How to reuse or reclaim a user's Google Workspace account in RM Unify
Published Date : 07 Jun 2019
Last Updated : 04 Oct 2024
Content Ref: TEC6793412
Operating System
(none)
Part No
(none)
Summary
Explains how an RM Unify super admin can prepare user accounts to reuse or reclaim a Google Workspace email address previously assigned to a different RM Unify account.
Symptoms
You need to delete and recreate a user's RM Unify account, but want to ensure that their Google Workspace account is re-attached to that recreated RM Unify account.
However, if you simply delete the user's RM Unify account and recreate it, the recreated account will not be automatically re-attached to the previous Google Workspace account, because of the expected behaviour detailed in this TEC.
Cause
Glossary of some terms, summary of behaviour
An RM Unify account represents an identity in the RM Unify database.
An RM Unify establishment can be federated with Microsoft® 365™ and/or Google Workspace.
An RM Unify account's email address is mainly generated/populated when Microsoft 365 or Google Workspace is federated to the establishment.
RM Unify requires that the Google Workspace account's UPN/account name and primary SMTP address are of the same value.
An RM Unify account's email address can also be considered a credential (a logon credential).
An identity can have numerous credentials associated with it.
Deleting an RM Unify account does not automatically release any email address credential claimed by that identity. This means that creating a new RM Unify account with the same name as that of a deleted account will not automatically link the email address (or the mailbox, data, etc.) used by that previous account.
Recreated RM Unify accounts can have the same RM Unify account names, but their linked Microsoft 365/Google Workspace accounts will receive new accounts created with a numerically appended account name.
Requirements
An RM Unify super admin account .
Google super admin access to the Google Workspace Admin console.
Note: this article is not for use where the RM Unify establishment has Microsoft 365 federated as well as Google Workspace.
Procedure
It is now possible for RM Unify super admins to delete the email credentials claimed by the deleted RM Unify accounts, so that those email addresses/accounts can be attached to new RM Unify accounts.
Note: The Deleted Users view only shows users deleted up to 90 days ago.
You have two choices to consider when wishing to reclaim a previously claimed email address. Do you wish to:
Re-attach an existing Google Workspace account and all its data (mailbox, etc.) to a new RM Unify account?
Or, do you wish to create a brand new Google Workspace account that simply uses the email address that has previously been used by another RM Unify user, but which has no associated data and instead has a brand new, empty mailbox?
1. Re-attach a Google Workspace email address and its existing mailbox/data
At this stage, the RM Unify account that is linked (holding a claim) to the desired email address must be deleted, before it can be used on another account. If the RM Unify account is not currently deleted, then please go ahead and delete it via whatever provisioning method you have chosen in your establishment (MIS Sync, AD Sync, CSV or manual), then:
Log on to the Google Admin console as a super admin user.
Find the desired Google Workspace account and select 'RENAME USER'.
Change the Primary email by appending '_XYZ' to the name, select Rename, then Continue. Note: This will be a temporary change and is needed to prevent the account from being deleted when you follow step 6 below. You can use any other identifier suffix than '_XYZ', which is just an example.
Log on to the RM Unify Management Console as a super admin and go to the Deleted Users page. This is found by using the View drop down menu from any Users page.
Find the deleted RM Unify user currently linked to the desired email address.
Select the user, choose 'Hard delete user' from the Actions menu and read and accept the warning. Important note: The account details page for the user will now show a date/timestamp for the 'Account Hard Delete Requested' attribute, but it may take up to five minutes for the account to be completely hard-deleted. Only once the user is removed from Deleted Users should you proceed to step 7. See the Possible Issues section below.
Back in the Google Admin console, rename the user account from step 2 by removing the appended '_XYZ'. The desired email address is now available and can be assigned (along with the retained mailbox/data) to a new RM Unify user account.
Create your new RM Unify user account.
2. Re-use a Google Workspace email address, but create a new, empty mailbox
At this stage, the RM Unify account that is linked (holding a claim) to the desired email address must be deleted before it can be used on another account. If the RM Unify account is not currently deleted, then please go ahead and delete it via whatever provisioning method you have chosen in your establishment (MIS Sync, AD Sync, CSV or manual), then:
Log on to the Google Admin console as a super admin user.
Find the desired Google Workspace account and select 'DELETE USER'.
If you wish to transfer ownership of the user's data to another user, please make the appropriate selections, then click Delete.
Log on to the RM Unify Management Console as a super admin and go to the Deleted Users page. This is found by using the View drop down menu from any Users page.
Find the deleted RM Unify user currently linked to the desired email address.
Select the user, choose 'Hard delete user' from the Actions menu and read and accept the warning. Important note: The account details page for the user will now show a date/timestamp for the 'Account Hard Delete Requested' attribute, but it may take up to five minutes for the account to be completely hard-deleted. Only once the user is removed from Deleted Users should you proceed to step 7. See Possible Issues below.
Create your new RM Unify user account, which will get a brand new Google Workspace account using the desired email address.
Possible Issues
The identity 'hard delete' process first sends a delete message to Microsoft 365 and/or Google Workspace to delete the associated email account(s), before continuing with the actual RM Unify account deletion. The average time to receive confirmation from Microsoft 365 or Google Workspace of the email address deletion is around two to three minutes, but if there are issues within the Microsoft or Google systems (e.g. the provisioning message queues are under load), then this delay could be longer. RM has no control over the Microsoft 365 or Google Workspace systems.
If this article has not helped provide a solution then it is also possible to
log a call...
Document Keywords: How to reuse or reclaim a user's G Suite account in RM Unify, soft delete, hard delete, attribute, credential, identity, identity hard delete, soft, soft, Google Workspace, TEC6793412