You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/active-directory/external-identities/external-collaboration-settings-configure.md
+13-3Lines changed: 13 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,7 +6,7 @@ services: active-directory
6
6
ms.service: active-directory
7
7
ms.subservice: B2B
8
8
ms.topic: how-to
9
-
ms.date: 05/05/2022
9
+
ms.date: 08/22/2022
10
10
11
11
ms.author: mimart
12
12
author: msmimart
@@ -42,13 +42,13 @@ For B2B collaboration with other Azure AD organizations, you should also review
42
42
43
43
-**Guest users have limited access to properties and memberships of directory objects**: (Default) This setting blocks guests from certain directory tasks, like enumerating users, groups, or other directory resources. Guests can see membership of all non-hidden groups. [Learn more about default guest permissions](../fundamentals/users-default-permissions.md#member-and-guest-users).
44
44
45
-
-**Guest user access is restricted to properties and memberships of their own directory objects (most restrictive)**: With this setting, guests can access only their own profiles. Guests are not allowed to see other users' profiles, groups, or group memberships.
45
+
-**Guest user access is restricted to properties and memberships of their own directory objects (most restrictive)**: With this setting, guests can access only their own profiles. Guests aren't allowed to see other users' profiles, groups, or group memberships.
46
46
47
47
1. Under **Guest invite settings**, choose the appropriate settings:
-**Anyone in the organization can invite guest users including guests and non-admins (most inclusive)**: To allow guests in the organization to invite other guests including those who are not members of an organization, select this radio button.
51
+
-**Anyone in the organization can invite guest users including guests and non-admins (most inclusive)**: To allow guests in the organization to invite other guests including those who aren't members of an organization, select this radio button.
52
52
-**Member users and users assigned to specific admin roles can invite guest users including guests with member permissions**: To allow member users and users who have specific administrator roles to invite guests, select this radio button.
53
53
-**Only users assigned to specific admin roles can invite guest users**: To allow only those users with administrator roles to invite guests, select this radio button. The administrator roles include [Global Administrator](../roles/permissions-reference.md#global-administrator), [User Administrator](../roles/permissions-reference.md#user-administrator), and [Guest Inviter](../roles/permissions-reference.md#guest-inviter).
54
54
-**No one in the organization can invite guest users including admins (most restrictive)**: To deny everyone in the organization from inviting guests, select this radio button.
@@ -59,6 +59,16 @@ For B2B collaboration with other Azure AD organizations, you should also review
59
59
60
60

61
61
62
+
1. Under **External user leave settings**, you can control whether external users can remove themselves from your organization. If you set this option to **No**, external users will need to contact your admin or privacy contact to be removed.
63
+
64
+
-**Yes**: Users can leave the organization themselves without approval from your admin or privacy contact.
65
+
-**No**: Users can't leave your organization themselves. They'll see a message guiding them to contact your admin or privacy contact to request removal from your organization.
66
+
67
+
> [!IMPORTANT]
68
+
> You can configure **External user leave settings** only if you have [added your privacy information](../fundamentals/active-directory-properties-area.md) to your Azure AD tenant. Otherwise, this setting will be unavailable.
69
+
70
+

71
+
62
72
1. Under **Collaboration restrictions**, you can choose whether to allow or deny invitations to the domains you specify and enter specific domain names in the text boxes. For multiple domains, enter each domain on a new line. For more information, see [Allow or block invitations to B2B users from specific organizations](allow-deny-list.md).
Copy file name to clipboardExpand all lines: articles/active-directory/external-identities/leave-the-organization.md
+63-19Lines changed: 63 additions & 19 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,7 +7,7 @@ services: active-directory
7
7
ms.service: active-directory
8
8
ms.subservice: B2B
9
9
ms.topic: how-to
10
-
ms.date: 06/30/2022
10
+
ms.date: 08/22/2022
11
11
12
12
ms.author: mimart
13
13
author: msmimart
@@ -19,46 +19,90 @@ adobe-target: true
19
19
20
20
# Leave an organization as an external user
21
21
22
-
An Azure Active Directory (Azure AD) B2B collaboration or B2B direct connect usercan decide to leave an organization at any time if they no longer need to use apps from that organization or maintain any association.
22
+
As an Azure Active Directory (Azure AD) B2B collaboration or B2B direct connect user, you can decide to leave an organization at any time if you no longer need to use apps from that organization or maintain any association.
23
23
24
-
B2B collaboration and B2B direct connect users can usually leave an organization on their own without having to contact an administrator. This option won't be available if it's not allowed by the organization, or if the user's account has been disabled. The user will need to contact the tenant admin, who can delete the account.
24
+
You can usually leave an organization on your own without having to contact an administrator. However, in some cases this option won't be available and you'll need to contact your tenant admin, who can delete your account in the external organization.
In your My Account portal, on the Organizations page, you can view and manage the organizations you have access to:
31
-
32
-
-**Home organization**: Your home organization is listed first. This is the organization that owns your work or school account. Because your account is managed by your administrator, you're not allowed to leave your home organization. (If you don't have an assigned home organization, you'll just see a single heading that says Organizations with the list of your associated organizations.)
33
-
34
-
-**Other organizations you collaborate with**: You'll also see the other organizations that you've signed in to previously using your work or school account. You can leave any of these organizations at any time.
35
-
36
-
To leave an organization, follow these steps.
37
-
38
-
1. Go to your **My Account** page by doing one of the following:
30
+
1. To view the organizations you belong to, first open your **My Account** page by doing one of the following:
39
31
40
32
- If you're using a work or school account, go to https://myaccount.microsoft.com and sign in.
41
33
- If you're using a personal account, go to https://myapps.microsoft.com and sign in, and then select your account icon in the upper right and select **View account**. Or, use a My Account URL that includes your tenant information to go directly to your My Account page (examples are shown in the following note).
34
+
42
35
> [!NOTE]
43
36
> If you use the email one-time passcode feature when signing in, you'll need to use a My Account URL that includes your tenant name or tenant ID, for example: `https://myaccount.microsoft.com?tenantId=wingtiptoys.onmicrosoft.com` or `https://myaccount.microsoft.com?tenantId=ab123456-cd12-ef12-gh12-ijk123456789`.
44
37
45
38
1. Select **Organizations** from the left navigation pane or select the **Manage organizations** link from the **Organizations** block.
46
39
47
-
1. Under **Other organizations you collaborate with**, find the organization that you want to leave, and select **Leave**.
40
+
1. The **Organizations** page appears, where you can view and manage the organizations you belong to.
41
+
42
+

43
+
44
+
-**Home organization**: Your home organization is listed first. This is the organization that owns your work or school account. Because your account is managed by your administrator, you're not allowed to leave your home organization (you'll see there's no option to **Leave**). If you don't have an assigned home organization, you'll just see a single heading that says **Organizations** with the list of your associated organizations.
45
+
46
+
-**Other organizations you collaborate with**: You'll also see the other organizations that you've signed in to previously using your work or school account. You can decide to leave any of these organizations at any time.
47
+
48
+
## How to leave an organization
49
+
50
+
If your organization allows users to remove themselves from external organizations, you can follow these steps to leave an organization.
51
+
52
+
1. Open your **Organizations** page. (Follow the steps in [What organizations do I belong to](#what-organizations-do-i-belong-to), above.)
53
+
54
+
1. Under **Other organizations you collaborate with** (or **Organizations** if you don't have a home organization), find the organization that you want to leave, and then select **Leave**.
48
55
49
56

57
+
50
58
1. When asked to confirm, select **Leave**.
59
+
1. If you select **Leave** for an organization but you see the following message, it means you’ll need to contact the organization's admin or privacy contact and ask them to remove you from their organization.
60
+
61
+

62
+
63
+
## Why can’t I leave an organization?
64
+
65
+
In the **Home organization** section, there's no option to **Leave** your organization. Only an administrator can remove your account from your home organization.
51
66
52
-
## Account removal
67
+
For the external organizations listed under **Other organizations you collaborate with**, you might not be able to leave on your own, for example when:
53
68
54
-
When a B2B collaboration user leaves an organization, the user's account is "soft deleted" in the directory. By default, the user object moves to the **Deleted users** area in Azure AD, but permanent deletion doesn't start for 30 days. This soft deletion enables the administrator to restore the user account, including groups and permissions, if the user makes a request to restore the account before it's permanently deleted.
69
+
70
+
- the organization you want to leave doesn’t allow users to leave by themselves
71
+
- your account has been disabled
72
+
73
+
In these cases, you can select **Leave**, but then you'll see a message saying you need to contact the admin or privacy contact for that organization to ask them to remove you.
74
+
75
+
## More information for administrators
76
+
77
+
Administrators can use the **External user leave settings** to control whether external users can remove themselves from their organization. If you disallow the ability for external users to remove themselves from your organization, external users will need to contact your admin or privacy contact to be removed.
78
+
79
+
> [!IMPORTANT]
80
+
> You can configure **External user leave settings** only if you have [added your privacy information](../fundamentals/active-directory-properties-area.md) to your Azure AD tenant. Otherwise, this setting will be unavailable. We recommend adding your privacy information to allow external users to review your policies and email your privacy contact when necessary.
81
+
82
+
1. Sign in to the [Azure portal](https://portal.azure.com) using a Global administrator account and open the Azure Active Directory service.
1. Under **External user leave** settings, choose whether to allow external users to leave your organization themselves:
87
+
88
+
-**Yes**: Users can leave the organization themselves without approval from your admin or privacy contact.
89
+
-**No**: Users can't leave your organization themselves. They'll see a message guiding them to contact your admin or privacy contact to request removal from your organization.
90
+
91
+

92
+
93
+
### Account removal
94
+
95
+
When a B2B collaboration user leaves an organization, the user's account is "soft deleted" in the directory. By default, the user object moves to the **Deleted users** area in Azure AD, but permanent deletion doesn't start for 30 days. This soft deletion enables the administrator to restore the user account, including groups and permissions, if the user makes a request to restore the account before it's permanently deleted.
55
96
56
97
If desired, a tenant administrator can permanently delete the account at any time during the soft-delete period with the following steps. This action is irrevocable.
57
98
58
99
1. In the [Azure portal](https://portal.azure.com), select **Azure Active Directory**.
59
-
2. Under **Manage**, select **Users**.
60
-
3. Select **Deleted users**.
61
-
4. Select the check box next to a deleted user, and then select **Delete permanently**.
100
+
101
+
1. Under **Manage**, select **Users**.
102
+
103
+
1. Select **Deleted users**.
104
+
105
+
1. Select the check box next to a deleted user, and then select **Delete permanently**.
62
106
63
107
Once permanent deletion begins, whether it's initiated by the admin or the end of the soft deletion period, it can take up to an additional 30 days for data removal ([learn more](/compliance/regulatory/gdpr-dsr-azure#step-5-delete)).
0 commit comments