> For the complete documentation index, see [llms.txt](https://helpdesk.augmentt.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://helpdesk.augmentt.com/stonly-import-engage/user-management.md).

# User Management

*Source guide title in Stonly: "Engage functionality".*

* Works with both Microsoft Entra and Google Workspace
* Saves time by providing multi-tenant access without jumping in and out of Microsoft and Google portals
* Promotes best practices, avoids human error, and provides audit of actions taken
* Protects the integration account from being modified by the module

## Engage platform support

| Action                                  | Microsoft 365 | Google Workspace |
| --------------------------------------- | ------------- | ---------------- |
| Create user                             | Yes           | Yes              |
| Offboard user                           | Yes           | Yes              |
| Schedule offboarding (Engage Autopilot) | Yes           | No               |
| Reset password                          | Yes           | Yes              |
| Force sign-out of all apps              | Yes           | Yes              |
| Block / suspend sign-in                 | Yes           | No               |
| Re-register MFA                         | Yes           | No               |
| Manage groups                           | Yes           | Yes              |
| Manage licenses                         | Yes           | Yes              |
| Manage shared mailboxes                 | Yes           | No               |
| Manage distribution lists               | Yes           | No               |
| Manage Out of Office replies            | Yes           | No               |
| Manage email forwarding                 | Yes           | No               |
| Create Temporary Access Pass (TAP)      | Yes           | No               |
| Block from Global Address List          | Yes           | No               |
| View and edit user details              | Yes           | Yes              |

## Enabling co-managed security and least-privileged access

Engage allows MSPs to apply least-privileged-access best practices by letting them assign L1 technicians to do more basic operations in a tenant's environment using a limited set of tools that can be audited instead of having the techs jump in and out of various tenants in Microsoft's Entra portal or Google Workspace.

Similarly in co-managed relationships, MSPs can create system users for employees within their tenants who can do basic onboarding, offboarding, resetting passwords, and so forth without even involving the MSP's techs. Tenants are happy because they can get simple things done more expediently, and MSP L1 techs face fewer tickets. Win, win.

## Creating new employees or adding users

Start by clicking the **Create new employee** button (**Add user** for Google Workspace).

1. **Add employee** — fill out basic information on the first of three data-entry pages.
2. **Account details** — set their new email address, what groups they belong in, etc.
3. **Assign license** — decide which licenses the new user will have.
4. **Review & finish** — double check to ensure all the details are correct, hit next, and you have a new user.

## Suspending or blocking sign-in

> This feature is not supported for Google Workspace Integration.

Blocking someone prevents anyone from signing in as the user and is a good idea when you think their password or username may have been compromised. When you block someone, it immediately stops any new sign-ins for that account. If they're already signed in, they'll be automatically signed out from all Microsoft services within 60 minutes.

Even though it can't be signed into, the account continues to receive mail and retains all data.

1. Select the box to the left of the user you wish to block
2. Click the **Block sign-in** button at the top
3. Accept the account change in the pop-up box

## Re-register MFA

> This feature is not supported for Google Workspace Integration.

You can use Engage to re-register a user's multi-factor authentication (MFA). This action resets the user's existing MFA methods, allowing them to configure a new preferred authentication method on their next sign-in.

1. Select the checkbox next to the user.
2. Click **Re-register MFA** at the top of the page.
3. Confirm the action in the pop-up window.

Once completed, the user will be prompted to set up MFA again during their next login.

## Resetting passwords

Resetting someone's password prevents anyone from signing into their account using the old password. It is often used when the user has forgotten their password, but it can also be a good idea when you think their password or username may have been compromised.

1. Select the box to the left of the user whose password you wish to reset
2. Click the **Reset Password** button at the top

In the dialogue pop-up box, accept the account change by:

* Choosing whether to automatically or manually generate the new password
* Deciding to whom the new password should be sent

## Forcing sign-out of all applications

Forcing sign-out of all applications prevents anyone with access to a device that was previously signed in from remaining signed in. It can be helpful when a user loses or steps away from a device. It does not prevent them from immediately signing back in, and it does not have an effect on their password or any of their content.

1. Select the small box to the left of the user you wish to force sign-out
2. Click the **Sign-out of All Apps** button at the top

There is no pop-up seeking confirmation, only one telling you if the sign-out has taken place successfully.

## Managing groups and shared mailboxes

Engage makes it easy for technicians to manage groups and shared mailboxes. Click on the small box to the left of the user to adjust, then on **Manage** (**Manage Groups** in Google Workspace).

Groups can be managed for both Microsoft 365 and Google Workspace users. Shared mailboxes are an Exchange object, so that action is only available for Microsoft 365 users.

## Offboarding users

To remove a user, first click the small box to the left of the user's name. Then hit the **Remove User** button in the top right. The user will not actually be removed until clicking on the confirmation dialogue box after all the settings are in place and confirmed.

### Offboard options

When offboarding a user, email and mailbox management options are presented as the first step in the process. These options allow you to manage email continuity, mailbox access, and directory visibility before completing the offboarding.

Available options include:

* Make the user's email aliases immediately available
* Remove delegate access from the user's mailbox
* Hide the user from the Global Address List (GAL)
* Convert the mailbox to a shared mailbox
* Send automatic replies
* Forward email to another mailbox
* Remove or retain the user's access to shared mailboxes

Security best practices are also integrated into the workflow. You can perform the following security actions:

* Unassign all Microsoft or Google licenses
* Reset the user's password
* Sign the user out of all applications
* Block the user from signing in

After selecting the desired actions, click **Next** to review and finalize the offboarding process.

### Scheduled offboarding

For customers with an Engage Autopilot license, an option to **Schedule** the offboarding will appear at the top of the workflow. By default, offboarding is set to **Now**, but you can switch to **Schedule** to select a future date and time.

When scheduling is selected, you can:

* Choose the date and time for the offboarding to run
* View the configured time zone
* Enable notifications to create an alert upon successful completion
* Enable notifications to create an alert if the offboarding fails

Scheduled tasks run automatically at the selected time and execute all configured offboarding actions.

If the Engage Autopilot license is not assigned, the scheduling option will not be available, and offboarding can only be executed immediately.

## Viewing and editing users' details

Augmentt Engage makes it easy to view and edit employees' information. Click a user's name from most parts of the Augmentt application to open a side panel with:

* Security information — sign-in status, MFA, license, and risk signals
* Profile, group, and licensing details
* Quick actions that can be performed on the user
* An **Edit** button to update the user's profile properties, group memberships, and licenses in one place

Augmentt user profiles combine actions and fields from different parts of your Entra and Exchange admin centers into one convenient location.

## Create TAP

A Temporary Access Pass (TAP) is a time-limited, Microsoft-issued passcode that lets a user sign in and register an authentication method — without needing their existing password or an existing MFA method. It's the right tool when a user is locked out, onboarding for the first time, or recovering a broken phone.

1. Select the box to the left of the user who needs a pass
2. Click the **Create TAP** button at the top
3. Choose a lifetime for the pass and whether it's single-use or multi-use
4. Click **Create**
5. Copy the pass shown in the confirmation dialogue and deliver it to the user via a channel you trust

TAPs are governed by the tenant's Temporary Access Pass authentication method policy. If the button greys out or creation fails, check that the policy is enabled for the user or their group in Entra.

TAPs are an Entra ID feature, so this action is only available for Microsoft 365 users.

## Block Global Address List

Hiding a user from the Global Address List (GAL) removes them from Exchange address-book lookups, distribution-list expansions, and Outlook directory search — without disabling the mailbox or blocking sign-in. It's the right move when someone has left a department, is on long-term leave, or needs to stop receiving internal mail routed via the GAL, but you still want their mailbox active.

1. Select the box to the left of the user you want to hide
2. Click the **Block GAL** button at the top
3. Confirm the change in the pop-up box

Microsoft Exchange's offline address book cache can take up to 24 hours to refresh in Outlook clients, so the user may continue to appear in colleague autocompletes until the cache rebuilds.

This action writes to the user's Exchange recipient object, so it is only available for Microsoft 365 users.

## Manage Licenses

You can use Engage to manage licenses assigned to a user directly from the platform. This allows administrators to quickly assign or remove licenses based on user requirements.

1. Select the user from the user list.
2. Click **Manage Licenses** at the top of the page.
3. In the pop-up window, review the list of available licenses for the tenant.
4. Select or deselect licenses as needed.
5. Save your changes.

The user's licenses will be updated based on your selection.

## Managing Out of Office replies

Set up or update a user's out-of-office auto-reply directly from Engage, without bouncing into the Exchange admin center. Useful for last-minute departures, scheduled leave, or offboarding handoffs where you want mail to land softly.

1. Select the box to the left of the user whose Out of Office you want to configure
2. Click the **Manage Out of Office** button at the top
3. Choose whether the reply should be active immediately or scheduled for a future window, with an optional end date
4. Enter the internal message (seen by colleagues) and, if needed, a separate external message for senders outside the tenant
5. Click **Save**

This action writes to the user's Exchange mailbox, so it is only available for Microsoft 365 users.

## Managing email forwarding

Forward a user's incoming mail to another internal or external address. Handy during offboarding when you want messages to reach a manager without keeping the user's sign-in active, or when covering leave without granting delegate access.

1. Select the box to the left of the user whose forwarding you want to configure
2. Click the **Manage Email Forwarding** button at the top
3. Enter the forwarding address
4. Choose whether to keep a copy of each message in the user's mailbox
5. Click **Save**

Forwarding is configured on the Exchange mailbox, so it is only available for Microsoft 365 users.

## Managing distribution lists

Create, edit, and remove Microsoft distribution lists across your tenants from **Engage → Distribution Lists**, without hopping between Exchange admin centers. Membership and ownership changes are applied consistently and captured in Augmentt's audit log.

For the complete walk-through with screenshots, see the dedicated Distribution Lists article.

Distribution lists are an Exchange object, so this action is only available for Microsoft 365 users.


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://helpdesk.augmentt.com/stonly-import-engage/user-management.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
