Skip to main content

ARS (Active Roles Server) is used to manage PennO365 PennKey-based mailboxes and PennO365 non-PennKey mailboxes.

Managing PennO365 PennKey Accounts

How do I make someone eligible for PennO365?

PennO365 eligibility is determined automatically based on affiliation with Penn in IIQ. In order to make someone eligible for PennO365, their affiliation must be added in:

  1. Workday
  2. Pennant
  3. Legacy PennCommunity

How do I manage an account in a different Center?

In order to administer an account outside their usual Center, add the account to your center's UsersFunctional group.

  1. Click "[School/Center]-PennO365" MU.
  2. Click "[School/Center]UsersFunctional" Group.
  3. Click "Members" in the right pane.
  4. Click "Add" and search for the user.
  5. Check the box next to the user and click Okay.

How do I know if an account has a mailbox?

  1. Search for the user's PennKey account and click on the checkbox next to their username.
  2. Click on "Azure Properties" > "Licenses (AD Group Sync)".
  3. If the license listed under "Current Licensing" has "Mailbox" in it, the account has email.  (If it says ProPlus, that account has access to all O365 services except Exchange mailboxes.)

How do I mailbox-enable a PennKey account?

It is possible to automatically mailbox-enable your users through Grouper. If you are interested, open a ticket to go through the configuration and implementation for your Org.

If you are manually mailbox-enabling PennKey accounts, use these steps:

To mailbox-enable a PennKey account, you must assign the user an appropriate PennO365 license.

  1. Search for the user's PennKey account and click on the checkbox next to their username.
  2. Click on "Azure Properties" > "Licenses (AD Group Sync)" and select the appropriate license (student or faculty/staff) with "Mailbox" at the end. (Do NOT select the license labeled PennO365_Student_Mailbox-PSTN.)  Then click the "Save" button.

Note: It may take up to an hour to fully-provision an account with Azure properties and a mailbox.

How do I bulk mailbox enable?

This function can be used to assign a specified mailbox license to any listed accounts that do not have any kind of license. It will not change existing licenses if they are different than the specified one.

  1. In Filter Pane, click on your school/center's MU.
  2. Check your school/center's "Bulk Operations Menu" and click the "UPenn Bulk Operations (doc)" that appears on the right.
  3. Enter Pennkeys separated by a return, comma, or semicolon and the billing code if you have it. 
    Note: If you do not enter a budget code, it will use the default one for your school/center.  There is no charge for O365 accounts; the budget code is only used for auditing.

You will receive an email when the bulk job is complete.

How do I change the budget code?

Note: There are is no charge for O365 accounts; the budget code is only used for auditing. If no code is entered, the default one for your school/center will be used.

  1. Search for the user's PennKey account and either click on the username or click the checkmark and click the "General Properties" link.
  2. Click on "Organization" and enter/change the budget code.

How do I move accounts between Orgs?

In the ARS system, moving an account between Orgs is not possible. When the user's primary affiliation changes in IIQ, the new Org will propagate over to the PennO365 system and automatically move the account.

If the account needs to be administered by a different school/center before the automatic process is complete, the LSP of the new school/center (this cannot be done by the LSP of the previous school/center) can add the user to their UsersFunctional group (See "How do I manage an account in a different Center?" above for instructions.). Since the user will eventually be added as part of the automatic process, it is recommended that the account is added to UsersFunctional with an expiration date to prevent future problems with transfers. To add an expiration date, before clicking the final OK, click the "Temporary Access" button and change "Remove from the Group" to a date in the future after the official transfer.

NOTE: When accounts are moved to Perelman School of Medicine, the user will immediately lose access to their previous email. The email is recoverable, if desired, for 30 days by means of submitting a ticket.

How do I mailbox-disable a PennKey account?

To mailbox-disable a PennKey account, you must assign the user a ProPlus license. The ProPlus license will override the Mailbox license.

  1. Search for the user's PennKey account and click on the checkbox next to their username.
  2. Click on "Azure Properties" > "Licenses (AD Group Sync)" and select "PennO365_ProPlus" from the license drop-down menu.

Note: Do NOT apply a license with PSTN in the name.

How do I bulk mailbox disable?

This function will remove a mailbox license from any listed accounts that have a mailbox license. It will not remove any other licenses and it will not replace the mailbox license with another non-mailbox license.

  1. In Filter Pane, click on your school/center's MU.
  2. Check your school/center's "Bulk Operations Menu" and click the "UPenn Bulk Operations (doc)" that appears on the right.
  3. Click on "UPenn Bulk Operations".
  4. Select the License type you are removing.
  5. Change "Mailbox Operations" to "Disable".
  6. Enter Pennkeys separated by a space or return.

You will receive an email when the bulk job is complete.

How do I add an email alias?

Note: Only those LSPs who manage their third-level domains have access to add email aliases.  If you do not have a third-level domain that you manage, please submit a ticket.

  1. Search for the user's PennKey account and click on the checkbox next to their username.
  2. Click on "General Properties" > "Email Addresses".
  3. Select the address type and domain and the address will be automatically generated.

How do I remove an email alias?

Note: Only those LSPs who manage their third-level domains have access to remove email aliases.  If you do not have a third-level domain that you manage, please submit a ticket.

  1. Search for the user's PennKey account and click on the checkbox next to their username.
  2. Click on "General Properties" > "Email Addresses".
  3. Remove the email alias.

How do I change the Primary SMTP (PSMTP) email address of a PennKey account?

  1. Search for the user's PennKey account and click on the checkbox next to their username.
  2. Click on "General Properties" > "Email Addresses - Set Primary".
  3. Select the address you want to be the Primary SMTP and click the "Set As Primary" checkmark.

How do I set email forwarding?

This can be configured in the email client itself. This method can be preferable because the end user will have visibility to manage the forwarding for themselves. Changes made in the email client will sync to AD.

To set email forwarding in ARS:

  1. Search for the user's PennKey account and click on the checkbox next to their username.
  2. Click on "Exchange Online Properties" > "Delegation"
  3. In the "ForwardingAddress" field enter the address.  

Note: You have the option to check the box regarding whether you want to keep a copy of emails in the mailbox.   It is checked by default.

Managing Delegation

How do I manage SendAs?

  1. Search for the user's PennKey account and click on the checkbox next to their username.
  2. Click on "Exchange Online Properties" > "Delegation"
  3. Under the "Send As" box, click "Add"
  4. Type in PennKey and press enter or click Magnifying Glass to search.
  5. Click the username or check the box next to the username to add them to the field at the bottom of the screen.

Note: If you want to confirm the change, wait 10-15 minutes for it to show up in ARS.

How do I manage SendOnBehalf?

  1. Search for the user's PennKey account and click on the checkbox next to their username.
  2. Click on "Exchange Online Properties" > "Delegation"
  3. Under the "Send On Behalf" box, click "Add"
  4. Type in PennKey and press enter or click Magnifying Glass to search.
  5. Click the username or check the box next to the username to add them to the field at the bottom of the screen.

Note: If you want to confirm the change, wait 10-15 minutes for it to show up in ARS.

Can SendOnBehalf settings be configured locally?

SendOnBehalf settings can be configured via the Outlook client. Note that send-on-behalf permissions cannot be set up via Outlook on the Web.

  1. Click File > Info > Account Settings > Delegate Access.
  2. Click Add.
  3. Choose the mailbox from the Address Book.
  4. If you need the user to have partial access to your mailbox, you can specify the access level on the next screen. If you only need to give "Send On-Behalf" permissions to the user, choose None for each folder.
  5. Click OK.

How do I manage full mailbox permissions?

  1. Search for the user's PennKey account and click on the checkbox next to their username.
  2. Click on "Exchange Online Properties" > "Delegation"
  3. Under the "Full Access" box, click "Add"
  4. Type in PennKey and press enter or click Magnifying Glass to search.
  5. Click the username or check the box next to the username to add them to the field at the bottom of the screen.

Note: If you want to confirm the change, wait 10-15 minutes for it to show up in ARS.

How do I manage calendar permissions?

Note: If the account has a large number of calendar delegates, ARS is likely to hang when you try to access/manage these settings. In this case, enter a ticket to have the calendar permissions changed.

  1. Search for the user's PennKey account and click on the checkbox next to their username.
  2. Click on "Exchange Online Properties" > "Calendar (Delegation)".  Existing permissions will be shown here, including those set at the client level.
  3. To add a new account for permissions, click "Add" under the "Select user(s)" box. To change permissions on an existing account, click "Add", "Remove", or "Set"(to modify existing permissions).
  4. Click "Save". 

It may take up to a minute to apply the permissions.  The button will show "Please wait" until it is complete. If you want to confirm the change afterward, wait 10-15 minutes for it to show up in ARS.

Managing PennO365 Non-PennKey Accounts

How do I create a non-PennKey mailbox?

LSPs cannot create non-PennKey accounts at this time.  If you would like a non-PennKey account created, please submit a ticket in Support Center.

How do I change account attributes?

  1. Click on your school/center's Managed Unit (MU).
  2. Click "Groups", "Resources", or "Rooms" depending on the type of account.
  3. Check the box next to the account name and click on "General Properties."

How do I set a password and log in as the non-PennKey account?

By default, you cannot log in with a non-PennKey account. To log in with a non-PennKey account, you will need a variance from the ITPC for the account to be converted to an individual-type account.

To reset the password for a non-PennKey account that functions as an individual-type account:

  1. Search for the account.
  2. Click the checkmark next to the account and click "Reset Password".

How do I add delegated access for a shared account?

  1. Click on your school/center's Managed Unit (MU).
  2. Click "Groups", "Resources", or "Rooms" depending on the type of account.
  3. Click on "Exchange Online Properties" > "Delegation"
  4. Under the appropriate access box, click "Add"
  5. Type in PennKey and press enter or click Magnifying Glass to search.
  6. Click the username or check the box next to the username to add them to the field at the bottom of the screen.