Automated Escalation Profile for Microsoft 365 Groups

    An automated escalation profile allows you to define how to manage a Microsoft 365 Group when a group lifecycle task, which is the inactivity threshold task or lease expiration task, is not completed within the specified time. You can define the escalation of the incomplete lifecycle task into one or two stages, and specify the different escalation action for each stage. To configure a group automated escalation profile, click Automated Escalation Profile for Microsoft 365 Groups in the Settings > Request Management group. Click Create on the ribbon, and then complete the following steps:

    1. Name and Description – Specify a name and an optional description for the group automated escalation profile.

    2. Stage One – Configure how to manage a group when the group lifecycle task is not completed within the specified time. Choose one of the following two escalation actions from the drop-down list as the first stage escalation:

      • Restrict access to the group – With the option selected, enter a number in the text box and select Day(s), Week(s), Month(s), Year(s) as the unit of time. If a group lifecycle task has not been completed after the specified period of time, access to the group will be restricted. To manage the group membership and group team site permissions when the group access is restricted, configure the following settings:

        • Remove all group members – Select this option to remove all group members when access to a group is restricted.

        • Change group owners – Choose to Remove all group owners or Demote all group owners to group members when access to a group is restricted.

          If you choose to change group owners, you must enter at least one username in the text box to specify users to take over the group owner role. If none of the specified users can be found in the Microsoft 365 tenant, the account that is used to create the Microsoft Entra ID app profile, the account in the service account pool, or the service account will become the group owner.

        • Change group team site permissions – If you choose to change group team site permissions, select one of the following results when access to a group is restricted. A restricted access group can be activated in the modern Cloud Governance admin center. If you choose to change the group team site permissions, note the corresponding restore results for the group team site:

          • Make the site read-only for group members – When a restricted access group is activated, group members’ permissions will be restored.

          • Make the site read-only for all users except the group owners – When a restricted access group is activated, users’ permissions to the group team site will not be restored.

          • Remove all site permissions from users except the group owners – When a restricted access group is activated, users’ permissions to the group team site will not be restored.

          • Lock the group team site – Choose to Lock the site in “no access” status or Lock the site in “read-only” status. The group team site will be unlocked when a restricted access group is activated.

        • You can choose to Send a reminder email to the task assignees before the escalation, and then select a reminder profile from the drop-down list or click Create new to create a new one if there is no existing profile.

        • You can choose to notify specific people when the escalation action is executed, and then specify users as the email notification recipients. You can also enter $ to select from available user roles. Then, select an email template from the drop-down list, and the escalation notification email will be sent in your selected email template.

        NOTE

        If you choose Restrict access to the group as the escalation action, you can configure the second stage escalation.

      • Delete the group – With the option selected, enter a number in the text box and select Day(s), Week(s), Month(s), Year(s) as the unit of time. If a group lifecycle task has not been completed after the specified period of time, the group will be deleted. Then, configure the following settings:

        • You can choose to Use a unique approval process for this automated action, and then select an approval process from the drop-down list or click Create new to create a new one if there is no existing approval process.

        • You can choose to Send a reminder email to the task assignees before the escalation, and then select a reminder profile from the drop-down list or click Create new to create a new one if there is no existing profile.

        • You can choose to notify specific people when the escalation action is executed, and then specify users as the email notification recipients. You can also enter $ to select from available user roles. Then, select an email template from the drop-down list, and the escalation notification email will be sent in your selected email template.

        NOTE

        If the group automatic deletion is selected as the escalation, you must activate the built-in Group/Team Lifecycle Management – Delete Service.

    3. Stage Two – When you choose Restrict access to the group as the first stage escalation action for the incomplete group lifecycle task, you can choose to Delete the group as the second stage escalation, or not take any further action after the first stage escalation. When you choose to delete the group, configure the following settings:

      • Enter a number in the text box and select Day(s), Week(s), Month(s), Year(s) as the unit of time. After the first stage escalation action has been completed after the specified period of time, the group will be deleted.

      • You can choose to Use a unique approval process for this automated action, and then select an approval process from the drop-down list or click Create new to create a new one if there is no existing approval process.

      • You can choose to Send a reminder email to the task assignees before the escalation, and then select a reminder profile from the drop-down list or click Create new to create a new one if there is no existing one.

      • You can choose to notify specific people when the escalation action is executed, and then specify users as the email notification recipients. You can also enter $ to select from available user roles. Then, select an email template from the drop-down list, and the escalation notification email will be sent in your selected email template.

        NOTE

        If the group automatic deletion is selected as the escalation, you must activate the built-in Group/Team Lifecycle Management – Delete Service.

    4. Click Save to save all your configurations.