09/12/2023 02:39 AM
We are going to change our user policy that only mailbox (Exchange Online) will be assigned to M365 A1 user.
However, from the entitlement list, we cannot find these Apps under M365 A1.
Please advise.
09/13/2023 01:10 PM
Hi @oscarcheng,
We are checking this and will get back to you.
09/14/2023 04:35 AM
Hi @oscarcheng,
If you could provide more details about your use case, we would appreciate it
09/14/2023 08:27 AM
hi @DixshantValecha ,
Currently, we will assign M365 A1 license (Entitlement name: STANDARDWOFFPACK_FACULTY and entitlement type: SKU) to each user M365 account (M365 A1 Entitlement.png). As long as the M365 A1 license is assigned, there are 28 Apps would be assigned to the user (Apps in A1.png).
Recently, we control the user to access mailbox (refer to Expected A1 apps.png) only but no other apps, like Teams, Sharepoint etc. On M365 platform, we can uncheck these apps one-by-one or we can run the PowerShell script to remove other apps explicitly. However, it will make the workflow and the operation more complicated. We would like to know how can we only assign the Exchange online (plan 1) to user on IGA. So that we don't need to re-work on M365 platform or running PowerShell script instead.
If you need more information, please feel free to discuss.
09/17/2023 07:04 PM
hi @DixshantValecha , any advice?
09/19/2023 05:42 AM
Hi @oscarcheng,
Thank you for your patience. We are currently in the process of investigating this matter, and we will promptly furnish you with an update in the near future.
10/03/2023 05:40 PM
hi @DixshantValecha sorry for pushy.
May I know any updates from your side?
10/05/2023 05:26 AM
Hi @oscarcheng ,
Kindly provide information regarding your current Saviynt version.
10/10/2023 05:42 AM
@DixshantValechawe are now running 2021.
10/10/2023 11:30 PM
Hi @oscarcheng
Your requirement as per my understanding:-
"The user currently assigns M365 A1 licenses to users, which includes 28 apps. They want to restrict access to only the Exchange Online (plan 1) app while avoiding complex manual adjustments or PowerShell scripts in the M365 platform. They are looking for a solution within their Identity Governance and Administration (IGA) system to achieve this."
Solution:-
You can achieve this requirement if you have a dedicated license for Exchange Online(the changes needs to be done on the license side) . This way, you can assign only the Exchange Online license to users and restrict access to other apps.
Please note that the entitlement type is "SKU."
Please validate and let us know if further details are needed on this.