Teams archive Provisioning settings
The provisioning job
- Synchronizes users of the Teams and AAD groups specified on the Provisioning settings page to the Teams archive Address book
- Verifies the user's Teams memberships and records these memberships in contentACCESS
- If contentACCESS Portal user creation is turned on in the Address book for an object (Teams/Team groups/Teams' users/AAD group), it creates a contentACCESS Portal user for the object users with a Microsoft 365 authentication type
- Based on the roles assigned in the Address book, it grants permissions on the specific Teams and private chats
In contentACCESS, a provisioning job is created automatically when Teams Archive is activated for the first time.
Teams Archive provisioning settings are available on the Provisioning settings page (Teams Archive -> Settings -> Provisioning settings):

a) Report mode settings
If the Use report mode checkbox is checked, the job will run in report mode. After the job finishes its run in this mode, the user will be able to download a .csv report file here in this section. The file will contain a list of teams selected in section Teams to process of the job and some information about them, including whether and how they will be processed.
b) Archive settings
This configuration section allows assigning default contentACCESS Portal user roles for Teams archive users. During provisioning, users can be automatically granted Portal access with a predefined role selected here (e.g., Standard user). This works similarly to other archives such as SharePoint, ensuring that Portal access is assigned immediately without requiring additional configuration in the Address book. It is recommended to assign a default role with limited contentACCESS Portal permissions. The roles must be created on the Roles page.
The Create Portal access setting controls whether users receive Portal access during provisioning. The system first evaluates the settings defined in the Address Book in the following order: User → Team → Team Group. An explicit Enabled or Disabled setting on a higher level always overrides lower levels and the provisioning job setting. If all levels in the Address Book are set to Inherit or remain undefined, the Create Portal access checkbox configured on the Provisioning Settings page determines whether portal access is created.
c) Provisioning options
When the Unlicense users not belonging to any Team option is enabled, the system checks if a user is assigned to any archived team. If the user is not a member of any (archived) team, the provisioning job will remove the Teams license from this user.
As a result, the user's status in Address Book -> Users -> License status column will change from Licensed to Allowed.
After the telemetry job has been executed, the User count in the Teams archive section on the Licensing page will be reduced accordingly.
Note: The Unlicense users not belonging to any Team option does not apply to private chats. It only works with (archived) teams.
d) Scheduling settings
Select the running times of the provisioning job or create a new scheduler. For more information on how to configure scheduler settings, please refer to section Schedules described above.
e) Teams to process
In this section, the user can choose whether to process all accessible Teams and Team groups or select only some of them manually. If you decide to select them manually, the
select option will appear. After clicking on it, the Team selection window will open. You can select the Teams or Team groups to be processed. After the selection is made, click OK.

There is also the option to set up Automated Team provisioning. After selecting this option from the Process teams dropdown list, click on + new. The Team selection window will open. Here you will be able to specify a list of filters for a group, based on which teams you want to be processed. Every filter is associated with one group. All teams matching the specified filter will be added into the group.
Before specifying a filter, you need to select a Group from the dropdown list. If you have no groups created, you can create one directly from here by clicking on the Create group button. For more information about group creation, see this section.
To specify a filter, click on the Change filter button. Specify your desired filtering options in the Filter settings window. Team name and Description are what you specify when creating a team; Members must be specified as UPN (User Principal Name) — an email address used for logging in to Microsoft 365. Team name can also be specified in a case sensitive (CS) manner.
Note: If the description is not filled in for a team during team creation, the team's name will be used as the description for filtering purposes. So, if a team is named „Team A" (no description) and in filtering you set the Description to starts with „Team", this team will be processed, because the text „Team A" is returned as the description value.

Select one of Processing strategy options:
- Only add – new teams matching the filtering settings will be added, but the old team members that do not match the filtering settings will not be removed from the group
- Synchronize – only the teams that match the filtering settings can be group members; teams that do not match the filtering settings will be removed from the group

Click OK. The group settings (database, store, index zone, creation of contentACCESS Portal access) will be applied to the teams that are members of the group. If the team already has an associated database, store, or index zone, it won't be overwritten by the provisioning job.
f) AAD groups
In this section, you can select AAD groups that you would like to add to the Address book and later use for private chat archiving. There are two available group types and three group membership types.
Group types: Security (used to manage user and computer access to shared resources) and Microsoft 365 (provides collaboration opportunities by giving group members access to shared mailbox, calendar, files, SharePoint sites, and more).
Group membership types: Assigned (lets you add specific users as members of a group and have unique permissions), Dynamic user (lets you use dynamic membership rules to automatically add and remove members) and Dynamic device (lets you use dynamic group rules to automatically add and remove devices). Read this article for more information about the group and group membership types.
To manually select from the available groups, click on the
select button. The Select AAD Group(s) window will open. You can select the AAD groups to be processed. After the selection is made, click OK.

If you want to add a group that is not in the list of available groups, click on the + add button. The Add AAD group window will open. Here you can specify the group’s name and then click on OK to add it to the AAD groups list in Provisioning settings.
g) Notification settings
If the provisioning job fails to run properly, contentACCESS can send a warning about the problem. A notification email will be sent to the email address set here under Recipient list option. Here you can also choose when these email messages should be sent: only if errors occur, when errors or warnings occur, or always, regardless of the successful completion of the provisioning job.
Save the settings and start the Provisioning job.