PII options help protect sensitive user data in Brightspace test environments. You can request individual PII options or run the Brightspace PII Data Anonymizer to anonymize user data throughout the environment.
To learn what a test environment refresh is and how to request one, refer to About test environment refresh.
PII Options
Access to administrator accounts may differ between your test and production environments. If test environment administrators do not have access to production administrator accounts, consider implementing personally identifiable information (PII) protections to help protect real user data.
- PII options mask sensitive personal information upon request.
- They are typically used with a refresh but can also run independently. PII options are included with any refresh upon request.
- When you request a refresh, include the PII options you want. You can request multiple options.
Data anonymizer
Option: PII Anonymize Users Exclude Cascading
What it does
- Runs the full anonymizer using the default configuration.
- The anonymizer replaces user PII across the learning environment.
For example, the anonymizer:
- Replaces usernames with generated GUIDs.
- Replaces first and last names using a dictionary of common names.
To customize anonymization, contact your D2L representative to request an Implementation Consultant engagement.
Who it affects
This option affects all organizations in the ILP.
Affected users:
- All users, excluding those in cascading roles and tool roles.
Basic user information is maintained for users in cascading roles and tool roles.
Communication clean
Option: PII Communication Clean
What it does
- Mask the PII in email.
- Affected fields: AddressTo, AddressFrom, AddressReplyTo, AddressCC, AddressBCC.
- Body attachments are removed from both emails and news items.
- Email signatures are removed.
Who it affects
This option can be targeted to a specific ILP organization in shared or consortium instances.
Affected roles:
- student
- parent
- teacher
- staff
- employee
Excluded roles:
- cascading roles
- tool roles (for example, Administrator, Super Administrator, LTI Advantage User, SIS Integration User)
Deactivate Users
Option Code: PII Deactivate Noncascading Users
What it does
This option deactivates all non-cascading users in your test environment. Administrators can re-enable deactivated users without recreating them. Deactivated users cannot log in until they are re-enabled.
Who it affects
Affected roles:
- student
- parent
- teacher
- staff
- employee
Excluded roles:
- cascading roles
- tool roles (for example, Administrator, Super Administrator, LTI Advantage User, SIS Integration User)
Delete email addresses
Option: PII Delete Noncascading Email Addresses
What it does
- Deletes user email addresses.
- This prevents emails from the test environment from being sent to real users.
For example:
- Testing Classlist-based emails could send real emails if addresses are not removed.
Who it affects
This option can be targeted to a specific ILP organization in shared or consortium instances.
Affected roles:
- student
- parent
- teacher
- staff
- employee
Excluded roles:
- cascading roles
- tool roles (for example, Administrator, Super Administrator, LTI Advantage User, SIS Integration User)
Delete local passwords
Option: PII Delete Noncascading Passwords
What it does
- Deletes local user passwords, which prevents users from logging in with local passwords.
- Users can still log in if they are authorized for single sign-on (SSO).
Who it affects
This option can be targeted to a specific organization in shared or consortium instances.
Affected roles:
- student
- parent
- teacher
- staff
- employee
Excluded roles:
- cascading roles
- tool roles (for example, Administrator, Super Administrator, LTI Advantage User, SIS Integration User)
Delete Users
Option Code: PII Delete Noncascading Users
What it does
This option deletes all non-cascading users from your test environment. Unlike most refresh options, it requires deleted users to be recreated before they can log in again.
Who it affects
Affected roles:
- student
- parent
- teacher
- staff
- employee
Excluded roles:
- cascading roles
- tool roles (for example, Administrator, Super Administrator, LTI Advantage User, SIS Integration User)
ePortfolio and profile clean
Option: PII ePortfolio and Profile Clean
What it does
- Breaks ePortfolio links and images for affected users.
- Clears the entire user profile for affected users.
- Profile fields removed include: Favorite Memories, Hobbies, Hometown, Nickname, phone numbers and other personal details.
Who it affects
This option can be targeted to a specific ILP organization in shared or consortium instances.
Affected roles:
- student
- parent
- teacher
- staff
- employee
Excluded roles:
- cascading roles
- tool roles (for example, Administrator, Super Administrator, LTI Advantage User, SIS Integration User)
Anonymizer options
The Brightspace PII Data Anonymizer (Anonymizer) anonymizes personally identifiable information (PII) in a Brightspace environment using a combination of pseudonymization, generated identifiers, blank values, and null values. For example, usernames are replaced with newly generated GUIDs, while other PII is cleared or set to null based on the data type.

|
Important: The Brightspace PII Data Anonymizer should not be run on production environments.
|
Running the anonymizer
Running the anonymizer does not require a test site refresh, although it is commonly performed as part of a refresh.
During anonymization:
Restoring an anonymized environment
The anonymization process cannot be reversed.
To restore original user information, perform a test site refresh of the non-production environment.
Users included in anonymization
By default, the anonymizer targets users who are not assigned to cascading roles.
Users assigned to cascading roles are excluded from anonymization because these roles typically belong to administrators, developers, or support personnel.
If you want to include or exclude additional roles, provide one of the following with your request:
- Exact role names
- Role IDs
The following non-cascading tool roles are excluded from anonymization:
- LTI Advantage User
- SIS Integration User
- SIS Integration
- CourseCatalog
- D2LMonitor
For additional information about roles, refer to About roles and permissions.
Default anonymization behavior
The default anonymizer replaces or removes common forms of personally identifiable information while preserving accounts assigned to cascading roles and excluded tool roles.
Basic user information
The anonymizer replaces or clears:
- Legal first name
- Legal last name
- Preferred first name
- Preferred last name
- Middle name
- Username
- Email address
User profile information
The anonymizer clears all user profile information, including:
- Favorite memories
- Hobbies
- Hometown
- Nickname
- Phone numbers
- Other profile fields
Additional user information
The anonymizer clears or replaces:
- Email signature
- Google URL
- Facebook URL
- LinkedIn URL
- Twitter URL
- Local password
IPSIS user information
The anonymizer:
- Removes user relationships with Exchange and SharePoint services.
- Replaces the IM User Identifier with a generated GUID.
Contact information
The anonymizer removes user contact information, including:
- Mailing addresses
- Phone numbers
- Website URLs
- Email addresses
The anonymizer also removes ePortfolio objects.
User contacts
The anonymizer clears user contact lists and associated contact information.
- Login history
- Replaces usernames with generated GUIDs.
- Sets originating IP addresses to
0.0.0.0.
Email
All email stored in the Brightspace instance is anonymized, including email belonging to users in cascading roles and excluded tool roles.
The following email fields are anonymized:
- To
- From
- Reply-To
- CC
- BCC
- Subject
- Body
- Attachments
User integrations after anonymization
After anonymization completes, student users may reappear if user integrations recreate or update accounts.
This behavior commonly occurs when integrations such as SIS, IPSIS, or Banner are configured with strict ownership of user records.
If you want anonymized users to remain anonymized, configure your test site integrations so they do not recreate or repair anonymized accounts.
Custom anonymization
The default anonymizer covers the most commonly anonymized user data. Additional Brightspace data can be included through a customized anonymizer configuration to meet your organization's requirements. Over-anonymizing an environment can reduce its usefulness for testing.
If you need additional data anonymized, contact your D2L account representative to customize the anonymizer configuration. The customized configuration is preserved and can be reused for future test site refresh and anonymization requests.