Class of Services (COS)#

A COS determines which features and options can be accessed by a user, how to access them, and sets the default values for a number of them.

To create a COS, click the CREATE button, on the top left corner, then enter a name and optionally a description and some notes. You can then configure all the options for the COS by entering the left-hand side Details menu.

General#

COS List#

Initially the page presents the list of the COSes defined on Carbonio and their status. Click any of them to see its options and configure them.

Details#

General Information#

This section shows information about the chosen COS: name (which can be changed), ID, and creation date together with some calculated value: which accounts and domains use the COS. These values are expanded below, with the complete list of handled accounts and domains.

Features#

Features are settings that allow or forbid the user to access the various features related to the everyday use of Carbonio.

Some of these options can be enabled or disabled via CLI: please refer to section Setting Features from CLI for more information.

General

In this section, administrators can control whether users assigned to the current COS are allowed to access and modify their personal settings.

Note

Prevent users to access the Settings can be useful in some scenarios, for example:

  • An organisation wants that all the communication of its employees has the same branding (including also Out Of Office replies, the visible name of the sender, and other).

  • Another organisation needs that the e-mails be encrypted and does not want users to send plain-text e-mails.

Two-Factor authenticator

Allow users to configure two-factor authentication (2FA). Users can set up and manage their one-time passwords (OTPs) from their account settings.

Two-Factor authenticator setup enforcement

This section allows administrators to configure remote self-enrollment for two-factor authentication (2FA). Users who have not yet configured 2FA can be allowed to enroll their one-time password (OTP) even when connecting from an untrusted network, such as a home or public Internet connection.

The same settings can also be configured for individual users in the Security section of the account settings.

To enable remote self-enrollment:

  1. Open the Class of Service (CoS) assigned to the users.

  2. Enable Allow users to configure 2FA from untrusted networks.

  3. Configure the Grace Period by selecting an expiration date.

  4. Save the changes.

Until the configured expiration date is reached, users connecting from an untrusted network can authenticate using their username and password. Before completing the login process, they are prompted to configure their OTP through the enrollment wizard.

After the grace period expires, users who have not completed the enrollment can no longer configure 2FA remotely and must contact an administrator to complete the setup.

In the other sections, administrators can determine whether users assigned to the current COS can:

Mail

Use the “Carbonio Mail” mobile app.

Mail Signatures

Create, manage, and use email signatures.

Out of Office Reply

Configure and customize automatic out-of-office replies.

Contacts

Use the Contacts feature in the webmail.

Calendar

Use the Calendar feature in the webmail.

Tasks

Use the Tasks feature in the webmail.

Files

Use the Files feature in the webmail and the “Carbonio Files” mobile app.

Chat#

Options in this section allow to customise some of the Chats features.

General Settings

The only option here enables or disables the Chats.

Messaging & Presence

Define the time out after which text messages can be modified or deleted and whether a user can see other users’ status and read receipt.

Private and Group Chats

These options limit the user ability to create new private chats and groups and limit their number and the file size of files that can be shared.

Video Calls

Enable video call and the possibility of users to record video calls and use virtual backgrounds.

Sharing & Attachments

Enable files upload in chats and calls and set the file’ maximum size.

Preferences#

Preferences consist of generic options for the various components (Mails, Calendar, Contacts). Most of these options can be overridden by users in their Settings Module.

The first is the default language to be used by the members of the COS, which includes also the locale The list of supported languages can be found in section Available Languages. The remaining options concern:

  • the default appearance of Carbonio in web clients: for example, if e-mails are displayed as conversations, or the calendar shows a month or a work week. The maximum size for attachments sent by e-mail is also configurable here.

  • the default values or behaviour of the features: for example whether new e-mail contacts are added automatically to Contacts or how often to check for new e-mails

  • which options are available to the user: for example, whether the user is allowed to forward e-mails or create a filter to forward specific e-mails

  • The default behaviour for sending the read receipt to the e-mail sender: to always send it or not, or asking each time

  • Whether new contacts from which we receive an e-mail are automatically added to the user’s Contacts and if GAL should be used to auto-fill addresses of outgoing e-mails

  • A number of default options for the Calendar: time zone, how the calendar is displayed, and additional option for appointments and events.

Server Pools#

In this page it is possible to select on which servers new users can be added to the COS.

Note

If only one server has been defined, no choice is possible.

Advanced#

Multiple Advanced options can be configured here, divided into groups.

General Options

The options in this group allow users of the COS to access the Undelete E-mail feature, so each user can autonomously retrieve an e-mail from the Carbonio Backup. Global Administrators have also the ability to enable or disable the Backup feature for all users in the COS.

See also

The backup can be enabled or disabled by CLI as well, please refer to Section Disable Backup for a COS for example commands.

Accounts not in Backup

When Backup is disabled, the following happens in the COS:

  • The RealTime Scanner will ignore all accounts

  • The Export Backup function will not export the accounts

  • Accounts in the COS will be ignored by the backup system. This means that after the data retention period expires, all data for such accounts will be purged from the backup store. Re-enabling the backup for a Class of Service will reset this behaviour to the default one and mark accounts as Active.

Forwarding

Two options govern how to forward messages: how long an e-mail address can be and the maximum number of recipients allowed.

Password

Settings for password policies: length, characters, and duration of the user passwords. It is also possible to reject common passwords.

Hint

These settings are disregarded if authentication relies on an external server.

Failed Login Policy

Define the behaviour of Carbonio when a user fails a log in.

Hint

A typical policy can lock out the user for one hour when three consecutive login attempts fail within 30 minutes.

Timeout Policy

Configure the duration of the token’s validity, i.e., how long a user or Administrator will be able to keep the Web-mail open without interaction.

Email Retention Policy

Define how long e-mails will be stored before being automatically deleted from the Inbox (including its sub-folders), Trash, and Spam folders.

Note

Even if you configure E-mail message lifetime with a value below 31 days, the system will automatically enforce a minimum retention of 31 days.

Quota Management#

A set of options that show how much space a user can occupy on the server for Mails, Chats and Carbonio Files.

These quotas are inherited from the COS the user belongs to and may be changed for the current user. It also encompasses the options to send periodic notifications when the user space raises over a given threshold and a template for the notifications.

Note

Storage is managed through a single unified quota. Emails, Files, and Chats attachments all contribute to the same per-user storage quota so the quota configured for a Class of Service (COS) represents the total storage available to each user rather than separate limits for each service.

Resetting Quota Values to the Inherited Class of Service Value#

Administrators can quickly restore quota settings to the value inherited from an account’s Class of Service (COS) by using the Reset icon available next to quota-related input fields.

When a quota value has been modified for a specific account, click the Reset icon to discard the account-specific custom value and restore the quota value defined by the account’s COS. This provides a faster alternative to manually reconfiguring the account.

Note

Hovering over the Reset icon displays a tool tip indicating that the field can be reset to its inherited COS value.

Benefits#

The reset action simplifies quota management by allowing administrators to:
  1. Quickly recover from incorrect account-specific quota configurations.

  2. Remove temporary quota overrides.

  3. Restore the quota value inherited from the account’s Class of Service (COS) with a single click.

  4. Maintain centralized quota management by relying on Class of Service (COS) settings instead of individual account overrides.

  5. Improve visibility and consistency of quota policies across accounts by managing quotas through COS values.

  6. Reduce configuration errors and administrative effort.

Shared Documents and Class of Service Quotas#

Storage usage for shared documents is always attributed to the owner of the document. As a result the quota inherited from the owner’s Class of Service (COS) determines whether a shared document remains editable.

If the owner exceeds their storage quota, any shared documents they own remain accessible to collaborators but become read-only. Collaborators cannot modify, save, or create new versions of these documents until the owner’s storage usage falls below the configured quota or the owner’s quota is increased. Once the owner is back within quota, editing is restored automatically without requiring any additional configuration.

Limiting Domain Functionalities using COSes#

When Carbonio is configured with multiple domains, it is possible for Global Administrators to limit the amount of accessible Modules, the quota, and the number of accounts available within a domain by employing suitable COSes on the server.

In our scenario, the Carbonio infrastructure defines three COSes:

  • Lite featuring the Mails, Calendars, and Contacts modules and a user quota of 1Gb.

  • Basic with Mails, Calendars, Contacts, and Chats modules and 10GB of quota

  • Pro has full access to all modules and 30Gb of quota

The Global Administrator wants to define a new domain, acme.com, limiting the accounts to 200, including 50 Base and 30 Pro.

This scenario can be set up as follows:

  1. Create the new domain (e.g., using the NEW button) and assign it 200 accounts

  2. Select the domain and in its General Settings, scroll to the bottom and select the Lite, Basic, and Pro COSes and assign them the respective number of accounts (120, 50, and 30), then click LINK or DUPLICATE

    Hint

    By duplicating a COS, it will be named as, e.g., lite.acme.com and will be considered as an entirely separated COS. Any change to the original COS (e.g., lite) will therefore not be propagated to lite.acme.com.

  3. In the COS list, which is populated while carrying out step #2, select the first one (lite.acme.com) as the default one