> For the complete documentation index, see [llms.txt](https://helpdesk.augmentt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://helpdesk.augmentt.com/modules/engage/user-management.md).

# User Management

Engage is the module you use to manage user lifecycle across your customers' Microsoft 365 and Google Workspace tenants — onboarding, offboarding, password resets, MFA, and the everyday account admin your L1 techs handle most often. Instead of jumping between the Entra admin center, the Google Workspace admin console, and Exchange, you do it all from one multi-tenant screen in Augmentt, and every action is captured in Augmentt's audit log.

{% hint style="info" %}
Engage supports both Microsoft 365 and Google Workspace, but the two platforms don't have feature parity. Several actions are Microsoft-only because they depend on Exchange or Entra ID objects — mailboxes, Temporary Access Passes, and the Global Address List — that don't have a Google Workspace equivalent exposed through the admin API.
{% endhint %}

## Why use Engage instead of the native admin portals

* **One pane of glass across tenants.** You don't have to sign in to each customer's Entra or Google Workspace portal separately to do routine account work.
* **Least-privileged access for your team.** You can let L1 technicians perform a limited, audited set of actions without giving them broad admin rights in a customer's tenant.
* **Self-service for co-managed customers.** In co-managed relationships, a customer's own IT staff can do basic onboarding, offboarding, and password resets themselves — fewer tickets land on your desk.
* **Consistency and an audit trail.** Actions taken through Engage are logged, so you have a record of who did what and when.

## What you can do, by platform

| Action                                  | Microsoft 365 | Google Workspace |
| --------------------------------------- | ------------- | ---------------- |
| Create user                             | Yes           | Yes              |
| Offboard user                           | Yes           | Yes              |
| Schedule offboarding (Engage Autopilot) | Yes           | No               |
| Reset password                          | Yes           | Yes              |
| Force sign-out of all apps              | Yes           | Yes              |
| Block / suspend sign-in                 | Yes           | No               |
| Re-register MFA                         | Yes           | No               |
| Manage groups                           | Yes           | Yes              |
| Manage licenses                         | Yes           | Yes              |
| Manage shared mailboxes                 | Yes           | No               |
| Manage distribution lists               | Yes           | No               |
| Manage Out of Office replies            | Yes           | No               |
| Manage email forwarding                 | Yes           | No               |
| Create Temporary Access Pass (TAP)      | Yes           | No               |
| Block from Global Address List (GAL)    | Yes           | No               |
| View and edit user details              | Yes           | Yes              |

## Creating a new user

Click **Create new employee** (Microsoft 365) or **Add user** (Google Workspace) and step through the wizard: basic profile details, account and group settings, license assignment, and a final review before the account is created.

{% hint style="warning" %}
Some partners have reported that account creation appears to time out or show a failure when the target user's display name contains a special character — even though the account is created successfully in Microsoft 365 and shows up in Engage's employee list afterward. If a creation shows an error but the user then appears in your employee list, check the tenant directly before assuming the account wasn't created.
{% endhint %}

## Viewing and editing user details

Click any user's name from most places in Augmentt to open a side panel showing:

* Security information — sign-in status, MFA state, license, and risk signals
* Profile, group, and licensing details
* Quick actions you can take on that user
* An **Edit** button to update profile properties, group memberships, and licenses in one place

{% hint style="warning" %}
Not yet re-verified against the codebase — flagged for fact-check: inline editing of Entra profile attributes (job title, department, manager, office location, etc.) directly in this side panel is a newer addition. Confirm it's live on your instance before documenting it as current behavior in customer-facing material.
{% endhint %}

## Resetting a password

Resetting a password immediately invalidates the old one. Use it when a user is locked out or you suspect their credentials are compromised.

1. Select the checkbox next to the user.
2. Click **Reset Password**.
3. Choose whether to auto-generate the new password or set one manually, and decide who receives it.

## Forcing sign-out of all applications

Forces a user out of every active session — useful if a device was left signed in or lost. It does **not** change the password and does not stop the user from signing back in immediately; pair it with a password reset or a sign-in block if you need to fully lock the account down.

## Blocking / suspending sign-in

Blocking prevents any new sign-in as that user. Existing sessions are cut within roughly 60 minutes as Microsoft revokes tokens. The mailbox keeps receiving mail and retains its data — blocking is a sign-in control, not a deletion.

## Re-registering MFA

Resets a user's existing MFA methods so they're prompted to set up a new one on next sign-in. Not available for Google Workspace.

{% hint style="warning" %}
If the **Re-register MFA** or **Create TAP** buttons are greyed out, or the action fails with a permissions error even though your GDAP role assignment looks correct (Authentication Administrator, Privileged Authentication Administrator, etc. all present), check the tenant's own Temporary Access Pass / authentication methods policy in Entra — the action can be blocked by tenant-level policy rather than by Augmentt's permissions. See the gotchas section below.
{% endhint %}

## Creating a Temporary Access Pass (TAP)

A TAP is a time-limited, Microsoft-issued passcode that lets a user sign in and register an authentication method without their password or an existing MFA method — useful for lockouts, first-time onboarding, or a lost/broken authenticator device.

1. Select the user.
2. Click **Create TAP**.
3. Choose a lifetime and whether it's single-use or multi-use.
4. Click **Create**, then copy the pass from the confirmation dialog and deliver it to the user through a trusted channel.

TAPs are governed by the tenant's own Temporary Access Pass policy in Entra — if creation fails or the button is disabled, that policy is the first place to check.

{% hint style="warning" %}
After creating a TAP, the generated code is shown once in the confirmation dialog. If you don't see it, check that you haven't dismissed that dialog before copying it — Engage doesn't currently show the code again afterward. Not yet re-verified against the codebase whether there's a way to retrieve a previously issued TAP; treat "copy it immediately" as the safe assumption until confirmed.
{% endhint %}

## Managing licenses

Assign or remove licenses for a user directly from Engage rather than the M365 or Google admin portal:

1. Select the user.
2. Click **Manage Licenses**.
3. Select or deselect licenses in the pop-up.
4. Save.

{% hint style="info" %}
"Engage licenses" (the Augmentt licenses that grant Engage functionality for a tenant) are a separate concept from the Microsoft 365 or Google Workspace licenses you assign to a user's mailbox or account. Don't confuse the two when troubleshooting a license question — see the gotchas below.
{% endhint %}

## Managing groups and shared mailboxes

Select a user and click **Manage** (**Manage Groups** for Google Workspace) to add or remove group memberships. Shared mailboxes are an Exchange object, so that part of the action is Microsoft 365 only.

## Blocking a user from the Global Address List (GAL)

Hides a user from Exchange address-book lookups, distribution-list expansions, and Outlook directory search, without disabling the mailbox or blocking sign-in. Useful for someone on long-term leave or who's changed roles but still needs an active mailbox.

{% hint style="info" %}
Outlook's offline address book cache can take up to 24 hours to refresh, so a user you've blocked from the GAL may still show up briefly in colleagues' autocomplete while that cache catches up.
{% endhint %}

## Managing Out of Office replies and email forwarding

Both are configured on the Exchange mailbox directly from Engage, so both are Microsoft 365 only:

* **Out of Office** — set an internal message, an optional separate external message, and either an immediate or scheduled active window.
* **Email forwarding** — forward incoming mail to another address, with the option to keep a copy in the original mailbox.

## Offboarding a user

Select the user and click **Remove User**. The offboarding wizard walks you through a set of options before anything is actually applied:

* Make the user's email aliases immediately available
* Remove delegate access from the user's mailbox
* Hide the user from the GAL
* Convert the mailbox to a shared mailbox
* Send automatic replies
* Forward email to another mailbox
* Remove or retain access to shared mailboxes
* Unassign all Microsoft or Google licenses
* Reset the password, sign the user out of everywhere, and block sign-in

Nothing takes effect until you confirm at the end of the wizard.

### Scheduled offboarding (Engage Autopilot)

If a tenant has an Engage Autopilot license, you get a **Schedule** option at the top of the offboarding workflow instead of running it immediately. You can pick a future date and time, confirm the time zone, and turn on success/failure notifications. Without an Autopilot license assigned, offboarding can only run immediately — the schedule option won't appear.

{% hint style="warning" %}
Multiple customers have reported that a scheduled offboarding doesn't start exactly at the scheduled time — delays of ten to twenty minutes (or more) between the scheduled time and execution have been reported, even with the tenant's time zone confirmed correct. If a scheduled offboarding needs to take effect at a precise moment (for example, coordinated with an employee's last day), don't rely on the schedule for that precision — run it manually at the required time instead. See the gotchas section below.
{% endhint %}

{% hint style="warning" %}
Not yet re-verified against the codebase — flagged for fact-check: whether scheduled offboarding is available per-tenant based on licensing at the MSP's own primary tenant versus each managed customer tenant individually. If scheduling appears in your own tenant but not in a client tenant, check that tenant's own Engage Autopilot license assignment before assuming it's a bug.
{% endhint %}

## Gotchas from real support cases

* **Scheduled offboarding running late.** This is the single most-reported Engage issue: an offboarding scheduled for a specific time doesn't kick off until well after — sometimes 15-20+ minutes later. If a scheduled offboarding needs to align tightly with a specific moment (an employee's last minute of access on their final day, for instance), treat the schedule as approximate and either build in a buffer or run the offboarding manually at the exact time you need it.
* **"Failed" offboarding notifications that aren't really failures.** A few customers have seen an offboarding flagged as failed when, in fact, every substantive action (mailbox conversion, license removal, group removal) succeeded — the only thing that failed was sending a password-reset notification email, often because the account being offboarded was an unlicensed system/integration account with no mailbox to email. If an offboarding shows as failed, check what actually happened in the tenant (and the audit log) before assuming nothing was applied — the failure is sometimes just the notification step, not the offboarding itself.
* **Offboarding doesn't remove Microsoft 365 licenses by default.** Unassigning licenses is one of the checkboxes in the offboarding wizard, not something that happens automatically — if a customer says "we offboarded the user but they still have their license," check whether that option was selected during the wizard.
* **Offboarding doesn't currently hand off OneDrive access.** Engage's offboarding flow covers mailbox and group actions, but it doesn't include a built-in option to grant another user delegated/read access to the offboarded user's OneDrive. If you need that, you'll still need to do it through the Microsoft 365 admin center or Graph directly.
* **Overassigned Engage licenses after a trial.** It's common for a large number of Engage user licenses to end up assigned across many tenants by the end of a trial period. There isn't a single bulk "unassign everywhere" action from the Engage employee list — expect to review and correct this tenant by tenant, or ask support for help doing it in bulk if you're managing a large number of tenants.
* **MFA re-registration or TAP creation blocked despite correct GDAP roles.** If re-registering MFA or creating a TAP fails with a permissions error even though the tenant's GDAP relationship and role assignments all look correct, check the tenant's own Temporary Access Pass / authentication methods policy in Entra ID — it can silently block the action independent of what roles Augmentt's integration account holds.
* **Post-provisioning automation (scripts) against Engage-created users.** At least one partner found that a PowerShell script used to add shared calendars to a new hire's Outlook worked when the user was created directly in the M365 admin center, but silently didn't take effect for users created through Engage — the script reported success but the calendars never appeared. If you run your own post-onboarding automation, test it specifically against Engage-created accounts rather than assuming parity with manually created ones.
* **Google Workspace test-account creation stalling on the license step.** A couple of first-time Google Workspace Engage users reported the license-selection step of user creation showing no options and blocking them from proceeding, and new accounts created directly in the Google Admin console not appearing in Engage even after a manual sync. If you hit this, re-check the Google Workspace integration's sync status and license configuration before assuming it's a one-off.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://helpdesk.augmentt.com/modules/engage/user-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
