 What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Demo.

Slides:



Advertisements
Similar presentations
Office 365 Identity June 2013 Microsoft Office365 4/2/2017
Advertisements

Office 365 Deployment FastTrack Overview
 This session details common scenarios for deploying Office 365 services. Office 365 provides a breadth of capability, but often there is a key scenario.
Azure AD & Office Logon with Username / Password 2. MFA challenge 3. Reply to MFA challenge -1-way or 2-way SMS -Phone call -Mobile Application.
IMAP migration Cutover migration Staged migration 2010 hybrid2013 hybrid Exchange 5.5 Exchange 2000 Exchange 2003 Exchange 2007 Exchange 2010 Exchange.
Private Cloud (on & off premises) Hybrid CloudPublic Cloud SaaS PaaS IaaS Microsoft’s Online service portfolio Office 365 Microsoft‘s communication.
Microsoft ® Exchange Online Migration and Coexistence Name Title Microsoft Corporation.
RequirementsDeployment Options 2 3 Dirsync Overview 1 Understanding Synchronization 4.
Identity management integration options for Office 365
Microsoft Ignite /16/2017 4:55 PM
Sessions about to start – Get your rig on!. Notes from the field – Implement Hybrid Search and OneDrive for Business Chris Zhong - Microsoft Aaron Dinnage.
Business Productivity Online Suite Enterprise class software delivered via subscription services hosted by Microsoft and sold with partners.
Active Directory Integration with Microsoft Office 365
Active Directory Integration with Microsoft Office 365 Ross Adams & Jono Luk Program Managers Microsoft Corporation OSP321.
Fast and fluid experience with touch, pen, mouse & keyboard Immersive touch-optimized Windows 8 apps Support for Windows phone, iOS & Android phones Office.
2 Part 1 What should I know before I jump into the deep water? Office Subscription plans Office 365 – Trail account Office 365 – what should I know.
Demi Albuz SENIOR PRODUCT MARKETING MANAGER Samim Erdogan PRINCIPAL ENGINEERING MANAGER Thomas Willingham TECHNICAL PRODUCT MANAGER.
SIM 320. Contoso customer premises AD MS Online Directory Sync Identity Services Provisioning platform Provisioning platform Lync Online Lync Online.
Scenario covered in this presentation Separate credential from on- premises credential Authentication occurs via cloud directory service Does not.
OUC204. Recently Announced… Identity Integration Options 2 3 Identity Management Overview 1.
Timothy Heeney| Microsoft Corporation. Discuss the purpose of Identity Federation Explain how to implement Identity Federation Explain how Identity Federation.
5 | Microsoft Confidential 6 | Microsoft Confidential.
Single Sign-On with Microsoft Azure
Objectives Introduce Lync Online Share some key metrics Educate about process and resources for XL tenants Discuss key success factors Listen to your.
Identity on Force.com & Benefits of SSO Nick Simha.
…. PrePlanPrepareMigratePost Pre- Deployment PlanPrepareMigrate Post- Deployment First Mailbox.
Virtual techdays INDIA │ august 2010 virtual techdays INDIA │ august 2010 Moving/Co-existing your messaging platform to the cloud with Exchange.
Microsoft ® Official Course Module 13 Implementing Windows Azure Active Directory.
PCIT313. Today’s challenges Deliver applications to mobile platforms (BYOD) Respond to dynamic business requirements for IT: Seasonal/temporary workers.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Paul Andrew. Recently Announced… Identity Integration Options 2 3 Identity Management Overview 1.
Alessandro Cardoso Microsoft MVP | Readify National Manager |
Lync Server Private cloud / dedicated Lync Server Single domain & directory Users split – server / online Lync Hybrid Office 365 Lync Online Hosted.
DMI202 Experience Value Early New Cloud Experience Real World Benefits Broad Production Use Full Feature Value Meet your needs Deploy Enhance Pilot.
Office 365: Identity and Access Solutions Suresh Menon Technology Specialist – Office 365 Microsoft Corporation India.
Version 2.0 for Office 365. Day 1 Administering Office 365 Day 2 Administering Office 365 Office 365 Overview & InfrastructureAdministering Lync Online.
Office 365 Directory Synchronization Update: Deploying Password Sync.
Access and Information Protection Product Overview Andrew McMurray Technical Evangelist – Windows
Bronze Sky customer premises AD MS Online Directory Sync Provisioning platform Provisioning platform Lync Online Lync Online SharePoint Online SharePoint.
Get identities to the cloud Mix on-premises and cloud identity for improved PC, mobile, and web productivity Cloud identities help you run your business.
Access resources in a federation partner organization.
Implementing Microsoft Exchange Online with Microsoft Office 365
Configuration Manager and InTune Gemeinsam oder einsam?
DNS DNS changes required to validate domains in Office 365 UPN – User Principal Name Every user must have a UPN UPN suffixes must match a validated.
#SPSMX Hybrid Environments SharePoint On-premises & SharePoint Online Luis Du Solier SharePoint Premier Field Engineer Microsoft.
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
Managing Office 365 Identities and Requirements Question Answer
Managing Office 365 Identities and Requirements.
 Step 2 Deployment Overview  What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Understanding.
Deployment on your terms Hybrid Exchange deployment on your terms On-premises.
ADFS - Does it Still have a Place? Fitting into the EMS puzzle Frank C. Drewes III 2016 Redmond Summit | Identity.
Private KEEP OFF! Private KEEP OFF! Open! What is a cloud? Cloud computing is a model for enabling convenient, on-demand network access to a shared.
Protect your data Enable your users Desktop Virtualization Information protection Mobile device & application management Identity and Access Management.
Recording Brief EMS Partner Bootcamp Variables Values Module Title
Office 365 Deployment FastTrack June 2013
Office 365 Fundamentals March 2014.
Directory Synchronization in Office 365
Microsoft Online Services Partner Deployment Training for Office 365
Microsoft Online Services Partner Deployment Training for Office 365
Office 365 Fundamentals March 2014.
Migrating to Office 365 from Google mail and exchange
06 | Planning Exchange Online and Configuring DNS Records
Encryption in Office 365 Shobhit Sahay Technical Product Manager
SharePoint Online Hybrid – Configure Outbound Search
M7: New Features for Office 365 Identity Management
Office 365 Identity Management
OSP312 Office 365 Deployment Ben Walters Jeff Medford Mark Rhodes
Office 365 Identity Management
10 | Implementing Directory Synchronization
Presentation transcript:

 What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Demo

Pilot completeDeploy CompleteAdopt new features Deploy Enhance Pilot

Sign-on Integrated identity management Sign-on with the same user and password as on premises Mail Integrated mail flow and migration Global address list Full mail content migration – mail, calendar, contacts Collaboration Sharing and working with others Lync business partner federation Site governance and provisioning support Setup of Apps for Office corporate app catalog Clients IT managed client productivity Office 365 ProPlus deployed to user desktop via IT process Mobile Managed mobile connectivity Send and receive mail from mobile device as on-prem Administration Control & monitor Data loss prevention configuration (limited) Exchange Online Protection mail protection configuration (limited) Setup in days Adds on-premises integration Pilot user and info is sustained IT driven migration Mail migration that best fits environment Deploy Experience – what’s added

Identity What’s Required Directory Sync server/s AD meets service requirements for hygiene Same password on-prem and in cloud via password sync Network What you need to connect Network access to service from client end points Network bandwidth availability Access to maintain DNS entries for share domains Clients Required to connect and deploy Web client – minimum browser Office 365 Pro Plus – clients running Windows 7 + Unique requirements per mail platform Dedicated customer IT team Change management readiness Mail Required to setup and migrate Admin access Deploy – what’s required

Cloud Identity Single identity in the cloud Directory & Password Synchronization Single identity without federation Federated Identity Single federated identity and credentials Deploy Identity Scenario Deploy Enhance Pilot

On-premises ExchangeActive Directory Office 365 Windows Azure Active Directory Directory Synchronization Provisioning Web Service Logon Enabled User Mail-Enabled (not mailbox-enabled) ProxyAddresses: SMTP: smtp: smtp: TargetAddress: SMTP: Logon Enabled User Mail-Enabled (not mailbox-enabled) ProxyAddresses: SMTP: smtp: smtp: TargetAddress: SMTP: Exchange Online Authentication Platform SharePoint Online Lync Online User Object Mailbox-Enabled ProxyAddresses: SMTP: User Object Mailbox-Enabled ProxyAddresses: SMTP: Sync Cycle Stage 3: Export Users, Groups, and Contacts to Office 365 Sync Cycle Stage 4: Export “Write Back” attributes Sync Cycle Stage 2: Import Users, Groups, and Contacts from Office 365

 Introduced with DirSync in June 2013  Benefits of using Password Sync as an alternative to Federated Authentication  “Single set of credentials” to access both on-premises and online resources  Managed in the customer’s Active Directory and is synchronized with Office 365 (username + password)  Fully integrated in the DirSync appliance  No requirement for Active Directory Federation Services.  Keeps the deployment simple and eliminates IT costs associated with AD/FS

 Does not require nor access the plain text password  No requirement for AD reversible encrypted format  AD user password hash is hashed again using a non-reversible encryption function and digest is synchronized into Azure AD  The digest in Azure AD cannot be used to access resources in the customer’s on-premises environment

 One-way synchronization from on-premises to the cloud  Password Complexity Policy implemented in the on-premises AD is the master policy  Password Expiration Policy on the Azure AD is set to “Never Expire”  Password expiration and sync to Azure AD is driven by on-premises events

On-premises Message Filtering MX Record: contoso.com User Object Mailbox-Enabled ProxyAddresses: SMTP: User Object Mailbox-Enabled ProxyAddresses: SMTP: ExchangeActive Directory

On-premises Message Filtering MX Record: contoso.com ExchangeActive Directory Office 365 MX Record: contoso.onmicrosoft.com contoso.mail.onmicrosoft.com Exchange Online Protection Exchange Online Online Directory DirSync DirSync Web Service Logon Enabled User Mailbox-Enabled ProxyAddresses: SMTP: smtp: smtp: Logon Enabled User Mailbox-Enabled ProxyAddresses: SMTP: smtp: smtp: User Object Mail-Enabled (not mailbox-enabled) ProxyAddresses: SMTP: TargetAddresses: SMTP: User Object Mail-Enabled (not mailbox-enabled) ProxyAddresses: SMTP: TargetAddresses: SMTP:

On-premises Message Filtering MX Record: contoso.com ExchangeActive Directory Office 365 MX Record: contoso.onmicrosoft.com contoso.mail.onmicrosoft.com Exchange Online Protection Exchange Online Online Directory DirSync DirSync Web Service Logon Enabled User Mail-Enabled (not mailbox-enabled) ProxyAddresses: SMTP: smtp: smtp: TargetAddresses: SMTP: Logon Enabled User Mail-Enabled (not mailbox-enabled) ProxyAddresses: SMTP: smtp: smtp: TargetAddresses: SMTP: User Object Mailbox-Enabled ProxyAddresses: SMTP: User Object Mailbox-Enabled ProxyAddresses: SMTP:

“It just seemed like every piece of the path that needed to be right at one point broke in the pilot, and nobody can explain why it all happened. “ “The very fundamental assumption I made is that O365 is ]the same if it's on-prem as in the Cloud. Functionality-wise, everything, as on prem.“ “Microsoft would get escalations internally, they’re like, we’ll just throw more resources at it.” “We weren’t proficient/technical enough to know the right questions to ask Microsoft” Satisfied Dissatisfied