Collaborate outside the firewall with Office 365 Groups Microsoft Ignite 2016 4/29/2018 12:40 AM BRK3250 Collaborate outside the firewall with Office 365 Groups Shashi Singaravel Principal Program Manager shashis@microsoft.com #Office365Groups © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Agenda Overview Admin functionalities & controls Reporting & Auditing How and what can I share externally with Office 365 groups? Admin functionalities & controls As a tenant admin how can I manage guests and control access to groups in my organization? Reporting & Auditing How can I identify the guests (external users) in my organization and in groups?
Overview Microsoft Ignite 2016 4/29/2018 12:40 AM © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Customers Suppliers Contractors Microsoft Ignite 2016 4/29/2018 12:40 AM Customers Suppliers Contractors © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Demo End user experiences Microsoft Ignite 2016 4/29/2018 12:40 AM © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Guests Experiences Guests gets access to group content on the web from their email account. … more to come.
Guest addition experiences Available on Outlook on the Web Owners of a group adds guests Awareness of guest participation in the group Coming soon on Outlook Desktop, and Mobile App Globe icon next to group and group description indicates group has guests as members. Guest are represented with a globe icon next to the display name (email in the absence of display name) and has a title “GUEST” Guest tab for a filtered view of guests in this group.
Architecture
Guest user in Office 365 Definition Single Identity External user with any email account (work, school or personal accounts) whose credentials aren’t managed by IT of the organization. Single Identity Guest identity is mastered in Azure AD and synced to Exchange Online and SharePoint Online. Access to Office 365 resources Restricted access to resources as defined by policy of organization. Guests are restricted from group management operations, and becoming an owner. CONTOSO fabrizwalter@gmail.com mgarcia@outlook.com sales@contoso.com FABRIKAM sarad@contoso.com robinc@fabrikam.com
Guest addition to Office 365 Office 365 Groups Owners of a group and tenant admin adds guests to group as members File and folder sharing through SharePoint site Guest is created in SharePoint first, and upon guest accessing resources, the guest user is created in Azure AD, and synched to other workload – Exchange Online. Azure B2B service Users from partner companies/federated tenant are added as guests to a target tenant to access SaaS applications, Office 365.
Welcome email & group messages Guest addition flow robinc@fabrikam.com added to sales@contoso.com CONTOSO (target tenant) FABRIKAM (guest’s tenant) Welcome email & group messages Robin from Fabrikam is added to group in Contoso organization. Robin is represented in the Contoso (target tenant) as guest (shadow representation). Robin gets welcome email, starts getting group messages from the group (including calendar invites). Add member sales@contoso.com Add Member robinc@fabrikam.com sarad@contoso.com Guest Mail User
Guest access flow Robin@fabrikam.com access group files/notebook from the welcome email or via links on the footer CONTOSO (target tenant) FABRIKAM (guest’s tenant) View files Sign In/AuthN Robin now tries to access the group files from Contoso organization. Robin authenticates himself with Fabrikam (home tenant), and is now authorized with Contoso (target tenant) to access the group files. The guest object in Contoso is now linked to Fabrikam organization. sales@contoso.com robinc@fabrikam.com sarad@contoso.com
Guest addition flow mgarcia@outlook.com or bob@gmail.com added to sales@contoso.com CONTOSO (target tenant) sales@contoso.com sarad@contoso.com CONSUMER EMAIL (home tenant) mgarcia@outlook.com Add member fabrizwalter@gmail.com View files
Guest AuthN flow to access group resources User signs in with his Fabrikam (existing O365) creds and redeems his invitation to Contoso robinc@fabrikam.com Office 365 account mgarcia@outlook.com (Has a MSA) sales@contoso.com User signs in with his Microsoft account and redeems his invitation to Contoso fabrizwalter@gmail.com (Has a MSA) User signs up for a Microsoft account and redeems his invitation to Contoso shaun@gmail.com (Doesn’t have a MSA)
Admin functionalities & controls
Admin Controls to manage guests Guest addition to organization Allow invitation to guests users in the organization Guest addition to groups Allow adding of guests to any group within the organization. Allow adding of guests to a specific group in the organization via PowerShell Guest access to group resources Allow guests to access to any Office 365 group resources
Admin Controls via Azure AD PowerShell Guest addition and access to Office 365 groups – org level Allow adding of guests to any group within the organization – “AllowToAddGuests” Allow guests to access to any Office 365 group resources – “AllowGuestsToAccessGroups” Guest addition to specific Office 365 group Allow adding of guests to a specific group in the organization – “AllowToAddGuests” Usage guidelines to guests Link to the guidance document for external users from the organization – “GuestUsageGuidelinesUrl”
Demo Administration Reporting & Auditing Microsoft Ignite 2016 4/29/2018 12:40 AM Demo Administration Reporting & Auditing © 2016 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Reporting and Auditing
Reporting Office 365 portal PowerShell cmdlets Number of guests in groups Guests users in the organization PowerShell cmdlets Get-Msol* cmdlets Get-UnifiedGroupLinks cmdlet
Auditing Azure AD portal Office 365 audit log report Invite external user Redeem external user Office 365 audit log report Add member to group
Frequently Asked Questions How does guest access impact other sharing features in Office 365? Are guests synced to on-premises directory in hybrid environments? Can mail contacts be added as guests in a group? Can guest access IRM messages?
See you at the Office 365 Groups booth everyday! Microsoft Ignite 2015 4/29/2018 12:40 AM Groups Sessions Session Code Time Room Collaborate with Office 365 BRK2288 Tue. @9:00 B405-407 Discover Office 365 Groups - overview, what's new and roadmap BRK2033 Tue. @10:45 C112 Meet Planner - the new Microsoft Office 365 work management application BRK1006 B312-314 Help your users collaborate better with Office 365 Groups THR3010 Tue. @11:05 Theater level 2 Using Office 365 Groups at schools and universities BRK2052 Tue. @12:45 C114 Manage Office 365 Groups BRK3019 Tue. @14:15 Georgia Ballroom Field Guide to Office 365 Groups: Planning, Implementation, and Management BRK3001 Wed. @10:45 B303-304 Collaborate outside of the firewall with Office 365 Groups BRK3250 Wed. @12:45 B211-212 Migrate DL to Microsoft Office 365 Groups THR3001 Wed. @12:40 Theater level 4 Migrate DL to Office 365 Groups Thu. @10:20 Theater 4 Work smarter with Yammer and Office 365 Groups BRK2019 Thu. @12:30 C113 Collaborate outside the firewall with Office 365 BRK3003 Thu. @13:35 Theater 3 Learn about Office 365 Groups and how to use them BRK2277 Fri. @9:15 B203 Ask us anything about Office 365 Groups BRK3227 Fri. @11:00 See you at the Office 365 Groups booth everyday! © 2015 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Next Steps Extend collaboration outside of your directory Use Guest access in Groups Give us feedback on our Technical Community 1 2 3 Guest access in Office 365 Groups Guest access in Office 365 groups – Admin Help aka.ms/o365g
Deploy, ramp-up on new services and onboard new users with Microsoft FastTrack: http://fasttrack.microsoft.com/
Join the Microsoft Tech Community to collaborate, share, and learn from the experts: http://techcommunity.microsoft.com
Please evaluate this session 4/29/2018 12:40 AM Please evaluate this session Your feedback is important to us! From your PC or Tablet visit MyIgnite at http://myignite.microsoft.com From your phone download and use the Ignite Mobile App by scanning the QR code above or visiting https://aka.ms/ignite.mobileapp © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
4/29/2018 12:40 AM © 2014 Microsoft Corporation. All rights reserved. MICROSOFT MAKES NO WARRANTIES, EXPRESS, IMPLIED OR STATUTORY, AS TO THE INFORMATION IN THIS PRESENTATION.
Office 365 Groups innovations Office 365 Connectors Microsoft Planner Professional learning community groups Office 365 Groups + team sites integration Guest user access (external users) Calendaring improvements Notifications improvements Mobile improvements Outlook Groups iPad app Experiences File quota management Hybrid guidance & improvements Privacy type conversion Multi-domain support Creation policies in AAD Mobile application management Data classification and extensible policies Usage guidelines Exchange Admin Center UI for upgrading DL to Groups Administration Shipped during past year Yammer Planner: multi-assign, external user, mobile Send As in Outlook on the web Outlook for Mac support Inbox tiered notifications Single Groups files view Skype Meet Now Continuously improving UI design Naming policies in AAD Hidden membership General usage reporting Preservation and deletion policies Soft-delete and restore Upgrading nested, dynamic and hybrid DLs to Groups Improved hybrid experiences Upcoming investments Key Resources Documentation: aka.ms/O365g | Questions: aka.ms/O365ng | FastTrack: fasttrack.microsoft.com/office Roadmap: fasttrack.office.com/roadmap | Sway: aka.ms/Office365Groups