M365 leavers: OneDrive backups failing on locked or unlicensed accounts, and how Exclude policies apply per module
Machine-distilled from a resolved support ticket on 2026-09-28. Source ref: ba7588c4ec52. Verify before relying on it.
Applies to: HYCU R-Cloud protecting Microsoft 365 (Exchange Online, OneDrive for Business, Teams)
Symptom: Several OneDrive for Business backups start failing together, reporting that the user's OneDrive is locked or that the account is no longer licensed or enabled in Microsoft 365. Unprotected and compliance warnings are raised for these users. Administrators are unsure whether excluding a leaver's OneDrive and Teams will also stop backups of their mailbox, including after it has been converted to a shared mailbox.
Cause: While a Microsoft 365 account or its OneDrive is locked, or the user is unlicensed (typically leavers, removed licences or a new tenant policy), Microsoft blocks all access, so the backup cannot read the data. This is a Microsoft 365 side condition, not a backup system fault. R-Cloud manages each Microsoft 365 service as a separate module with its own entities and policy assignments, so a policy assigned in one module (for example OneDrive or Teams) has no effect on entities in another (for example Exchange Online).
Resolution: 1. Ask the Microsoft 365 administrator to check whether the affected accounts are still active and licensed, and to unlock any OneDrive accounts that should still be protected. 2. For users who have left and should not be protected, assign the Exclude policy to their entities in the OneDrive for Business and Teams modules. Excluded entities report as Undefined rather than Unprotected, which stops the failures and unprotected warnings and avoids skewing compliance metrics. 3. Note that this does not affect the mailbox: Exchange Online is a separate module. A mailbox converted to a shared mailbox becomes a distinct shared mailbox entity in Exchange Online and continues to be discovered and backed up according to the policy assigned there. To exclude it (and silence its warnings), assign the Exclude policy to it separately in the Exchange Online module. 4. For a recurring leaver process, consider automatic policy assignment in the module, keyed on mailbox type (shared mailbox) or on an Entra ID group such as a leavers group, to apply the Exclude policy automatically.
Was this article helpful?
That’s Great!
Thank you for your feedback
Sorry! We couldn't be helpful
Thank you for your feedback
Feedback sent
We appreciate your effort and will try to fix the article