Views:

To deprovision a service account for Office 365 services, do the steps below:

  1. Log in to CAS web console, and go to Administration > Service Account.

    Service Accounts List

    Click the image to enlarge.

     
    (Optional) Take note of the App Id of the corresponding service account. It may be needed in the succeeding steps.
     
  2. Select an Office 365 service account (e.g. SharePoint Online account), and click Remove.
     
    Be cautious when deprovisioning an Exchange Online service account. The following supported Cloud App Security automation APIs will not work after the Exchange Online service account is deprovisioned: Threat Investigation, Intelligent Investigation, Threat Mitigation.
     

    Remove Service Account

    Click the image to enlarge.

  3. On the Remove <Office 365 Service Name> Service Account screen that appears, click OK.

    Confirm Service Account Removal

    Click the image to enlarge.

    If the service account is a Delegate Account, Cloud App Security requests Office 365 to verify the selected service account.

    • If the service account is valid, proceed to the next step.
    • If the service account is invalid, choose to cancel the operation or forcibly remove your data generated in Cloud App Security as instructed.
     
    Global Administrator privileges are required for removing service accounts. If your account does not have required privileges, specify the Global Administrator credentials as instructed and click OK.
     
  4. Wait for a few minutes, then manually refresh the web console.

    To check the removal progress, click the Details link under the Status column. This will open a screen showing all the steps involved, the status of each step, and the estimated time left.

    Removal Progress and details

    Click the image to enlarge.

    • If the selected service account is successfully removed, it disappears from the Service Account screen.
    • If Cloud App Security fails to remove the selected service account, you still have the option to forcibly remove your data generated in Cloud App Security as instructed.
  5. For SharePoint Online, OneDrive, and Microsoft Teams: Open {sharepoint_admin_site}/_layouts/15/TA_AllAppPrincipals.aspx, find the application with name Trend Micro Cloud App Security and the App Identifier associated with the service being deprovisioned, and then click in the front.

    Apps List

    Click the image to enlarge.