Policy Statement

Effective 10 January 2025, all email accounts not assigned to individual users (e.g., FunctionalUnit@apu.edu.my) must be converted to shared mailboxes. This policy applies to all existing and newly created non-personal email accounts across the organisation. The policy is introduced to enhance security and ensure effective management of organisational email resources.


Purpose

The purpose of this policy is to:

  1. Strengthen security by minimising the risk of unauthorised access to generic email accounts.

  2. Streamline the management and monitoring of shared resources for operational efficiency.


Scope

This policy applies to:


Policy Requirements

  1. Mandatory Conversion:

  2. Access Permissions:


Procedure

  1. The Technology Services will identify all existing non-personal accounts and notify the respective department heads.

  2. Unit heads will provide a list of authorised users and their required access permissions (Full Access, Send-As, Send-On-Behalf).

  1. The IT team will perform the conversion and configure access permissions.

  2. Post-conversion, a security audit will be conducted to verify proper implementation and compliance.

For new accounts:


Exceptions

Exceptions to this policy may be granted under the following conditions:


Effective Date: 10 January 2025