> For the complete documentation index, see [llms.txt](https://docs.expel.io/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.expel.io/workbench-setup/auto-remediations/disable-accounts/microsoft-365-disable-accounts.md).

# Microsoft 365: Disable Accounts

*This guide is the first step of a larger process to enable auto remediations. After completing the steps on this page, you will be instructed to return to the* [*Enable an Auto Remediation in Workbench*](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md) *guide to finish your setup.*

## How It Works <a href="#h_01jh8ncdq41ghs4zvz4pj1n7wp" id="h_01jh8ncdq41ghs4zvz4pj1n7wp"></a>

If our SOC identifies an account (username or email address) that is compromised and must be disabled, Workbench completes the action automatically and logs the user out of their session. You have the option to restrict these actions to specific accounts by configuring an allow or deny list (the accounts must first be added as context, and then the list can be configured in Workbench; see [Step 2](#h_01jh5zhtqthkyym38xnhr25vgj)).

{% hint style="info" %}
Some vendors refer to disabling a user account as blocking a user, suspending a user, changing user status, removing a user from the org, or locking a user account.
{% endhint %}

## Scope and Limitations <a href="#h_01j7kypdqgb3n0715pj3hey31m" id="h_01j7kypdqgb3n0715pj3hey31m"></a>

When choosing to enable this auto remediation, remember the following:

* After a previously logged-in account is disabled, it can still access some resources until the access token expires and requires re-authentication. *Default expiration is 60 to 90 minutes after the disabling; as a result, it is possible for a user to remain logged in and to access some of the resources for up to 90 minutes after an account is disabled.*
* This auto remediation will not work on admin user accounts, or on any user who is assigned a privileged directory-level role or a privileged read-only role.
* While an account is disabled, the admin or user cannot reset the password. After the account is re-enabled, the account must be reset manually.

**If you have an on-prem Active Directory or hybrid Entra ID/ on-prem Active Directory environment**, consider the following safety precautions before enabling this auto remediation:

* This remediation action will perform Account Disablement in Entra ID and NOT in on-prem AD.&#x20;
* In hybrid environments, the On-prem AD configuration always takes precedence and is considered the "Source of Truth." Microsoft initiates automatic syncs from on-prem AD to Entra ID every 30-60 min.&#x20;
* For hybrid environments, the account disablement Expel pushes via Entra ID will be rolled back by Microsoft after the next sync. You must also lock the account in the on-prem environment before the next sync to keep the account locked.&#x20;
* **To safely disable accounts in on-prem or hybrid AD environments, Expel recommends using our Microsoft Defender for Endpoint: On-Prem/Hybrid Disable Accounts auto remediation. Enable this auto remediation via the** [**Microsoft Defender for Endpoint: Disable Accounts**](/workbench-setup/auto-remediations/disable-accounts/microsoft-defender-for-endpoint-disable-accounts.md) **setup guide.**

## Prerequisites <a href="#h_01jh8nq251nv5b8fbtex2jg713" id="h_01jh8nq251nv5b8fbtex2jg713"></a>

1. You must be an Azure admin for your organization, as you must have the ability to grant app permissions and add assignments.
2. You must have admin access in Workbench, as auto remediations are enabled at the organization level.

## Step 1: Grant Necessary Permissions <a href="#h_01jh8mnfygz4b6p8rhnyxm11nh" id="h_01jh8mnfygz4b6p8rhnyxm11nh"></a>

The option you choose in this section depends on how you initially [onboarded your Microsoft 365 device](/connect-your-technology/l-p-integrations/microsoft/microsoft-365-setup-for-workbench.md) in Workbench.

* If you chose to enable the Microsoft 365 integration, follow [Option 1](#h_01jh8n0bjdxxhn53r6j0t3zndk).
* If you chose to create a custom Azure application, follow [Option 2](#h_01jh8n0edbykrcyfnqfdyybw5n).

### Option 1 (Microsoft 365 Integrations) <a href="#h_01jh8n0bjdxxhn53r6j0t3zndk" id="h_01jh8n0bjdxxhn53r6j0t3zndk"></a>

**New installation**

No changes are required.

**Existing installation**

1. Open **Expel O365 Integration > API Permissions**.
2. Select the **Grant admin consent** button.
3. Consent to the new API permissions.

### Option 2 (Custom Azure Applications) <a href="#h_01jh8n0edbykrcyfnqfdyybw5n" id="h_01jh8n0edbykrcyfnqfdyybw5n"></a>

**New and existing installations**

1. Follow all previous API permission steps in [Microsoft 365 Setup for Workbench](/connect-your-technology/l-p-integrations/microsoft/microsoft-365-setup-for-workbench.md).
2. Add this Microsoft Graph application permission to your custom Azure application:
   * User.ReadWrite.All

     <div align="left"><figure><img src="/files/g62no5Na1aMEr55GkHZl" alt="User.ReadWrite.All is selected in the permissions list." width="337"><figcaption></figcaption></figure></div>
3. Verify `User.ReadWrite.All` is added, and then select **Grant admin consent**.

   <div align="left"><figure><img src="/files/3fkLuV0ZORjiRgIZoWzf" alt="The permission and Grant consent buttons are highlighted on the Configured permissions page." width="375"><figcaption></figcaption></figure></div>

## Step 2: Update Your Context <a href="#h_01jh5zhtqthkyym38xnhr25vgj" id="h_01jh5zhtqthkyym38xnhr25vgj"></a>

**If you do not want to specify any accounts for a "do not disable" or "always disable" list, and instead wish for Expel to automatically disable&#x20;*****all*****&#x20;identified accounts, skip to** [**Step 3**](#h_01jgycgywj4m9tc7j443dvsmf1)**.**

Working with your Customer Success Manager, prepare to create an allow or deny list by adding accounts as [org context](/workbench-reference/expel-terminology.md#org-context) for your environment. You will then be able to select those accounts as "Never disable" or "Always disable" assets when you enable the auto remediation in Workbench.

{% hint style="info" %}
If our SOC identifies an account that must be disabled and you have created either an allow ("Always disable") or deny ("Never disable") list in Workbench, any accounts falling outside of those parameters are assigned to you as actions rather than being disabled automatically.
{% endhint %}

## Step 3: Return to the Main Setup Guide <a href="#h_01jgycgywj4m9tc7j443dvsmf1" id="h_01jgycgywj4m9tc7j443dvsmf1"></a>

Your Microsoft 365 device is now ready for the Disable Accounts auto remediation. You should now do one of the following:

* **If you do not need to set up any other devices for this auto remediation**, you can return to the [Enable an Auto Remediation in Workbench](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md) guide to finish Step 2 of the process.
* **If you need to set up additional devices for this auto remediation, or wish to use this device with multiple auto remediations**, be sure to [complete those setup guides as well](/workbench-setup/auto-remediations.md) before returning to the [Enable an Auto Remediation in Workbench](/workbench-setup/auto-remediations/enable-an-auto-remediation-in-workbench.md) guide to finish Step 2 of the process. *Make sure to follow the setup guide that is specific to your auto remediation, as device setup instructions are unique to each auto remediation and device.*


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://docs.expel.io/workbench-setup/auto-remediations/disable-accounts/microsoft-365-disable-accounts.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
