Skip to content
Open
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -7,10 +7,16 @@ description: This article explains how to set up the Orphaned Workspaces policy
Syskit Point detects **workspaces that don't have active owners**, which helps you ensure there is always someone responsible for access and content management for your workspaces.

:::warning
**Please note!**
The default Orphaned Workspaces policy now also applies to SharePoint Sites.
You can expect to see the changes after the next AutoDiscover sync following the upgrade to the latest Point version.
Custom Orphaned Workspaces policies created by Syskit Point admins can also be applied to SharePoint sites using Rules or manually.
**Please note**, this policy can be applied to the following workspaces:
* **Microsoft Teams**
* **Microsoft 365 Group**
* **SharePoint Sites**
* **Viva Engage Community**

The default Orphaned Workspaces policy can applies to **SharePoint Sites**.

**Custom Orphaned Workspaces policies** created by Syskit Point admins **can also be applied to SharePoint sites using Rules or manually**.

:::

A predefined policy - **Orphaned Workspaces** - can be found on the Policies screen.
Expand All @@ -24,10 +30,9 @@ The **Edit Policy** dialog opens, where you can:
* **Choose the severity level (2)**; this option is enabled by default
* **Enable Task Delegation (3)** by clicking the toggle next to it and selecting your task delegation preferences:
* **Select between the 3 available processes (4)**:
* **Ask Specific Users to Assign New Owners**; this is a **1-stage process**, where selected users - Syskit Point Administrators and/or custom recipients - **get a task to assign new owners**
* **Ask Members to Suggest New Owners**; this is a **2-stage process**, where members can suggest new owners, and afterward, the selected users - Syskit Point Administrators and/or custom recipients - **get a task to resolve the task based on the suggestions from owners**; by default, this option is selected
* **Automatically Assign New Owners**; if selected, Syskit Point **automatically assigns the last owner's manager as a new owner**
* If the manager cannot be found, Syskit Point escalates the task to the user you defined when creating the policy
* [**Ask Specific Users to Assign New Owners**](#ask-specific-users-to-assign-new-owners)
* [**Ask Members to Suggest New Owners**](#ask-members-to-suggest-new-owners)
* [**Automatically Assign New Owners**](#automatically-assign-new-owners)
* Click **Save (5)** once you are done with the policy configuration

![Edit Policy Dialog](../../../static/img/set-up-automated-workflows-orphaned-dialog.png)
Expand All @@ -46,13 +51,60 @@ The **Edit Policy** dialog opens, where you can:

:::

For details on how collaborators can [**resolve Orphanes Workspaces policy vulnerability tasks**, navigate to the following article](../../point-collaborators/resolve-governance-tasks/orphaned-resources.md).

## Ask Specific Users to Assign New Owners

The **Ask Specific Users to Assign New Owners** option is a **1-stage process**.

When an Orphaned Workspace is detected, **selected users (Syskit Point Administrators and/or custom recipients) receive a task to assign a new owner to the workspace**. No additional steps or user involvement is required beyond this.

For more details on how this task is resolved from the specific users perspective, take a look at the [Resolve Orphaned Workspace tasks article.](../../point-collaborators/resolve-governance-tasks/orphaned-resources.md#specific-users-assign-new-owners)


## Ask Members to Suggest New Owners

The **Ask Members to Suggest New Owners** is a **2-stage process**, and is the default option selected.


In the first stage, **Members suggest new owners**:
* When the Ask Members action is triggered, e-mails and tasks are sent to all members of the workspace
* Members are asked to suggest one or more users as new owners
* Members can resolve the task directly from the e-mail they receive
* The suggestions are stored as members resolve their tasks, and stage one stays active until all members resolve their tasks

:::info
**Please note**, this policy can be applied to the following workspaces:
* **Microsoft Teams**
* **Microsoft 365 Group**
* **SharePoint Sites**
* **Viva Engage Community**

:::
**Please note:**

**If the team has no members**, this action cannot be completed. In that case, the admins have to resolve the vulnerability by using one of the following actions;
* Add Owners
* Archive Workspace
* Delete Workspace

:::


* In the second stage, **admins or designated resolvers get a new the task**:
* After all members tasks are completed, a new task is created for admins or designated reviewers to take one of the following actions:
* **Add Owners**, by approving the suggestions made by members or deciding on an owner yourself
* **Archive** the workspace
* **Delete** the workspace

For more details on how this task is resolved from the specific users perspective, take a look at the [Resolve Orphaned Workspace tasks article.](../../point-collaborators/resolve-governance-tasks/orphaned-resources.md#members-suggest-new-owners)


## Automatically Assign New Owners

When the **Automatically Assign New Owners** option is selected, Syskit Point **automatically assigns the last owner's manager as a new owner**. If the manager cannot be found, Syskit Point escalates the task to the user you defined when creating the policy.

When resolving the Orphaned Workspaces task by selecting the Automatically Assign New Owners option, Syskit Point tries to find the most appropriate owner by **using the following logic**:

* **Check for disabled or deleted owners**
* If the workspace had disabled or deleted owners, Point assigns ownership to the manager of one of those users.
* The selected manager cannot be disabled or deleted and is chosen based on the most recent sign-in.
* If no disabled or deleted owners are found, Point checks audit logs for users who were removed as owners within the last 7 days.
* If such users exists, ownership is assigned to the manager of one of those users while using the same criteria as mentioned above.

* **Fallback to tasks**
* If no suitable owner can be found during the above step, resolution tasks are assigned to the configured resolvers and an e-mail is sent to them.
* If an owner is found, but assignment fails, tasks are assigned to Syskit Point Admins, without sending an e-mail notification.
Original file line number Diff line number Diff line change
Expand Up @@ -36,6 +36,7 @@ The report itself provides information on:

Additionally, you can complete the following actions for the policy vulnerability:
* **Ask Members (8)** - this action requests that the workspace members select new workspace owners
* For more details on the Ask Members action, [please check out the section below](#ask-members-action)
* **The Ellipsis (more options) Menu (9)** - clicking the 3 dots next to the Ask Members button provides the option to complete the following actions:
* **Archive** - this action archives the workspaces
* **Delete** - this action deletes the workspace
Expand Down Expand Up @@ -77,3 +78,56 @@ Here you can find the following information:
* Only users who are part of the SharePoint Owners group are considered Site Owners and can resolve tasks. **Site Admins cannot resolve tasks** and are not considered Site Owners.

:::

## Ask Members Action

The **Ask Members action** helps resolved orphaned workspace tasks by **asking workspace members to suggest new owners when no active owners exist**.

The Ask Members action is a two-stage process:

* **Stage One - Members suggest new owners**
* When the Ask Members action is triggered, e-mails and tasks are sent to all members of the workspace
* Members are asked to suggest one or more users as new owners
* Members can resolve the task directly from the e-mail they receive
* The suggestions are stored as members resolve their tasks, and stage one stays active until all members resolve their tasks

:::info

**Please note:**

**If the team has no members**, this action cannot be completed. In that case, the admins have to resolve the vulnerability by using one of the following actions;
* Add Owners
* Archive Workspace
* Delete Workspace

:::


* **Stage 2 - Resolving the task**
* After all members tasks are completed, a new task is created for admins or designated reviewers to take one of the following actions:
* **Add Owners**, by approving the suggestions made by members or deciding on an owner yourself
* Archive the workspace
* Delete the workspace

:::warning

For more details, on **how the Ask Members task resolution looks like from the perspective of members that receive the task**, [**take a look at the Resolve Orphaned Workspaces Tasks.**](../../point-collaborators/resolve-governance-tasks/orphaned-resources.md#members-suggest-new-owners)

:::

The **policy vulnerability is closed only after the second stage is resolved**. Collecting suggestions alone from members does not close the vulnerability.


## Designated Reviewers

**Designated reviewers are determined** using the following:
* Point tries to use the currently defined reviewers and respects existing policy settings
* If specific reviewers are are designed as custom recipients in the policy settings, the task is sent to them
* If the reviewer type is set to anything other than Point Admins or custom recipients, the task is sent to Point Admins
* If the reviewer type is set to Custom Recipients, but the recipient list is empty, the task defaults to Point Admins

**Tasks are sent to all workspace members**, if a Guest User is a member, they will receive the task as well and can submit suggestions.

**Users have 15 days to resolve Tasks**, after 15 days the second stage is triggered and the approval task is created.

**Users cannot become owners based on suggestion alone**, this decision needs to be approved during stage 2 by either a Point Admin or a specified designated reviewer.