contentACCESS documentation – version Orion

  1. Introduction to contentACCESS
    1. Services provided by contentACCESS
    2. Software requirements
      1. contentACCESS prerequisites
  2. contentACCESS setup package
    1. Installation of contentACCESS
      1. EULA
      2. Installation type
      3. Components
      4. Prerequisites
      5. Base folder
      6. Service settings
      7. Database connection
      8. contentACCESS Central Administration
      9. Backup Administration for Microsoft 365
      10. contentACCESS Web Services (Proxy)
      11. contentACCESS Portal
      12. Preview service
      13. Central login
      14. Virtual drive
      15. Search service
      16. Search service (V2)
      17. SMTP server
      18. Overview
      19. Installation
      20. Summary
    2. Update of contentACCESS
      1. Managing the index reset or migration
  3. contentACCESS components
    1. contentACCESS Central Administration
      1. Central administration login
      2. contentACCESS Automated single sign on
      3. Central Administration logout
      4. contentACCESS Central Administration user interface
    2. contentACCESS Portal
      1. Logging in to contentACCESS Portal
      2. contentACCESS Portal Automated single sign on
    3. Backup Administration for Microsoft 365
    4. Virtual drive
    5. contentACCESS Web Services (Proxy)
    6. Central login page
  4. contentACCESS Tools
    1. Installing Outlook forms
    2. Legacy email archive connectors
    3. Legacy archive connector for Metalogix Archive Manager Exchange Edition (MAM EE)
      1. Installing Legacy MAM retrieve service and its configuration on the MAM server
      2. Configuration of the MAM server in contentACCESS Central Administration
    4. Legacy archive connector for Email Lifecycle Manager (ELM)
    5. Installing TECH-ARROW’s WinShortcutter
    6. contentACCESS Outlook add-in
      1. Installation of contentACCESS Outlook add-in
      2. How to use contentACCESS Outlook add-in
  5. Tenants in contentACCESS
    1. How to create a new tenant
      1. How to edit and disable a tenant
    2. Tenant limitations
    3. How to provide access to a tenant (adding new tenant administrators)
    4. Tenant administrator invitation types
    5. Tenant associations
      1. Tenant - database association
      2. Tenant - user association
    6. Tenant deletion
  6. General system configurations
    1. Connection
    2. User interface
    3. Users in contentACCESS
    4. Invitations
    5. Roles
      1. Creating roles
      2. Role details
      3. Role assignment
      4. Defining specific permissions of a role assignment
      5. Editing roles, editing role assignments
      6. Role cloning
      7. General use cases of how to create/assign roles
      8. Managing access to contentACCESS objects
    6. Login providers
      1. Login providers’ context menu options
      2. External login provider configuration
        1. Configuring Google OAuth
        2. Configuring Microsoft 365 login provider
        3. Exchange login provider
        4. External AD login provider
      3. Associating an enabled provider with a user login
      4. contentACCESS users in third party systems
    7. System
    8. Licensing
      1. How to activate your license key
    9. Notifications
    10. System logs — how to find out possible misconfigurations / reasons of potential system/job failures
    11. Configuration auditing
    12. Archive auditing
    13. Distributed environment in contentACCESS — Clusters
    14. Statistics
    15. Legal hold
    16. Task runner
    17. Indexing
    18. SMTP Servers
    19. SMTP Mappings
    20. SMTP Rules - selective journaling
    21. Sharing job
    22. Sharing settings
    23. How to create/configure databases — All databases
  7. Common features
    1. Databases
    2. Schedules
    3. Retentions
    4. Storages
      1. Amazon S3
      2. Wasabi storage
      3. Google drive storage
      4. Datengut storage
      5. Azure storage
      6. Disk storage
      7. HybridStore
      8. Perceptive storage
      9. Kendox storage
    5. Exchange connections
      1. Exchange performance settings – turning off the Exchange throttling policies
      2. Mixed Exchange environments in the Email Archive system
    6. Importing contentACCESS configurations from files
      1. Manual import of Exchange servers/groups/mailboxes to the contentACCESS Address book
      2. Importing File Archive root folders to be archived
  8. Creating new jobs in contentACCESS
  9. Jobs’ page, jobs’ context menu
  10. Filtering in jobs
  11. File Archive
    1. Introduction to File system archive
    2. File archive settings
    3. File archive Databases
    4. File archive System settings
    5. File archive Retentions
    6. File archive Storages
    7. Root folders
    8. Aliases
    9. File archive Schedules
    10. Provisioning settings and managing access to contentACCESS Portal
      1. File system provisioning job description
    11. Remote agents (file archive)
    12. Global rules (remote file archive)
    13. Configuring aliases
    14. Configuration of jobs available in contentACCESS File Archive
    15. Configuration of File archive retention changer job
    16. Configuration of File system archive job
      1. File system archive job description
    17. Configuration of a File system restore job
      1. File system restore job description
    18. Configuration of File system recovery job
      1. File system recovery job description
    19. Configuration of Delete job in File archive
      1. File system delete job description
    20. Configuration of File system shortcut synchronization job
      1. File system shortcut synchronization job description
    21. Configuration of Remote shortcutting job
      1. File system remote shortcutting job description
    22. Active/inactive documents in File system archive
  12. Email Archive
    1. Important settings before creating an Email Archive job
    2. Database settings
    3. Email archive System settings
      1. Hybrid exchange settings
    4. Email archive Provisioning settings
      1. Email archive provisioning job description
    5. Retention settings
    6. Shortcuts in email archiving
    7. Storing of archived emails
      1. LoboDMS storage
    8. Creating email archive schedulers
    9. User experience
      1. Exchange 2013+: contentACCESS MailApp in OWA 2013+ or on MS Outlook 2013+ desktop version
      2. Exchange 2010: OWA 2010 integration
    10. Address book objects
      1. Adding address book objects manually
      2. Removing groups and mailboxes from the Address book
    11. Granting access rights for mailbox users and explicit users to view the mailbox archive
      1. Creating contentACCESS Portal users (option 1)
      2. Manage access to a mailbox archive (option 2)
    12. Database and store assignment in email archiving
      1. How to assign database, storage and index zone to an Exchange group?
      2. How to assign database, storage and index zone to a mailbox?
      3. How to move data from source database/storage into a second (target) database/storage?
    13. contentACCESS MailApp access
    14. Remote agents (email archive)
    15. PST import
      1. PST import job description
    16. Creating Email archive jobs: archive, restore, recovery, delete, mailbox move, shortcut synchronizaion, shortcut repair
    17. Email archive job
      1. Email archive job configuration
      2. Email archive job description
      3. Email archive journal processing
        1. Recommendations after turning on journal archive
      4. Archiving of rights protected messages
    18. Email archive retention changer job
    19. Email restore job
      1. Email restore job configuration
      2. Email restore job description
    20. Email recovery job
      1. Email recovery job configuration
      2. Email recovery job description
    21. Configuration of Delete job in Email archive
      1. Email delete job description
    22. Journal post processing job
      1. Journal post processing job configuration
    23. Mailbox move job
      1. Mailbox move job configration
      2. Mailbox move job description
    24. Shortcut synchronization job
      1. Shortcut synchronization job configuration
      2. Email shortcut synchronization job description
    25. Shortcut repair job
      1. Shortcut repair job configuration
      2. Email shortcut repair job description
    26. Public folder archiving
      1. How to configure a job to archive public folders
      2. Public folders in the contentACCESS Portal archive
      3. User permissions to public folders
      4. Public Folder archiving in mixed Exchange environments
    27. Access to private emails and archiving them
    28. SMTP archiving
  13. SharePoint archive plugin
    1. SharePoint Archive settings
    2. SharePoint archive System settings
    3. Site connections in the SharePoint archive
    4. SharePoint archive Provisioning settings
      1. SharePoint provisioning job description
    5. Shortcut configuration in SharePoint
    6. SharePoint archive Address book
    7. SharePoint Archive job configuration
      1. SharePoint archive job description
    8. SharePoint archive retention changer job configuration
    9. SharePoint recovery job configuration
      1. SharePoint recovery job description
    10. Configuration of Delete job in SharePoint archive
      1. SharePoint delete job description
    11. SharePoint Publishing job
      1. SharePoint publishing job description
    12. SharePoint in the contentACCESS Portal archive
  14. OneDrive archive
    1. OneDrive Archive job configuration
    2. OneDrive archive Jobs
  15. GDPR plugin
    1. GDPR Settings
      1. GDPR Databases
      2. GDPR Schedules
      3. GDPR Index zones
    2. GDPR Processing
      1. GDPR File system settings
      2. GDPR Exchange settings
      3. GDPR Applications
      4. GDPR Jobs
        1. GDPR File system job
          1. GDPR file system job description
        2. GDPR Exchange job
          1. GDPR Exchange job description
        3. GDPR Application job
          1. GDPR application job description
  16. Teams archive
    1. Teams archive databases
    2. Teams archive System settings
    3. Teams archive Provisioning settings
    4. Shortcut configuration in Teams archive
    5. Teams archive Address book
      1. Removing objects from Teams archive Address book
    6. Teams archive Licensing
    7. Teams archive Jobs
      1. Teams archive job
      2. Teams compliance archive job
        1. Comparison between the Teams archive and Teams compliance archive jobs
      3. Teams chat archive job
      4. Teams compliance chat archive job
        1. Comparison between the Teams chat archive and Teams chat compliance archive jobs
      5. Teams archive recovery
        1. Teams recovery job description
      6. Configuration of Teams archive retention changer job
      7. Configuration of Teams chat archive retention changer job
      8. Configuration of Delete job in Teams archive
        1. Teams archive delete job description
      9. Configuration of Delete job in Teams chat archive
  17. Custom plugins
    1. Email management job configuration
    2. Storage replication plugin
    3. Sharing plugin
    4. Datengut plugin
    5. Email synchronizer plugin
    6. Categorize to Public folders plugin
    7. LoboDMS plugin
  18. ThreatTest
    1. ThreatTest configuration
      1. ThreatTest Databases
      2. ThreatTest System settings
      3. ThreatTest Schedules
      4. ThreatTest User experience
      5. ThreatTest Statistics
      6. ThreatTest Job
    2. Using ThreatTest App
  19. officeGATE
  20. contentACCESS Mobile
  21. Virtual drive configurations
  22. Teams application
  23. Application settings
  24. Terms of use
  25. FAQ
    1. Download sample for the file to be imported does not work
    2. Archiving is not working if MAPI is set to communicate with the Exchange server
    3. Virtual drive is still appearing after the uninstall
    4. Outlook forms problems
    5. Unable to open shortcuts of archived files on the server side
    6. Samples are not shown using 'Show sample" option in the Import dialog
    7. Do I need to create separate tenants for file archiving and email archiving
    8. What is the recommended database size for email, file and Sharepoint archiving
    9. The TEMP folder is running out of space when archiving big files
    10. The attachment could not be opened
    11. After updating Exchange 2013, the EWS connection might not work in contentACCESS
    12. If Windows authentication is not working in contentACCESS and an alias was created for contentACCESS
    13. contentACCESS Outlook add-in certificate issue
    14. Prerequisites for Microsoft 365 archiving
    15. PowerShell scripts for setting up Email archive
    16. How to reconfigure your email archive to use modern authentication for PowerShell
    17. Solution for Outlook security patches
    18. Solution for Outlook security patches through GPO
    19. Solution for indexing PDF files
    20. Microsoft 365 SuperUser mailbox configuration
    21. Microsoft 365 journaling
      1. Configuring Microsoft 365 journal forwarding through third-party Exchange Online Protection
    22. Organizational forms
    23. Multifactor authentication
    24. Region setting
    25. contentACCESS MailApp installation issue
    26. Azure app registration for Microsoft 365 archiving
      1. Grant permissions for Email archive
      2. Grant permissions for the OneDrive archive
      3. Grant permissions for the SharePoint archive
      4. Grant permissions for Teams archive
      5. How to request access to Microsoft Protected API
  26. Troubleshooting

13.4.SharePoint archive Provisioning settings

The provisioning job

  • Creates and updates contentACCESS users and assigns contentACCESS roles to them based on information gathered from SharePoint
Note: The contentACCESS technical user account performing the provisioning job reads the permissions set on the archived SharePoint objects. Therefore it needs to read the SharePoint users, groups and group membership information. To achieve this, please add the contentACCESS technical user account to the list of Site Collection Administrators.

In contentACCESS, a provisioning job is created automatically when activating SharePoint archive for the first time.
The process is similar for on-premise SharePoint and SharePoint online. The differences are as follows:

On-premises SharePoint

  • Scans SharePoint groups and users, then they are snapshotted in the SharePoint archive database
  • Picks users with Windows login and creates these users in contentACCESS (see more in SharePoint Archive settings, section System settings) together with Windows login
  • Grants permissions to access the given SharePoint connection (archive only)

The on-premises SharePoint is working with the Active Directory and using its users and groups to grant them access to sites, folders and items.

SharePoint defines SharePoint groups, which is a collection of AD users, AD groups and other users (Azure, etc.).

The provisioning job also collects information about AD groups and their members. This is important when permissions are evaluated, because they are configured through AD groups.

Snapshot means that a copy of the user/group is created in the archive, which remains even after the user or group is deleted from SharePoint. This allows to use the last known permissions for the user when working with the archive.

At the end of the provisioning job, the archive has collected the following information:

  • Collected all AD groups which are somehow related to SharePoint
  • Collected all AD users which are somehow related to SharePoint
  • Collected AD group memberships
  • Collected SharePoint groups for the given site connection
  • Collected members of the SharePoint groups

To access the folders and documents the user requires individual permissions which are synchronized by the SharePoint archive job.
Code:

Note: The user will only see those folders and items to which it really has access.


Screenshot: Provisioning settings for On-premise SharePoint

SharePoint online
The users and SharePoint groups from Microsoft 365 are also synchronized by the provisioning job.
Microsoft 365 users, together with Microsoft 365 logins, are also created automatically by the provisioning job.

Important: Please note, that the Sites to provision and OneDrive groups to provision (AAD) sections are only visible if Microsoft 365 SharePoint type is selected on the System settings page! In On-premise mode, the provisioning will process the created site connections without the Sites to provision and OneDrive AAD group sections.

SharePoint Archive provisioning settings are available on the Provisioning settings page (SharePoint Archive ⇒ Settings ⇒ Provisioning settings):

Screenshot: Provisioning settings for SharePoint online

The status bar of the provisioning job offers the following options:

If a scheduler has not been selected, the provisioning job can be started/stopped manually with the “start immediately/stop” control button. To manually refresh the provisioning progress information, click on “refresh” button. To enable/disable auto refresh in every 5 seconds, click on “enable auto refresh”/“disable auto refresh” button. The provisioning job can be also deactivated with the “deactivate job” button. A deactivated job will not start automatically, nor can be started manually. The “edit” button is used to select the node, where provisioning job will be run. The user may also rename the provisioning job here. To view further event details of provisioning job (and also to detect any potential failures/errors in the provisioning events), click on “logs” button. This will redirect you to the System logs page, where the last run of the provisioning job will be preselected and the last events will be shown in the events table.

Screenshot: System logs page with logs

The following configuration sections are available on the Provisioning settings page:

Report mode settings
If the Use report mode checkbox is checked, the job will run in report mode and the user will be able to download a .csv report here in this section after the job finishes the run. This file will contain a list of teams selected in the Sites to provision section and OneDrive groups selected in the OneDrive groups to provision (AAD) section of the job and some information about them, including whether they will be processed or not.

Archive settings
This configuration section allows to assign default contentACCESS Portal user roles. This rule is granted for the users on SharePoint archive site.
It is recommended to specify here a default role with less contentACCESS Portal permissions. The roles to be assigned must be created on the Roles page.

Note: Roles containing Manage system and/or Manage tenant permissions are unavailable in the default roles’ dropdown list.


Scheduling settings
Select the running times of the provisioning job or create a new scheduler. For more information on how to configure scheduler settings please refer to section Schedules.

Sites to provision
In this section, the user can choose if he wants to process all accessible SharePoint sites or select only some of them manually. It is also possible to provision groups by selecting the Automated selection.

  1. All sites – if the Administrator selects all sites, then all accessible sites will be processed and provisioned.
  2. Manual selection – in case of Manual selection, the user can pick which sites to process and add to the address book. If he decides to select them manually, the Documentation340.1 select option will appear.

    After clicking on it, the Site selection window will open. Here, it is possible to select the sites to be processed. After the selection is made, click OK.
  3. Automated selection – there is also the option to set up Automated Site provisioning. After selecting this option from the Sites to process dropdown list, click on + new.

    The Site selection window will open.
    Here, you will be able to specify a list of filters for a group, based on which sites do you want to be processed. Every filter is associated with one group. All sites matching the specified filter will be added into the group.

    Before specifying a filter, you will first need to select a Group from the dropdown list. If you have no groups created, is it possible to create one directly from here by clicking on the Create group button (more information about group creation can be found in this section).

    To specify a filter, click on the Change filter button. Specify your desired filtering options in the Filtering settings window, then click OK.

    Important: Please note, that the Sites to provision section is visible only if Microsoft 365 SharePoint type is selected on the System settings page!

    Select one of Processing strategy options:

    • Only add – new sites matching the filtering settings will be added, but the previously added sites won’t be updated during the process
    • Synchronize – add or remove sites from the group based on the filtering settings. The new sites will be added to the group, and the sites no longer matching the filtering settings will be removed from the group

    Click OK. The group settings (database, store, index zone) will be applied to the sites that are members of the group. If the site has already associated database, store or index zone, it won’t be overwritten by the provisioning job.

Important: Sites connected to a Teams team will not be provisioned by automatic provisioning.

Default provisioned site settings
In this section, the Administrator can select the default database connection, the storage, and the assigned index zone for the provisioned sites and OneDrive groups. During the run of the provisioning job, if a new site/group provisioned, the selected database, store, and index zone will be automatically assigned to them.
On the other hand, if a database, store or index zone is already assigned to the provisioned site or group, it won’t be updated during the next run of the provisioning job.

OneDrive groups to provision (AAD)
In this section, it is possible to select OneDrive groups that the Administrator would like to add to the Address book and later use for OneDrive archiving. This option is only visible if OneDrive archiving is enabled on the System settings page.

To manually select from the available groups, click on the Documentation340.1 select button. The Select AAD Group(s) window will open. Here, it is possible to select the AAD groups to be processed. After the selection is made, click OK.

If you want to add a group that is not in the list of available groups, click on the + add button. The Add AAD group window will open. Here you can specify the group’s name and then click OK to add it to the AAD groups list in the Provisioning settings.

Important: Please note, that the OneDrive groups to provision (AAD) section is visible only if Microsoft 365 SharePoint type is selected on the System settings page!

Notification settings
If the provisioning job could not run properly due to some reasons, contentACCESS can send a warning about the problem. The notification email message will be sent to the email address that is set here under Recipient list option. Here you can also choose when these email messages should be sent: only if errors occur, or when errors or warnings occur, or always, regardless of the faultless running of the provisioning job.

Yes No Suggest edit
Help Guide Powered by Documentor
Suggest Edit