Skip to main content
This action is deprecated and no longer functional. Build an Agent with the Microsoft 365 tools instead. It covers the full onboarding/offboarding lifecycle and is the only supported path today. The page below is kept for reference only.
This action sets up new users in Microsoft 365 or removes departing users. It creates accounts, assigns licenses, manages mailboxes, and updates your PSA records.
This action is available only as a triggered action in workflows.

Quick start

1

Choose process type

Select whether you’re onboarding a new user or offboarding a departing user.
2

Configure approval settings

Set up human approval via Teams before making changes.
3

Select process steps

Choose which steps to enable: account creation, license management, group membership, mailbox handling, etc.
4

Add custom instructions

Provide specific guidance for unique scenarios or company-specific requirements.

How it works

This action manages user lifecycle processes:
  1. Analyzes the request - Reviews ticket content to understand onboarding/offboarding requirements
  2. Creates execution plan - Develops step-by-step plan based on your configuration
  3. Requests approval - Sends approval request to designated approvers if enabled
  4. Executes M365 changes - Creates/removes accounts, manages licenses, handles groups
  5. Manages security - Blocks access, handles device wipes, manages mailbox conversion
  6. Updates records - Creates/deactivates PSA contacts and updates ticket information

Setup

Process type: Choose what you want to accomplish:
  • Onboard a User: Set up a new employee with M365 access
  • Offboard a User: Remove departing employee and secure their data
Approval settings: Have designated people review and approve requests before execution. Select who gets approval requests in Teams. License management: Choose how to handle Microsoft licenses:
  • Direct Microsoft: Manage licenses directly through Microsoft
  • Pax8: Use your Pax8 account for license management
  • Microsoft Partner Center: Use Partner Center for licensing
Password handling (onboarding): Choose how new passwords are shared:
  • Secure Link: Create a one-time password link via Password Pusher
  • Direct Message: Include password directly in messages
  • No Sharing: Don’t share passwords automatically
Process steps: Control which steps happen during onboarding or offboarding. Custom instructions (optional): Provide specific instructions for unique scenarios or company-specific requirements.
For companies where users are created in on-prem Active Directory and synced to Microsoft 365, or maintained in both on-prem AD and Entra ID without a sync, follow the Hybrid AD User Onboarding recipe before running the agent live.