Jump to content

Recommended Posts

Posted

Hi Guys

 

We're hosting all our user files in OneDrive now and I've only just thought about what we're doing for leavers files. Staff and students.

 

Previously we'd take the staff or student server hosted documents folder and backup to a SAN. We'd keep staff for about a year and students for as long as we has space.

Do i need to go into leavers OneDrive and download the files back to SAN to store a copy or is there a better way.

 

I'd be interested in what you're all doing

Posted

if you have unlimited licences you don't have to delete them. My plan was to remove them from active directory, have them deleted from o365, then restore them as a cloud users.

 

There is probably a better solution.

Posted

Yea i'd ideally want them out the system completely just retaining their files.

From what i can see so far i have to connect to their drive and download a copy to store. Won't be an issue for students but staff spaces are pretty big in a lot of cases.

Posted
I just set up an account called onedrive archive and I download a zip of the users onedrive files and store them on the archive account. That way I have easy access to their old files if needed and can remove the user from our environment.
Posted

How do you find doing this for large amounts of data? We have some staff with 100gb of data. Its ashame the sharepoint upload tool thing doesn't go both ways

Student wise i guess it would be fairly easy.

 

I like the idea of the Onedrive account setup to store this. It will be a good option for when my SAN dies.

Posted
Can't you just disable their account once they've left and leave it be? If files are ever needed just re-enable the account, reset the password and access it. Depending on your setup you may need written SLT permission to access someone else's account.
Posted
We have an Archive OU and move leaver / disabled accounts in there, not doing anyone any harm being there. I would argue you do need permission, as accessing the account also grants you access to their email account and all files, which may or may not contain personal information.
Posted
Large amounts of data gets a little tricky trying to download all from the browser but using the onedrive sync client takes care of that issue. I have been using this method for a couple years and have archived about 120 previous staff this way. Student data we do not backup when they leave.
Posted
We have an Archive OU and move leaver / disabled accounts in there, not doing anyone any harm being there. I would argue you do need permission, as accessing the account also grants you access to their email account and all files, which may or may not contain personal information.

 

Its a you say tomato i say tomato argument. I don't see the point of having an account held in the system for no reason. Compared to holding onto them all in an OU like a shrine to the leavers :) The permission thing depends on your position and authority. I don't need general access but I do need access if needed. I don't need to ask for that permission if its within my role which this is.

Large amounts of data gets a little tricky trying to download all from the browser but using the onedrive sync client takes care of that issue. I have been using this method for a couple years and have archived about 120 previous staff this way. Student data we do not backup when they leave.

 

So you sync their account with the sync tool then just copy paste the data off to wherever you're storing it?

Posted
So you sync their account with the sync tool then just copy paste the data off to wherever you're storing it?

Exactly I first look the user up in the sharepoint admin center under user profiles and once at their document page you can click the sync button to set up the sync client under your admin account after coping the files over I just disconnect the sync and delete the user.

Posted
We keep our accounts on the system (but disabled) until after any resits are done, then we delete them all with no backups kept. This is the way we were told to do it for GDPR as when a student leaves you should only be holding the legally required data for safeguarding. (and you dont know what theyve saved to their one drives). Also its less to look through in the event of a SAR.
Posted
I don't like leaving accounts in the system it's bad practice in my opinion. I don't need anyone's permission to do anything :)

 

It's actually best practice to leave them in, as the accounts may be needed in the future, for example if a staff member returns after leaving, which does happen quite often. I've got an environment where not a single account has been deleted since 2005. Doesn't cost anything or cause any harm to keep them. All accounts are disabled obviously and don't have any licenses assigned to them.

Posted
It's actually best practice to leave them in, as the accounts may be needed in the future, for example if a staff member returns after leaving, which does happen quite often. I've got an environment where not a single account has been deleted since 2005. Doesn't cost anything or cause any harm to keep them. All accounts are disabled obviously and don't have any licenses assigned to them.

 

Feel free to correct me if I am wrong but I believe in Office 365 if you remove the licenses the accounts mailbox and onedrive files are deleted after 30 days.

Posted

Yeah we don't usually archive emails or files stored by that user unless requested. The way we do it is remove the user from all security groups, disable the account, move it to the old staff OU and then remove any licenses. If the staff member ever returns we enable the account and give them the relevant access and they can still use the same username and password they left with to access the system.

 

It also helps stop orphaned user accounts in SharePoint, as the accounts still technically exist.

Posted
Feel free to correct me if I am wrong but I believe in Office 365 if you remove the licenses the accounts mailbox and onedrive files are deleted after 30 days.

 

Correct... unless retention policies or legal hold are in place. Both are nice solutions to this issue. I'm going need a citation for keeping all accounts forever is 'best practise', if your churn is any more than trivial you'll end up with a directory full of zombies.

Posted

We currently have 5741 accounts in AD, dating back to 2002 actually so thats about 18 years worth of users. It's probably safe to delete some of those users, as realistically people who attended in 2002 aint coming back. I actually think the real reason for us doing this is we dont manage AD ourselves for student accounts and let Salamander do that for us instead, so data is imported from SIMS into AD.

 

As for staff accounts, it really depends on who you talk to. The main reason I dont delete them is if a member of staff called jsmith leaves and another staff member with the same name joins, they'd effectively end up with the same username as the staff member who left. This means they'd get all that staff members emails that they'd previously signed up to with their school email. Just disabling them ensures each account is unique to the user and that we dont accidently give another staff member the same alias as one who's left.

Posted

I'm not sold. I don't get the point of holding on to dead accounts, i still think you should delete them. If you leave you leave end of story. If you come back later on you get a new account. If you come back and there's someone with your username you had before, you get a different one. you shouldn't have left If you come back after 12 months your files are gone anyway who cares about old e-mails.

I'm far more interested in keeping staff files for a 12 months so we don't loose work created for the department and school. Which someone has answered :)

This post is now more of a discussion about who deletes account and who just keeps them

Posted
IMHO, I think you could come unstuck on a GDPR basis. You are required to only keep data for as long as you have good reason. You could put it in your retention policy and justify it that way, but I think it'd be quite a hard one to make a good case for.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...