User identity, Account Provisioning, Directory Synchronization, Federation
|
|
|
- Theresa Shelton
- 10 years ago
- Views:
Transcription
1 User identity, Account Provisioning, Directory Synchronization, Federation
2 Workshop Purpose and Objectives Workshop Purpose Plan for user identity and provisioning, including discussion of Active Directory Domain Services (AD DS) cleanup, *configuration of identity federations, and planning for the installation and configuration of the Microsoft Online Services Directory Synchronization (DirSync) tool Objectives Establish approach for adding and provisioning users for the service Understand and plan for Office 365 licensing activation Understand and plan for steps required to enable Directory Synchronization *Outline identity federation requirements and provide approach 2 *Denotes optional Service Enhancement features
3 Common Identity Platform Windows Azure Active Directory (WAAD or Azure AD) is the underlying identity platform for various Organizational cloud services Windows Azure Active Directory Authentication platform Directory store 3
4 User Identity and Account Provisioning Planning Workshop Topics Current Provisioning and Deprovisioning process Review current identity lifecycle tools and process Provision Users and License Activation Active Directory Synchronization *Identity Federation Review options to provision and license users Review requirements and drive planning considerations to implement synchronization between on-premises AD DS and the Office 365 environment Review requirements to support single sign-on 4 *Denotes optional Service Enhancement features
5 Current Provisioning and Deprovisioning Process HR System Manual process or automated through feed What is the most common login identity (AD, LDAP, etc) Employee creation Mailbox creation Groups Contractors Terminated Mailbox retention Provisioning Deprovisioning Workshop participants and outcomes Participants Technical Leads (AD DS and Provisioning) Outcome Draft user provisioning and licensing approach 5
6 Provision Users and License Activation Differences between account provisioning and licensing Provisioning Options License Activation Workshop participants and outcomes Participants Technical Leads (AD DS and Provisioning) Outcome Draft user provisioning and licensing approach 6
7 Provisioning Options Option Directory Synchronization Windows PowerShell Bulk Import Microsoft Online Services Portal Considerations Synchronizes users from the customer s AD DS infrastructure to the Microsoft Online Services environment Synchronizes security and mail-enabled groups *Allows for onboarding and offboarding of users when Exchange hybrid deployment is configured *Provides the infrastructure necessary to support single sign-on Allows mass import of users via Windows PowerShell command line interface scripting Does not allow for single sign-on Allows for an import of a comma-separated values (CSV) file to mass populate users Does not allow for single sign-on Provides a simple web interface to add and modify user accounts Cannot be used to modify users if Directory Synchronization is enabled *In a federation scenario that enables single sign-on, Directory Synchronization is the only provisioning option User identities can be mastered on-premises Existing end-user provisioning capabilities that integrate with on-premises AD DS can be used with Office *Denotes optional Service Enhancement features
8 Office 365 Management cmdlets Management categories Manage users Manage group and role memberships Manage service principals Manage domains *Manage single-sign on Manage subscriptions and licenses Manage company information and service Manage Microsoft Exchange Online Description Used to perform a variety of tasks related to managing users, passwords, and user principal names (UPN). Used to perform a variety of tasks related to group and role membership, including adding a user to a role or group, creating groups, and removing groups. Used to perform a variety of tasks related to service principals. Used to perform a variety of domain management tasks, including creating or removing a domain. Used to perform tasks related to single sign-on, such as adding a new single sign-on domain to Office 365. Used to manage subscriptions, accounts, and licenses. Used to perform tasks related to managing your company s information and connecting to Office 365 for enterprises. There are also cmdlets for tasks performed by partner companies. Used to perform management tasks that are not available nor practical in the Exchange Administration Console (EAC). 8 *Denotes optional Service Enhancement features
9 Provisioning Gotchas DirSync must sync the objects to Office 365 before a license can be assigned Provisioning requires several steps in order to get a new user up and running in Office 365 Users should only be licensed for what customer is ready to support. SharePoint, Lync, OneDrive, Office Pro Plus may not be ready for consumption EAS, POP3, IMAP are all on by default when a mailbox is provisioned. Powershell would need to be run to turn these off as the mailbox is created Workshop participants and outcomes Participants Technical Leads (AD DS and Security) Microsoft has some sample scripts that can help provision users based on group membership Outcome Document plan to support single-sign and overall AD FS implementation approach. 9
10 Active Directory Synchronization Review requirements to drive planning considerations to implement synchronization between the on-premises AD DS and the Office 365 environment Directory Synchronization Overview Source of Authority AD DS Preparation *Multi-forest Deployment Considerations Workshop participants and outcomes Participants Technical Leads (AD DS and Network) Two-way Synchronization (write-back) Password Sync Outcome Document plan to modify Domain Controller infrastructure to support Office 365 requirements, implement Direct Synchronization appliance, and clean up required AD DS attributes 10 *Denotes optional Service Enhancement features
11 Directory Synchronization Overview Required permissions for installation Enterprise Administrator rights during the installation process. Nonprivileged AD DS account is required post-installation (this account is automatically created during installation). Review planning considerations for installation of the Directory Synchronization tool AD DS object considerations If a domain is verified on the tenant, by default, it will be possible to synchronize up to 300,000 AD objects (if no domain validated, no more than 50,000 objects). To sync more objects, the Office 365 support team will need to be contacted to open a service request with the number of objects to synchronize. Capacity planning For object count greater than 50,000, Microsoft SQL Server 2008 R2 or higher is required and can be installed on the same server as Dirsync. Follow-up actions and additional information from prior assessments Service Enablement Plan Considerations Review AD DS object count to be synchronized, and draft Directory Synchronization installation plan accordingly [List specific issues uncovered or context from prior assessments] 11
12 Directory Synchronization Hardware Requirements Active Directory Objects CPU Memory Hard Disk Full SQL Required? Less than 10, GHz 4 GB 70 GB No 10,000 50, GHz 4 GB 70 GB No 50, , GHz 16 GB 100 GB Yes 100, , GHz 16 GB 300 GB Yes 300, , GHz 32 GB 450 GB Yes More than 600, GHz 32 GB 500 GB Yes This table includes SQL sizing if SQL is installed on same box than Dirsync ( AD objects and more) If SQL is deployed on a dedicated server, use these numbers for SQL and size an additional server for DirSync with 2 cores, 4GB RAM and 72 GB disk 12
13 Source of Authority Office 365 requires a single source of authority for every object. Three scenarios exist for where source of authority is changed for an object. Activate: When you activate Directory Synchronization and then synchronize directories, the source of authority for any cloud object that is matched to an on-premises object is transferred from the cloud to your on-premises AD DS. Deactivate: When you deactivate Directory Synchronization, the source of authority is transferred from the on-premises AD DS to the cloud. Reactivate: When you reactivate Directory Synchronization, the source of authority is transferred from the cloud back to your onpremises AD DS (where it previously resided). Follow-up actions and additional information from prior assessments Service Enablement Plan Considerations Review concept of "source of authority" and the three scenarios it applies to (active, deactivate, reactivate). Review steps to ensure minimal directory data loss in the reactivate scenario by reviewing the globally unique identifier (GUID) and Simple Mail Transfer Protocol (SMTP) match logic. (online resource) [List specific issues uncovered or context from prior assessments] 13
14 Active Directory Preparation Review tasks needed to address remediation efforts. Outline plan for addressing all directory object preparation activities. Verify each user planning to use Office 365 has a valid and unique address Remove duplicate values in the ProxyAddress attribute field and UserPrincipalName that exists in the forest Populate the following username attributes: First name Last name Display name Directory object preparation Use IDFix to remediate AD Follow-up actions and additional information from prior assessments Service Enablement Plan Considerations Review the state of the on-premises AD DS from previous assessments. Document remediation steps prior to first synchronization. [List specific issues uncovered or context from prior assessments] 14
15 Directory Object Preparation Guidance 15 Maximum number of characters: 20 Invalid Note: If a user has an invalid samaccountname but a valid userprincipalname, the user account is created in Office 365. Note: If both the samaccountname and userprincipalname are invalid, the on-premises AD DS userprincipalname must be updated. samaccountname Maximum number of characters: 256 Invalid characters: [! #$ %&*+ / =? ^ ` { }] The mail attribute cannot contain any duplicate values. Note: If there are duplicate values, the first user with the value is synchronized. Subsequent users will not appear in the Microsoft Online Services Portal. You must modify the value not found the in portal, or modify both of the values in the on-premises directory in order for both users to appear in the Office 365 service. mail For mail-enabled objects and alternate addresses, the targetaddress attribute is required. This is especially true in third-party messaging migration and coexistence scenarios. If the targetaddress attribute is not present, the fallback is to the mail attribute. Maximum number of characters: 256 Invalid characters: [! #$ %&*+ / =? ^ ` { }] targetaddress Maximum number of characters: 64 Questionable characters:?@\+ givename sn (surname) Maximum number of characters: 64 Invalid characters: ""\\\[\]:><; and space mailnickname userprincipalname Maximum number of characters: 256 Questionable characters:?@\+ displayname Maximum number of characters: 256 Invalid characters: \)\(;><\]\[\\, Multi-value attribute proxyaddresses Maximum number of characters for username: 64 Maximum number of characters for domain name: 256 Invalid characters: }{ # * + ) ( > < / \ =? ` & character: Automatically changed to underscore: character is required in each userprincipalname character cannot be first character in each value. Username cannot end with a period (.), an ampersand (&), a space ( ), or an at sign (@). Username cannot have a space ( ). Routable domains must be used. Unicode is converted to underscore characters. userprincipalname may not contain any duplicate values in the forest. Note: Before making changes to the attribute it is critical to validate that there are no applications dependent on the existing value such as smart cards, certificates, Unix, or Linux.
16 *Multi-forest Deployment Considerations Review options for a multi-forest AD DS implementation, including forest consolidation or a primary logon forest. Evaluate consolidation - In general, there is more overhead required to maintain multiple forests. Unless the organization has security constraints that dictate the need for separate forests, consider simplifying the on-premises environment prior to deploying Office 365. Required Multiforest Synchronization- Dirsync appliance cannot be used, required Office 365 supported MA Additional multi-forest options can be provided through FIM-based solutions in place of the standard Directory Synchronization software appliance. Follow-up actions and additional information from prior assessments Remediation Checklist Review if multi-forest scenario is applicable. Document remediation steps prior to first synchronization. Considerations [List specific issues uncovered or context from prior assessments] 16 *Denotes optional Service Enhancement features
17 Two-Way Synchronization (write-back aka Hybrid) Two-way synchronization (or write-back) is required for Office 365 features and functionality such as cloud-based archiving, safe and blocked senders configuration, and cloud voice mail Filtering coexistence Enables two-way synchronization onpremises filtering and online safe and blocked sender data from clients MSExchBlockedSendersHash, SExchSafeRecipientsHash, MSExchSafeSendersHash Online archive Allows archiving of mail in Office 365 MSExchArchiveStatus Mailbox offboarding Allows online mailboxes to move back on-premises ProxyAddresses *Enabled Unified Messaging online voice mail Indicates to Lync communications software when user has a voice mail in Office 365 MSExchUCVoic Settings Delegates Allows delegation of a user s mailbox Follow-up actions and additional information from prior assessments Service Enablement Plan Considerations Review business requirements to determine if two-way synchronization is to be enabled. Document steps to support the appropriate features outlined. [List specific issues uncovered or context from prior assessments] 17 *Denotes optional Service Enhancement features
18 Core identity scenarios with Office 365 Cloud identity Cloud identity with directory & password synchronization Federated identity ADFS Federated identity 3 rd Party IDM Single cloud identity Single identity but separate credentials suitable for medium and large organizations Single identity utilizing AD credentials & password. Required for MFA and access controlled environments Single identity utilizing AD credentials & password. Required for MFA and access controlled environments
19 Identity federation Review requirements to enable single sign-on. Identify tasks required to enable in-scope scenarios covering user experience and align customer s AD DS implementation for federation. Identity Federation Requirements Infrastructure Design Workshop participants and outcomes Participants Technical Leads (AD DS and Security) User Experience by Location Namespace Considerations and Acceptable Domains Virtualization and Capacity Planning Outcome Document plan to support single-sign and overall AD FS implementation approach. 19
20 DirSync with Password Sync Description Not Single Sign On (SSO), but user experience nearly identical to ADFS, password cached for Outlook and Lync Substantially less complex, less hardware, networking, and only a single server to monitor Password is synched to cloud, Microsoft becomes responsible for login Password can be used across cloud properties No longer need to route any traffic back on premises like ADFS Password Changes/Deactiveated users are high priority and force a sync Concerns Security concerns, we sync the hash, we reverse the hash and we obfuscate it beyond that Account lockouts not replicated to cloud, DirSync syncs Account Disabled Password expiry on-premises will not result in password expiry in the cloud No auditing logs for logins Limited two factor (2FA) authentication coming soon Requires customer Portal to change passwords No High Availability, but not critical in current form No way to control access via ADFS claims 20
21 3 rd Party IDM Description Not all 3 rd party IDM s are equally integrated Not a formal logo program Some 3 rd parties entering this space without a formal relationship with Office 365 Product Group Concerns Active (Outlook, Lync) vs Passive (OWA) applications Some have issues with remapping UPN and cause AUTOD issues Others have issues with multiple federated namespaces Not true SAML, uses WSFED in many cases 21
22 Identity Federation Requirements User Principal Name (UPN) available in AD since Windows 2000, it is not tied to Sam Account Name UPN Required! Workshop participants and outcomes Participants Technical Leads (AD DS and Security) Office 365 leverages domains to uniquely identify customers in multi-tenant environment UPN = [email protected] SAM Account = contoso\eadams SMTP [email protected] Message to Users: Users can now login to everything with their addresses! (Office 365, Windows, Applications ) Outcome Document plan to support single-sign and overall AD FS implementation approach. 22
23 Identity federation requirements Single Active Directory forest The onpremises infrastructure must meet the following requirements to implement AD FS. AD FS deployed on Windows 2008 R2 Server or higher Supported client operating system and service packs Unique third-party SSL certificate for AD FS proxy server to allow: Remote workers to access the service without a virtual private network (VPN) For ActiveSync devices Outlook clients running on Windows XP or Windows Vista, or any version of Windows XP, Windows Vista, and Windows 7, where NEGO2 (Nego2 HTTP Authentication Protocol) is not implemented For IMAP clients For POP clients Windows PowerShell 2.0 to provide remote access to the AD FS server Follow-up actions and additional information from prior assessments Service Enablement Plan Considerations Review requirements to support identity federation. Capture necessary actions to be taken in the Prepare phase to support identity federation. [List specific issues uncovered or context from prior assessments] 23
24 User experiences A user s experience with single sign-on varies, based on how the user s computer is connected to the organization s network and how an administrator has configured AD FS. Sample configurations are as follows: Work computer on a corporate network. When users are at work and signed into the corporate network, single sign-on allows them to access the services in Office 365 with their corporate credentials. Roaming with a work computer. For users who are logged onto domain-joined computers with their corporate credentials, but who are not connected to the corporate network (for example, a work computer at home or at a hotel), single sign-on allows them to access the services in the Office 365. Home or public computer. When the user is using a computer that is not joined to the corporate domain, the user must sign in with corporate credentials to access the services in the Office 365 suite. AD FS federation server proxies are required in this scenario. Non domain-joined computer on a corporate network. This configuration is similar to the one previously described, except that AD FS federation server proxies are not required in this scenario. Follow-up actions and additional information from prior assessments Service Enablement Plan Considerations Review user experiences that are deemed required, and plan AD FS design accordingly. [List specific issues uncovered or context from prior assessments] 24
25 Virtualization and capacity planning Capacity planning for AD FS is the process of forecasting peak usage periods and planning or scaling-up the AD FS server deployment to meet those load requirements. AD FS supports software virtualization of both the federation server and federation-server proxy roles. To account for redundancy, Microsoft recommends that each AD FS virtual machine be stored on a separate physical virtual server. Number of users Suggested hardware configuration For additional AD FS capacity planning guidance, please refer to Planning for AD FS Server Capacity. Fewer than 1,000 No dedicated federation server proxies. Two dedicated load-balanced AD FS servers. 1,000 to 15,000 Two dedicated federation server proxies. 15,000 to 60,000 At least two dedicated federation server proxies. More than 60,000 Use the AD FS Capacity Planning Spreadsheet. Follow-up actions and additional information from prior assessments Service Enablement Plan Considerations Review anticipated user count for AD FS capacity planning. Document anticipated hardware needs or virtualization approach, if necessary. [List specific issues uncovered or context from prior assessments] 25
26 Office 365 identity-federation standard design The Office 365 identity-federation standard design represents a baseline implementation for providing the single sign-on experience. Outlines the standard design from Microsoft Services for establishing identity federation with Office 365. The provided architecture does not represent the only available option but, instead, the standard design that Microsoft Services recommends and implements. Specific requirements or constraints that are not satisfied within the standard design should be discussed and addressed. Out of scope for the standard design: Office 365 cloud identities that are used for authentication (user identities that are managed fully in the cloud without integration with on-premises AD DS) Operations guidance to run the identity federation and Directory Synchronization infrastructure Advanced requirements that would require custom design, such as: Multiple forest topologies Strong authentication or two-factor authentication Geo-redundancy support for federation services Follow-up actions and additional information from prior assessments Service Enablement Plan Considerations Review the Office 365 identity federation standard design documentation, and validate it with the existing enterprise requirements for single sign-on. [List specific issues uncovered or context from prior assessments] 26
27 Standard design logical view AD FS is the logical component that implements the federation standards required to configure identity federation between the on-premises Active Directory forest and Office 365. Directory Synchronization for Office 365 performs synchronization of AD DS objects (users, groups, and contacts) from one on-premises AD DS into one Office 365 tenant directory. Windows Azure Active Directory represents the multi-tenant directory service in the cloud. Office 365 Authentication Platform represents the authentication platform that constitutes the relying party for the federation with the onpremises Active Directory forest. Office 365 Provisioning Web Service exposes a web service interface used by on-premises Directory Synchronization to synchronize data with the Microsoft Online Directory Services. Client components use three different authentication flows in federated identity scenarios, based on the type of client: The active profile is used with Microsoft Outlook and Exchange ActiveSync devices. The metadata exchange (MEX) is used with Microsoft Lync and the Office Pro Plus Subscription Agent. The passive profile is used with web browsers and other Office applications such as Microsoft Word, Excel, and PowerPoint. 27
28 Standard design physical view Active Directory Federation Server is a specific role service of AD FS, designed to implement the federation protocols, to define and manage relying parties, and to provide tokens in response to requestors. Active Directory Federation Proxy or Application Proxy is a specific role service of AD FS, designed to publish the AD FS on the Internet, for federation relationships involving external relying parties. Directory Synchronization Server continuously synchronizes the Active Directory forest onpremises with Office 365. Domain Name System (DNS): The Office 365 identity federation standard design prescribes a split-dns design for the AD FS internal and external load balanced endpoints. This essentially means that the same external fully qualified domain name (FQDN) (typically sts.contoso.com) must be resolved differently for internal and external resolvers. Internal clients (internal DNS) must resolve the AD FS external FQDN to the load balanced end point of the internal AD FS federation servers. External resolvers (public DNS) must resolve the AD FS external FQDN to the load balanced end point of the AD FS proxy servers. 28 Additional AD FS proxy considerations and a list of required ports and protocols are provided in the Office 365 Identity Federation Standard Design documentation.
29 Understanding client authentication path OWA Internal AD FS 2.0 Server MEX Web Active Outlook 2013 IMAP/POP AD FS 2.0 Proxy MEX Web Active Lync 2013/ Office Subscription Active Sync Username Password Basic auth proposal: Pass client IP, protocol, device name Corporate Boundary Username Password Lync 2013/ Office Subscription Exchange Online Username Password OWA External Active Sync Username Password Outlook 2013 IMAP/POP
30 Identity federation Authentication flow (passive/web profile) Customer Microsoft Online Services Active Directory AD FS 2.0 Server Logon (SAML 1.1) Token Source User ID: ABC123 Authentication platform Auth Token Unique ID: ` Client (joined to CorpNet) Exchange Online or SharePoint Online
31 Identity federation Authentication flow (MEX/rich client profile) Customer Microsoft Online Services Active Directory AD FS 2.0 Server Logon (SAML 1.1) Token Source User ID: ABC123 Authentication platform Auth Token Unique ID: ` Client (joined to CorpNet) Lync Online
32 Identity federation Active flow (Outlook/Active Sync) always external Customer Microsoft Online Services Active Directory AD FS Logon (SAML 1.1) Token Source User ID: ABC123 Authentication platform AD FS Proxy Auth Token Unique ID: ` Client (joined to CorpNet) Basic Auth Credentilas Username/Password Exchange Online
33 Namespace considerations and acceptable domains Support for multiple top domains is available within AD FS AD FS has an update rollup that works in conjunction with SupportMultipleDomain switch to support multiple top-level domains for UPN suffixes. Note: the SupportMultipleDomain switch is not required when you have a single top-level domain and multiple subdomains. Only routable domains can be used with an AD FS deployment. Examples of nonroutable domains are the following:.local.loc.internal Follow-up actions and additional information from prior assessments Service Enablement Plan Considerations Review whether multiple namespaces are in use, and determine whether the SupportMultipleDomain AD FS switch is needed. Review whether the UPN suffix is required for instances in which the customer has implemented AD DS with an internal namespace. [List specific issues uncovered or context from prior assessments] 33
34 Client access control AD FS 2.0 Server AD FS 2.0 Proxy Passiv e Active Passiv e Active Browser Internal Browser External Web Auth (OWA, SharePoint) Outlook and ActiveSync Auth Block all external access to Office 365 based on the IP address of the external client Block all external access to Office 365 except Exchange Active Sync; all other clients such as Outlook are blocked. Block all external access to Office 365 except for passive browser based applications such as Outlook Web Access or SharePoint Online Outlook 2010/2007 ActiveSync ActiveSync Outlook 2010/2007
35 Identity federation Recap and next steps Provision Users and License Activation Active Directory Synchronization Identity Federation Complete planning for: Federation design for user experience requirements. AD FS infrastructure design (validate if Standard Design will meet requirements). Namespace and domains for federated identities. Service Enablement plan to be completed for Assess phase completion checkpoint (mmm/dd). 35
36 Questions? 2013 Microsoft Corporation. All rights reserved. Microsoft, Access database software, Active Directory directory service, ActiveSync technology, ActiveX controls, Excel spreadsheet software, InfoPath information gathering program, Internet Explorer Internet browser, Lync communications software, Office 365 hosted productivity software, OneNote note-taking program, Outlook 2013 Microsoft Corporation. All rights reserved. Microsoft, Windows, Windows Vista and other product names are or may be registered trademarks and/or trademarks in the U.S. and/or messaging and collaboration client, PowerPoint presentation software, RoundTable communications and archival system, SharePoint services, SQL Server software, Windows operating system, other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation as of the date of this presentation. Because Microsoft must Windows Azure technology platform, Windows Intune software and services, Windows Server operating system, and Windows Vista operating system and other product names are or may be respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided registered trademarks and/or trademarks in the U.S. and/or other countries. The information herein is for informational purposes only and represents the current view of Microsoft Corporation after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION as of the date of this presentation. Because Microsoft must respond to changing market conditions, it should not be interpreted to be a commitment on the part of Microsoft, and Microsoft cannot guarantee the accuracy of any information provided after the date of this presentation. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED, OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION
Mod 3: Office 365 DirSync, Single Sign-On & ADFS
Office 365 for SMB Jump Start Mod 3: Office 365 DirSync, Single Sign-On & ADFS Chris Oakman Managing Partner Infrastructure Team Eastridge Technology Stephen Hall CEO & SMB Technologist District Computers
Network Configuration/Bandwidth Planning Scope
Network Configuration/Bandwidth Planning Scope Workshop Focus and Objective Workshop Focus Drive key planning considerations for Office 365 domain and domain name service (DNS) records configuration Network
Mod 2: User Management
Office 365 for SMB Jump Start Mod 2: User Management Chris Oakman Managing Partner Infrastructure Team Eastridge Technology Stephen Hall CEO & SMB Technologist District Computers 1 Jump Start Schedule
Bill Fiddes Learning and Development Specialist Rob Latino Program Manager in Office 365 Support
Bill Fiddes Learning and Development Specialist Rob Latino Program Manager in Office 365 Support Learning & Development Specialist Customer Support Services Been with Microsoft for 7 years Professionally
Office 365 deployment checklists
Chapter 128 Office 365 deployment checklists This document provides some checklists to help you make sure that you install and configure your Office 365 deployment correctly and with a minimum of issues.
Office 365 deploym. ployment checklists. Chapter 27
Chapter 27 Office 365 deploym ployment checklists This document provides some checklists to help you make sure that you install and configure your Office 365 deployment correctly and with a minimum of
Workshop purpose and objective
Messaging Workshop purpose and objective Workshop purpose Facilitate planning discussions for messaging coexistence Considerations of Office 365 limits and features Objectives Identify Microsoft Office
SINGLE & SAME SIGN-ON ASPECTS
SINGLE & SAME SIGN-ON ASPECTS OF AZURE ACTIVE DIRECTORY Harold Baele Senior ICT Trainer JULY 2, 2015 SLIDE 1 TRAINER INFO Harold Baele MCT at RealDolmen Education [email protected] - @hbaele
Microsoft Premier Deployment. Office 365 Service Description
Microsoft Premier Deployment Office 365 Service The information contained in this document represents the current view of Microsoft Corporation on the issues discussed as of the date of publication and
SPHOL300 Synchronizing Profile Pictures from On-Premises AD to SharePoint Online
SPHOL300 Synchronizing Profile Pictures from On-Premises AD to SharePoint Online Contents Overview... 3 Introduction... 3 The Contoso Ltd. Scenario... 4 Exercise 1: Member Server Sign up for Office 365
MICROSOFT 70-346 EXAM QUESTIONS & ANSWERS
MICROSOFT 70-346 EXAM QUESTIONS & ANSWERS Number: 70-346 Passing Score: 800 Time Limit: 120 min File Version: 58.5 http://www.gratisexam.com/ MICROSOFT 70-346 EXAM QUESTIONS & ANSWERS Exam Name:Managing
Migrating Exchange Server to Office 365
Migrating Exchange Server to Office 365 By: Brien M. Posey CONTENTS Domain Verification... 3 IMAP Migration... 4 Cut Over and Staged Migration Prep Work... 5 Cut Over Migrations... 6 Staged Migration...
Agenda. Federation using ADFS and Extensibility options. Office 365 Identity overview. Federation and Synchronization
Agenda Office 365 Identity overview 1 Federation and Synchronization Federation using ADFS and Extensibility options 2 3 What s New in Azure AD? Cloud Business App - Overview 4 Identity Management is
Table of Contents Introduction... 2 Azure ADSync Requirements/Prerequisites:... 2 Software Requirements... 2 Hardware Requirements...
Table of Contents Introduction... 2 Azure ADSync Requirements/Prerequisites:... 2 Software Requirements... 2 Hardware Requirements... 2 Service Accounts for Azure AD Sync Tool... 3 On Premises Service
Extend your Exchange On Premises Organization to the Cloud
Phoenix Cloud Intelligence 2012 Extend your Exchange On Premises Organization to the Cloud Mike Pfeiffer Technical Director Interface Technical Training What is Office 365? Bringing together cloud versions
Before you begin with an Exchange 2010 hybrid deployment... 3. Sign up for Office 365 for an Exchange 2010 hybrid deployment... 10
Contents Before you begin with an Exchange 2010 hybrid deployment... 3 Sign up for Office 365 for an Exchange 2010 hybrid deployment... 10 Verify prerequisites with an Exchange 2010 hybrid deployment...
WHITEPAPER. 13 Questions You Must Ask When Integrating Office 365 With Active Directory
WHITEPAPER 13 Questions You Must Ask When Integrating Office 365 With Active Directory Many organizations have begun their push to the cloud with a handful of applications. Microsoft s Office 365 offering
Managing Office 365 Identities and Services 20346C; 5 Days, Instructor-led
Managing Office 365 Identities and Services 20346C; 5 Days, Instructor-led Course Description This is a 5-day Instructor Led Training (ILT) course that targets the needs of IT professionals who take part
Course 20346: Managing Office 365 Identities and Services
Course 20346: Managing Office 365 Identities and Services Overview About this course This is a 5-day Instructor Led Training (ILT) course that targets the needs of IT professionals who take part in evaluating,
Managing Office 365 Identities and Services
Course 20346B: Managing Office 365 Identities and Services Page 1 of 7 Managing Office 365 Identities and Services Course 20346B: 4 days; Instructor-Led Introduction This is a 4-day Instructor Led Training
Office 365 DirSync, ADFS, Single Sign On and Exchange Federation
Chapter 11 Office 365 DirSync, ADFS, Single Sign On and Exchange Federation An Office 365 site is an organizational unit complete with its own security components and e-mail domain: @onmicrosoft.com
Deployment Guide for Enterprises
Deployment Guide for Enterprises Published: June 2011 Updated: September 2011 The information contained in this document represents the current view of Microsoft Corporation on the issues discussed as
Before you begin with an Exchange 2010 hybrid deployment... 3. Sign up for Office 365 for an Exchange 2010 hybrid deployment... 10
Contents Before you begin with an Exchange 2010 hybrid deployment... 3 Sign up for Office 365 for an Exchange 2010 hybrid deployment... 10 Verify prerequisites with an Exchange 2010 hybrid deployment...
Service Desk Readiness
Service Desk Readiness Service Desk Readiness Workshop Topics Review requirements for Service Desk readiness Assess how current support processes should be adapted to support cloud services incident management
SharePoint 2013 Logical Architecture
SharePoint 2013 Logical Architecture This document is provided "as-is". Information and views expressed in this document, including URL and other Internet Web site references, may change without notice.
Managing Office 365 Identities and Services
Course 20346B: Managing Office 365 Identities and Services Course Details Course Outline Module 1: Preparing for Office 365 This module reviews the features of Office 365 and identifies recent improvements
HOTPin Integration Guide: Microsoft Office 365 with Active Directory Federated Services
HOTPin Integration Guide: Microsoft Office 365 with Active Directory Federated Services Disclaimer Disclaimer of Warranties and Limitation of Liabilities All information contained in this document is provided
Office 365 from the ground to the cloud
Office 365 from the ground to the cloud Webinar 8 Preparing for Exam 74-325 July 2014 The Series The Basics Building Your Office 365 Practice Cross-Selling and Upselling Opportunities Microsoft Azure and
Road2Master Office 365 Hybrid Deployment and Migration Part 1 - Introduction. Ashwin Venugopal www.road2master.ms
Please Note: This is made for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS. Unless otherwise noted, the example companies, organizations,
Configuration Guide BES12. Version 12.2
Configuration Guide BES12 Version 12.2 Published: 2015-07-07 SWD-20150630131852557 Contents About this guide... 8 Getting started... 9 Administrator permissions you need to configure BES12... 9 Obtaining
Configuring Single Sign-On from the VMware Identity Manager Service to Office 365
Configuring Single Sign-On from the VMware Identity Manager Service to Office 365 VMware Identity Manager JULY 2015 V1 Table of Contents Overview... 2 Passive and Active Authentication Profiles... 2 Adding
Hybrid Architecture. Office 365. On-premises Exchange org (Exchange 2007+) Provisioned via DirSync. Secure Mail flow
Hybrid Deployment Hybrid Architecture Provisioned via DirSync Exchange 2010 (HUB/CAS) Exchange 2013 CAS & MBX Secure Mail flow Exchange Federation (Free/Busy, Mail Tips, Archive, etc.) Mailbox data via
Get started with cloud hybrid search for SharePoint
Get started with cloud hybrid search for SharePoint This document supports a preliminary release of the cloud hybrid search feature for SharePoint 2013 with August 2015 PU and for SharePoint 2016 Preview,
Configuration Guide BES12. Version 12.1
Configuration Guide BES12 Version 12.1 Published: 2015-04-22 SWD-20150422113638568 Contents Introduction... 7 About this guide...7 What is BES12?...7 Key features of BES12... 8 Product documentation...
Configuration Guide. BES12 Cloud
Configuration Guide BES12 Cloud Published: 2016-04-08 SWD-20160408113328879 Contents About this guide... 6 Getting started... 7 Configuring BES12 for the first time...7 Administrator permissions you need
Navigate your checklist... 3. Before you begin with Exchange 2007... 4. Sign up for Office 365... 11
Contents Navigate your checklist... 3 Before you begin with Exchange 2007... 4 Sign up for Office 365... 11 Verify coexistence prerequisites when deploying AD FS with Exchange 2007... 11 Collect needed
Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER
Integrating VMware Horizon Workspace and VMware Horizon View TECHNICAL WHITE PAPER Table of Contents Introduction.... 3 Requirements.... 3 Horizon Workspace Components.... 3 SAML 2.0 Standard.... 3 Authentication
Windows Azure Pack Installation and Initial Configuration
Windows Azure Pack Installation and Initial Configuration Windows Server 2012 R2 Hands-on lab In this lab, you will learn how to install and configure the components of the Windows Azure Pack. To complete
Ondřej Výšek Sales Lead, Microsoft MVP. [email protected]
Ondřej Výšek Sales Lead, Microsoft MVP [email protected] Azure Active Directory Features Free edition Basic edition Premium edition Directory as a service User and group management using UI or Windows PowerShell
Test Lab Guide: Creating a Windows Azure AD and Windows Server AD Environment using Azure AD Sync
Test Lab Guide: Creating a Windows Azure AD and Windows Server AD Environment using Azure AD Sync Microsoft Corporation Published: December 2014 Author: Mark Grimes Acknowledgements Special thanks to the
Agency Pre Migration Tasks
Agency Pre Migration Tasks This document is to be provided to the agency and will be reviewed during the Migration Technical Kickoff meeting between the ICS Technical Team and the agency. Network: Required
Cloud-Accelerated Hybrid Scenarios with SharePoint and Office 365
Cloud-Accelerated Hybrid Scenarios with SharePoint and Office 365 Contents Contents 1 About this guide 3 Overview 9 Authentication and authorization 10 Getting started with identity integration 26 Getting
NYSeMail Office 365 Administration Guide for Agencies
NYSeMail Office 365 Administration Guide for Agencies Office 365 Overview... 34 What is included... 34 Software Requirements... 34 Message Limits... 34 Provisioning... 34 Archive and Retention Policy...
Resonate Central Dispatch
Resonate Central Dispatch Microsoft Exchange 2010 Resonate, Inc. Tel. + 1.408.545.5535 Fax + 1.408.545.5502 www.resonate.com Copyright 2013 Resonate, Inc. All rights reserved. Resonate Incorporated and
Configuration Guide. BlackBerry Enterprise Service 12. Version 12.0
Configuration Guide BlackBerry Enterprise Service 12 Version 12.0 Published: 2014-12-19 SWD-20141219132902639 Contents Introduction... 7 About this guide...7 What is BES12?...7 Key features of BES12...
Microsoft Dynamics CRM 2013 Service Provider Planning and Deployment Guide
Microsoft Dynamics CRM 2013 Service Provider Planning and Deployment Guide Copyright This document is provided "as-is". Information and views expressed in this document, including URL and other Internet
Configuration Guide BES12. Version 12.3
Configuration Guide BES12 Version 12.3 Published: 2016-01-19 SWD-20160119132230232 Contents About this guide... 7 Getting started... 8 Configuring BES12 for the first time...8 Configuration tasks for managing
O, P, Q I, J, K. Nuvolex, 260, 340
Index A Administration center administrator options, 265 administrator roles, 266 billing administrator, 267 configuration adding new Skype, 280 add password information, 271 add user information and E-mail
Office 365. Migrating and Managing Your. Business in the Cloud. Matthew Katzer. Don Crawford
Office 365 Migrating and Managing Your Business in the Cloud Matthew Katzer Don Crawford Contents About the Authors About the Technical Reviewers Acknowledgments Introduction xxi xxiii xxv xxvii Chapter
Dell One Identity Cloud Access Manager 8.0.1 - How to Configure Microsoft Office 365
Dell One Identity Cloud Access Manager 8.0.1 - How to Configure Microsoft Office 365 May 2015 This guide describes how to configure Microsoft Office 365 for use with Dell One Identity Cloud Access Manager
10135A: Configuring, Managing, and Troubleshooting Microsoft Exchange Server 2010
10135A: Configuring, Managing, and Troubleshooting Microsoft Exchange Server 2010 Course Number: 10135A Course Length: 5 Day Course Overview This instructor-led course will provide you with the knowledge
Simple migrations. Hybrid. IMAP migration Supports wide range of email platforms Email only (no calendar, contacts, or tasks)
Hybrid Simple migrations IMAP migration Cutover migration Staged migration 2010 hybrid 2013 hybrid IMAP migration Supports wide range of email platforms Email only (no calendar, contacts, or tasks) Cutover
VMware Identity Manager Administration
VMware Identity Manager Administration VMware Identity Manager 2.4 This document supports the version of each product listed and supports all subsequent versions until the document is replaced by a new
Quick Start Guide Migration Planner
Quick Start Guide Table of Contents...3 10 Start... 3-4 Customer Info...5 Office 365...6 Review Accounts...7 End User...8 DNS...9 Final Review...10 1 Start Customer Info Office 365 Review Accounts Settings
Exchange Server Hybrid Deployment for Exchange Online Dedicated
Dedicated and ITAR-support Plans Hybrid Deployment for Exchange Online Dedicated Applies to: Office 365 Dedicated - Legacy 2013 Platform Release Topic Last Modified: 31-Jan-2013 Topic Last Modified: 31-Jan-2013
AVG Business SSO Connecting to Active Directory
AVG Business SSO Connecting to Active Directory Contents AVG Business SSO Connecting to Active Directory... 1 Selecting an identity repository and using Active Directory... 3 Installing Business SSO cloud
Microsoft 70-331. Version: Demo 15.0
Microsoft 70-331 Core Solutions of Microsoft SharePoint Server 2013 Version: Demo 15.0 Topic 1, Scenario 1 Background You are employed as a SharePoint administrator at ABC.com. ABC.com has a single Active
How To Manage Your Online Experiences On Windows Achemosade Online (Windows) And On-Premises) With A Free Version Of Windows.Com (Windows.Com) On A Microsoft Powerbook (Windows).Com) For Free Recipe
https://login.microsoftonline.com Sign in to Windows Azure AD manage your identity data in Windows Azure Active Directory Windows Azure Windows Azure Your account is being created Windows Azure Maria
An identity management solution. TELUS AD Sync
An identity management solution TELUS AD Sync June 2013 Introduction An important historic challenge faced by small and mid-sized businesses when opting for the TELUS Business E-mail Service is the requirement
Copyright 2012 Trend Micro Incorporated. All rights reserved.
Trend Micro Incorporated reserves the right to make changes to this document and to the products described herein without notice. Before installing and using the software, please review the readme files,
OVERVIEW. DIGIPASS Authentication for Office 365
OVERVIEW DIGIPASS for Office 365 Disclaimer Disclaimer of Warranties and Limitation of Liabilities All information contained in this document is provided 'as is'; VASCO Data Security assumes no responsibility
F, G I, J, K. Line of Business Applications (LOB), 10 Lync, 107 Lync administration conferencing add-on configuration, 419 functions, 371 set up, 419
Index A Active Directory Federation services (ADFS) compliance, 591 592 Exchange Server 2010 implementation account configuration, 601 adding Exchange Management Forest, 593 adding hybrid domain for Federation,
Lesson Plans Configuring Exchange Server 2007
Lesson Plans Configuring Exchange Server 2007 (Exam 70-236) Version 2.1 Table of Contents Course Overview... 2 Section 1.1: Server-based Messaging... 4 Section 1.2: Exchange Versions... 5 Section 1.3:
Microsoft SharePoint Architectural Models
Microsoft SharePoint This topic is 1 of 5 in a series Introduction to Fundamental SharePoint This series is intended to raise awareness of the different fundamental architectural models through which SharePoint
Cloud Identity Management Tool Quick Start Guide
Cloud Identity Management Tool Quick Start Guide Software version 2.0.0 October 2013 General Information: [email protected] Online Support: [email protected] Copyright 2013 CionSystems Inc., All
Microsoft Lync Server 2010
Microsoft Lync Server 2010 Scale to a Load Balanced Enterprise Edition Pool with WebMux Walkthrough Published: March. 2012 For the most up to date version of the Scale to a Load Balanced Enterprise Edition
Quest Collaboration Services 3.7. Deployment Guide
Quest Collaboration Services 3.7 Deployment Guide 2013 Quest Software, Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide
Total Cost of Ownership Overview ADFS vs OneLogin WHITEPAPER
Total Cost of Ownership Overview vs OneLogin WHITEPAPER Are you really going to double down on machines, software and professional services to extend Active Directory (AD)? Executive Summary Are you planning
Course 20533: Implementing Microsoft Azure Infrastructure Solutions
Course 20533: Implementing Microsoft Azure Infrastructure Solutions Overview About this course This course is aimed at experienced IT Professionals who currently administer their on-premises infrastructure.
How Microsoft IT manages mobile device management
IT Insights A service of Microsoft IT Showcase How Microsoft IT manages mobile device management July 2015 Bring Your Own Device (BYOD) is no longer just a trend. It is arguably the dominant culture in
MCSE Objectives. Exam 70-236: TS:Exchange Server 2007, Configuring
MCSE Objectives Exam 70-236: TS:Exchange Server 2007, Configuring Installing and Configuring Microsoft Exchange Servers Prepare the infrastructure for Exchange installation. Prepare the servers for Exchange
Implementing Microsoft Azure Infrastructure Solutions
Course Code: M20533 Vendor: Microsoft Course Overview Duration: 5 RRP: 2,025 Implementing Microsoft Azure Infrastructure Solutions Overview This course is aimed at experienced IT Professionals who currently
This course is intended for IT professionals who are responsible for the Exchange Server messaging environment in an enterprise.
10233A: Designing and Deploying Messaging Solutions with Microsoft Exchange Server 2010 Course Number: 10233A Course Length: 5 Day Course Overview This instructor-led course provides you with the knowledge
Setting Up Resources in VMware Identity Manager
Setting Up Resources in VMware Identity Manager VMware Identity Manager 2.4 This document supports the version of each product listed and supports all subsequent versions until the document is replaced
Configuring Sponsor Authentication
CHAPTER 4 Sponsors are the people who use Cisco NAC Guest Server to create guest accounts. Sponsor authentication authenticates sponsor users to the Sponsor interface of the Guest Server. There are five
MOC 5047B: Intro to Installing & Managing Microsoft Exchange Server 2007 SP1
MOC 5047B: Intro to Installing & Managing Microsoft Exchange Server 2007 SP1 Course Number: 5047B Course Length: 3 Days Certification Exam This course will help you prepare for the following Microsoft
Speeding Office 365 Implementation Using Identity-as-a-Service
August 2015 www.sarrelgroup.com [email protected] Speeding Office 365 Implementation Using Identity-as-a-Service White paper August 2015 This white paper is sponsored by Centrify. August 2015 www.sarrelgroup.com
Special thanks to the following people for reviewing and providing invaluable feedback for this document: Joe Davies, Bill Mathers, Andreas Kjellman
Test Lab Guide: Creating a Microsoft Azure Active Directory and Windows Server Active Directory Environment using Microsoft Azure Active Directory Sync Services Microsoft Corporation Published: December
70-662: Deploying Microsoft Exchange Server 2010
70-662: Deploying Microsoft Exchange Server 2010 Course Introduction Course Introduction Chapter 01 - Active Directory and Supporting Infrastructure Active Directory and Supporting Infrastructure Network
Exchange Deployment Options: On-premises, cloud, or hybrid? Jeff Mealiffe Principal Program Manager Microsoft
Exchange Deployment Options: On-premises, cloud, or hybrid? Jeff Mealiffe Principal Program Manager Microsoft Agenda Overview of the options & decision points Keep it all to myself Outsource it all Outsource
5053A: Designing a Messaging Infrastructure Using Microsoft Exchange Server 2007
5053A: Designing a Messaging Infrastructure Using Microsoft Exchange Server 2007 Course Number: 5053A Course Length: 3 Days Course Overview This three-day instructor-led course provides students with the
HOTPin Integration Guide: Salesforce SSO with Active Directory Federated Services
1 HOTPin Integration Guide: Salesforce SSO with Active Directory Federated Services Disclaimer Disclaimer of Warranties and Limitation of Liabilities All information contained in this document is provided
Setup Guide: Server-side synchronization for CRM Online and Exchange Server
Setup Guide: Server-side synchronization for CRM Online and Exchange Server Version 8.0 Microsoft Dynamics CRM 2016 Authors: Elad Ben Yosef, Sumanta Batabyal This document is provided "as-is". Information
Office 365. Service Overview with a focus on Identity Federation and Directory Synchronization. Jono Luk, Program Manager jluk@microsoft.
Office 365 Service Overview with a focus on Identity Federation and Directory Synchronization Jono Luk, Program Manager [email protected] Presented on July 6, 2011 at Seattle Windows Networking User Group
Active Directory Synchronization Tool Architecture and Design
Active Directory Synchronization Tool Architecture and Design Revised on: March 31, 2015 Version: 1.01 Hosting Controller www.hostingcontroller.com Contents Proprietary Notice... 1 1. Introduction... 2
WINDOWS SERVER SMALL BUSINESS SOLUTIONS. Name: Marko Drev
WINDOWS SERVER SMALL BUSINESS SOLUTIONS Name: Marko Drev SMB Windows Server Family SOLUTION SERVERS TRADITIONAL SERVERS Complete server platform, integrated and optimized Customizable Server platform for
SHAREPOINT HYBRID AND IMPLICATIONS OF 2016
SHAREPOINT HYBRID AND IMPLICATIONS OF 2016 Dan Charlton Senior Consultant MCSE, MCSA, MCP COMPANY OVERVIEW TOTAL SOLUTIONS OVERVIEW SharePoint Consulting & Development Organization Design Development Administration
Google Apps Deployment Guide
CENTRIFY DEPLOYMENT GUIDE Google Apps Deployment Guide Abstract Centrify provides mobile device management and single sign-on services that you can trust and count on as a critical component of your corporate
AV-006: Installing, Administering and Configuring Windows Server 2012
AV-006: Installing, Administering and Configuring Windows Server 2012 Career Details Duration 105 hours Prerequisites This course requires that student meet the following prerequisites, including that
Introducing. Markus Erlacher Technical Solution Professional Microsoft Switzerland
Introducing Markus Erlacher Technical Solution Professional Microsoft Switzerland Overarching Release Principles Strong emphasis on hardware, driver and application compatibility Goal to support Windows
"Charting the Course... Implementing Citrix NetScaler 11 for App and Desktop Solutions CNS-207 Course Summary
Course Summary Description The objective of this course is to provide the foundational concepts and teach the skills necessary to implement, configure, secure and monitor a Citrix NetScaler system with
Digital certificates and SSL
Digital certificates and SSL 20 out of 33 rated this helpful Applies to: Exchange Server 2013 Topic Last Modified: 2013-08-26 Secure Sockets Layer (SSL) is a method for securing communications between
Planning your Microsoft Application Strategy in a Cloud Crazy World. Steve Soper Senior Managing Partner
Planning your Microsoft Application Strategy in a Cloud Crazy World Steve Soper Senior Managing Partner Who is AdaptivEdge Founded in June 2013 Partnered with Nth Generation for 2+ years and delivered
Hosting topology SMS PASSCODE 2015
Hosting topology SMS PASSCODE 2015 Hosting Topology In a hosting environment, you have a backend and a several front end (clients). In the example below, there is a backend at the right side. At the left
5/20/2013. The primary design goal was for simplicity of scale, hardware utilization, and failure isolation. Microsoft Exchange Team
Additions and Subtractions The primary design goal was for simplicity of scale, hardware utilization, and failure isolation. Microsoft Exchange Team Exchange Version Exchange Server 2003 and earlier versions
Dell One Identity Cloud Access Manager 7.0.2. Installation Guide
Dell One Identity Cloud Access Manager 7.0.2 2014 Dell Inc. ALL RIGHTS RESERVED. This guide contains proprietary information protected by copyright. The software described in this guide is furnished under
MICROSOFT EXCHANGE, OFFERED BY INTERCALL
MICROSOFT EXCHANGE, OFFERED BY INTERCALL Comparison Sheet The table below compares in-product or service feature availability between Microsoft 2013 on-premises and Online within. Planning and Deployment
