3CP%3EIt%20depends%20on%20how%20your%20network%20is%20configured.%20%26nbsp%3BIf%20you%20want%20to%20make%20sure%20that%20a%20disabled%20account%20can't%20get%20into%20Yammer%2C%20then%20you%20need%20to%20configure%20your%20Yammer%20network%20with%20Office%20365%20Identity%20Enforcement%3A%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20style%3D%22width%3A%20797px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Fgxcuf89792.i.lithium.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F11455iB56283B2C0617047%2Fimage-size%2Flarge%3Fv%3D1.0%26amp%3Bpx%3D999%22%20alt%3D%22O365IdentityEnforced.JPG%22%20title%3D%22O365IdentityEnforced.JPG%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EOnce%20you've%20done%20that%2C%20then%20anyone%20without%20a%20valid%20Office%20365%20account%20cannot%20access%20Yammer.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EBefore%20you%20do%20this%2C%20ask%20your%20technical%20people%20how%20your%20accounts%20are%20set%20up.%20%26nbsp%3BIt%20only%20talks%20about%20Azure%20AD%20because%20that's%20what%20is%20meant%20by%20Office%20365%20Identity.%20%26nbsp%3BSome%20enterprises%20use%20a%20hybrid%20where%20account%20management%20is%20done%20on-premesis%20and%20all%20changes%20are%20replicated%20to%20Office%20365.%20%26nbsp%3B%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIf%20you're%20not%20usng%20Office%20365%20Identity%2C%20then%20the%20only%20way%20to%20ensure%20that%20former%20employees%20do%20not%20access%20your%20Yammer%20network%20is%20to%20use%20bulk%20update%20to%20delete%20%2F%20suspend%20all%20disabled%20accounts%2C%20and%20then%20block%20those%20accounts%20from%20your%20network.%20%26nbsp%3BThis%20usually%20requires%20some%20scripting%20to%20get%20the%20list%20of%20newly%20disabled%20accounts.%20%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-49857%22%20slang%3D%22en-US%22%3ERe%3A%20Manage%20Yammer%20users%20across%20their%20life%20cycle%20from%20Office%20365%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-49857%22%20slang%3D%22en-US%22%3E%5BCaveat%2C%20I'm%20not%20a%20technical%20person.%5D%3CBR%20%2F%3E%3CBR%20%2F%3EWe're%20trying%20to%20prove%20out%20through%20testing%20that%20when%20we%20disable%20a%20user's%20AD%20account%2C%20they're%20O365%20account%20will%20be%20disabled%20and%20all%20Yammer%20sessions%20will%20be%20terminated.%20So%20far%2C%20our%20testing%20is%20demonstrating%20the%20user%20still%20has%20access.%3CBR%20%2F%3E%3CBR%20%2F%3EI%20read%20the%20article%20above%2C%20and%20it%20talks%20only%20about%20Azure%20AD.%20I%20think%20we%20are%20using%20an%20%22on%20prem%22%20AD%20or%20maybe%20an%20older%20version.%20Should%20we%20be%20able%20to%20expect%20this%20to%20work%20the%20same%3F%20Also%2C%20is%20there%20a%20delay%20between%20disabling%20the%20AD%20account%20and%20the%20user's%20sessions%20ending%3F%3C%2FLINGO-BODY%3E
Microsoft

After Yammer is activated on your Office 365 tenant, you, as the Office 365 administrator, can control the life cycle for Yammer users from Office 365. When you create users in Office 365, they can log on to Yammer with their Office 365 credentials. When a user is deleted from Office 365, they are automatically deactivated or suspended in Yammer. When a user is restored in Office 365, they are reactivated in Yammer. Also, the user's profile properties (such as name and department) from Azure Active Directory will be automatically populated in the user's Yammer profile, and any changes to the profile properties in Azure Active Directory will be reflected in Yammer as well. 

 

YammerActivate.png

 

Learn more on how to manage, add, block, and delete users here

4 Replies
[Caveat, I'm not a technical person.]

We're trying to prove out through testing that when we disable a user's AD account, they're O365 account will be disabled and all Yammer sessions will be terminated. So far, our testing is demonstrating the user still has access.

I read the article above, and it talks only about Azure AD. I think we are using an "on prem" AD or maybe an older version. Should we be able to expect this to work the same? Also, is there a delay between disabling the AD account and the user's sessions ending?

It depends on how your network is configured.  If you want to make sure that a disabled account can't get into Yammer, then you need to configure your Yammer network with Office 365 Identity Enforcement:O365IdentityEnforced.JPG

 

Once you've done that, then anyone without a valid Office 365 account cannot access Yammer.

 

Before you do this, ask your technical people how your accounts are set up.  It only talks about Azure AD because that's what is meant by Office 365 Identity.  Some enterprises use a hybrid where account management is done on-premesis and all changes are replicated to Office 365.  

 

If you're not usng Office 365 Identity, then the only way to ensure that former employees do not access your Yammer network is to use bulk update to delete / suspend all disabled accounts, and then block those accounts from your network.  This usually requires some scripting to get the list of newly disabled accounts.  

Thanks, Tom. We are using Office 365 Identity. I didn't realize this was "synonymous" with Azure AD. We may have that hybrid design your talking about. At least now, I know what to ask my technical folks.

Michael,

 

We are full 0365 cloud with no on-prem.  Yammer is fully 0365 connected so identity is coming from AzureAD.  Profiles are not syncing properly for some...per the article "Also, the user's profile properties (such as name and department) from Azure Active Directory will be automatically populated in the user's Yammer profile, and any changes to the profile properties in Azure Active Directory will be reflected in Yammer as well."  How is email address pulled into the profile?  I would think it should pull in the Primary SMTP address.  What we are noticing is that some people are getting one of their email alias's listed for email address.  The email listed in Yammer is not their 0365 username or their ReplyTo/Primary SMTP address but another alias on the account.  Should I just be patient and wait for this to work itself out as updates are rolled out or should I call support?

 

Is anyone else having these issues?  

 

Thanks in advance for any responses.

 

Christine Stack