Solution recommendation for separating contractors from MS365 Organization

BS 1 Reputation point
2020-10-23T14:00:44.553+00:00

Hello,
from time to time my organization hires a temporary contractor to do specific task.
I'd like to separate such person from my organization's resources - I mean files, distribution lists, Office 365 groups, shared mailboxes, conference rooms etc. Why? Because I don't want them to see who works here, organization structure, departments, naming convention etc. Such "privileges" should only be given to regular workers.

What is the most efficient way to do it? I've tried address book policies but from contractors' account there is still access to regular users' profile cards (for example), organization data etc. I think you get the idea. I know that there may not be a all in one solution but I'd like to be as close to it as possible.

In short, contractors should only have access to workers from its department or team, at most.

Could you recommend something?

Exchange Server Management
Exchange Server Management
Exchange Server: A family of Microsoft client/server messaging and collaboration software.Management: The act or process of organizing, handling, directing or controlling something.
7,356 questions
Microsoft Entra ID
Microsoft Entra ID
A Microsoft Entra identity service that provides identity management and access control capabilities. Replaces Azure Active Directory.
19,560 questions
0 comments No comments
{count} votes

2 answers

Sort by: Most helpful
  1. Vasil Michev 95,666 Reputation points MVP
    2020-10-23T18:02:15.633+00:00

    Address book policies are being superseded by Information barriers, those are your best shot currently: https://learn.microsoft.com/en-us/microsoft-365/compliance/information-barriers?view=o365-worldwide


  2. KyleXu-MSFT 26,211 Reputation points
    2020-10-26T05:35:21.68+00:00

    @BS
    Exchange online server doesn't have such function now. Exchange online RBAC can only configured as below:

    • Team A could manage Compliance in your organization.
    • Team B could manage Recipient in your organization.
    • Etc.

    Exchange online RBAC cannot spilt permission by department, such as team A can only manage users in department a. For more detail information about permission in Exchange online, you can have a look about this article: Permissions in Exchange Online

    You can have a try with the Office 365 suggestion as michev said, if you doesn't familiar with it, you can create a service request to Office 365 team.


    If the response is helpful, please click "Accept Answer" and upvote it.
    Note: Please follow the steps in our documentation to enable e-mail notifications if you want to receive the related email notification for this thread.