Skip to content
Lambert Consulting

Artificial Intelligence: A Cross-Functional Offering

Results first. Infrastructure second.

An assistant for your documents, end-of-line verification, a platform for multiple services. Where artificial intelligence is applied is determined by your data, not by a catalog.

See all solutions
4Comparing Architectures, Criterion by Criterion
2 fieldsSoftware and hardware under one roof
All Use CasesUse cases first, technology last

Our first department

This is what needs to work every morning.

Your servers, your workstations, your phone systems, and your identities. The foundation that no one notices as long as it holds, but that everyone notices the day it fails.

View the department
Multi-siteNational and international projects
3Branches in French-speaking Switzerland
View our client projectsCase Studies and References
Let us know how you're doingGetting a quote is free

How We Work

A piece of advice, not a sales pitch.

Our approach is consultative: we tell you what we think, even when it’s not in our best interest. That’s what makes projects succeed.

About Us
1995First project, using Microsoft SMS
Family-orientedOn a human scale and sustainable

Our Branches

Vaud, headquarters9 Avenue des Baumettes, 1020 Renens+41 21 806 37 15
Valais134 Oscar-Bider Street, 1950 Sion+41 27 552 00 22
FribourgChemin de Montmoirin 18a, 1618 Châtel-Saint-Denis+41 26 322 59 05
Monday through Friday8:00 a.m. – 6:00 p.m.
Contact UsFirst 30-minute consultation, with no obligation

O365 Groups - Top 3 best practices for administrators to avoid clutter

By default,every user in your organization has the right to create a group Office 365. This is a major advantage for collaboration, but it’s an even bigger headache for management.

Publication Date
6 minReading time
Microsoft 365 and collaborationBlog Archive

Imagine: everyone creates groups without standardisation or consultation with others?

If you want to avoid all the chaos and manageyour groups stress-free, keep reading tosee our list of best practices.

No. 1 Configure the group naming policy Office 365

It is recommended that you use a group naming policy to enforce a standard naming policy. Setting up a naming policy will help your users to identify the group's function, its members, its geographical region or the group's creator.

There are two naming strategies, described below:

1. Prefixes and suffixes

The simplest way to define your naming conventions is to use prefixes and suffixes. These can be fixed strings, such as '_Name', or user attributes, such as [Department], which will be substituted according to the group creator.

For example, let's imagine a company that operates worldwide and has several marketing departments. If a Swiss user wants to create a group called "Promotional content", it would be wise to define a strategy similar to this one:

Policy = " [Department] [Country] [Group name]".

In this case, the attributes Azure Active Directory (AAD) of the group creator will be:

Department = "Marketing Country = "CH

This would lead to the creation of a group with this name:

Name of the group = "Content Marketing of Swiss Prom".

With a simple glance at the group name, you can identify the location and function of the group.

Some important points to note

  • This feature requires a AAD Premium license.
  • The user attributes supported in AAD are as follows: [Department], [Company], [Office], [StateOrProvince], [CountryOrRegion], [Title].
  • All other user attributes are considered fixed strings, for example, "[Postcode]".
  • You cannot add extension attributes or custom attributes.
  • You can write up to 53 characters in suffixes and prefixes.

2. Blocked words

For reasons of security or decency, you can create a list of blocked words ( separated by commas) that cannot be used for group names. A common scenario is to block profanity and obscenities, or specific words that you want only certain users to be allowed to use. For example, if a user in a human resources department wants to enter the word "Payroll" without an administrator's permission, the group name will fail because that administrator has restricted the use of that word to Finance users.

Things to bear in mind

  • This feature requires a premium license AAD.
  • Blocked words only work as an exact match.
  • Blocked words are not case sensitive.
  • You can block up to 5000 words.

Replacement of the administrator   

As a general rule, a select group ofadministrators are exempt from these rules and are allowed to create groups with any naming conventions they wish, even with blocked words. Administrators who can generally be exempted from these policies include:

  • Global admin.
  • Level 1 partner support.
  • Partner support level 2.
  • User account admin.
  • Writers' directory.

See howto configure the naming policy at Azure AD PowerShell .

No. 2 Configure the group expiration policy Office 365

Previously Office 365, only administrators had the right to create groups. Now, by default,every tenant user can automatically provision a new group with just a few clicks. This can increase the number of groups in your tenant,potentially making them nearly impossible to manage. At some point, you’ll need to clean up the clutter and delete some of your groups—groups that may no longer be in use or duplicate groups. A simple method is touse an expiration policyto delete your unwanted groups. Deleting unnecessary groups will also free up storage space and save you money.

What is an expiry policy?

Administrators can specify an expiry period after which the group will be deleted. Group owners will automatically receive an email before the expiry allowing them to renew the group for another expiry interval. When a group expires, it is deleted in software, which means that you can restore it for up to 30 days.

Who can set it up?

There arethree levels of permissions related to the expiration policy. The global administrator forOffice 365 can create, read, update, or delete expiration policy settings for groups Office 365. Group owners can renew or restore the groups they previously owned.

How can they set it up?

Expiration is disabled by default. Therefore, if you wish to use it, the administrator must enable it for your hosted client. To enable it, do the following:

  1. Open the administration centeratAzure Active Directory (AAD).
  2. Access the groups;
  3. Under Settings, click on the Expiration option.

Expiration Strategy - Administration Center Azure Active Directory

Here you can set the default group lifetime and specify how far in advance you want to trigger the first and second expiry notifications. The group lifetime can be set to 180 days, 365 days or a custom value that you specify.

No. 3 Configure the list of permissions/group blocks Office 365

Allow guest users

Suppose your company has a partnership or regularly collaborates with another company. You can add the partner company's domain to your control list so that your users can add these guests to their groups.

Blocking guest users

If you do not want your users to add people from certain domains, such as private email, to their groups, you can add those domains to the red list. For example, you can add the domains of Gmail.com, Yahoo.com or other popular email providers to your ban list.

Important points to note

  • You cannot set up the authorisation and block lists for a single group. By default, any domain that is not in the authorisation list is in the block list and vice versa.
  • This feature isavailable only with a AAD Premium license.
  • You can currently only define one authorisation/block list per organisation. However, you can update the existing list countless times.
  • A list of allow/block groups operates independently of a list of allow/block rules SharePoint.
  • The list does not apply to guests already added to the group, but you can remove them viathe script or using our permissioncontrol tool
After reading

What an article Can't Know

An article describes what applies to everyone. What varies from one organization to another is the inventory: which applications, which accounts, and which pieces of equipment are actually involved in your organization. The inventory determines the scope of the effort, and it cannot be summarized on a single page.

You'll be speaking directly with the engineers who will be doing the work, not with a middleman. We'll respond within 24 business hours.

If the topic has changed

Check what is still true

Announced dates are sometimes postponed, products are renamed, and conditions change. The blog tracks these topics over time: when a rule changes, a new post announces it.

Search for a topic in the blog