O365 & AD Integration January 2017.

Slides:



Advertisements
Similar presentations
Agenda AD to Windows Azure AD Sync Options Federation Architecture
Advertisements

Core identity scenarios Federation and synchronization 2 3 Identity management overview 1 Additional features 4.
 This session details common scenarios for deploying Office 365 services. Office 365 provides a breadth of capability, but often there is a key scenario.
Configuring SharePoint 2013 and Office 365 Hybrid – Part 1
Federated sign-in WS-Federation WS-Trust SAML 2.0 Metadata Shibboleth Graph API Synchronize accounts Authentication.
Administering Active Directory
Hands-On Microsoft Windows Server 2003 Administration Chapter 3 Administering Active Directory.
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
Office 365 Administration Ron Schindler See full Office 365 Admin course on Ron Schindler See.
Chapter-4 Windows 2000 Professional Win2K Professional provides a very usable interface and was designed for use in the desktop PC. Microsoft server system.
OUC204. Recently Announced… Identity Integration Options 2 3 Identity Management Overview 1.
Timothy Heeney| Microsoft Corporation. Discuss the purpose of Identity Federation Explain how to implement Identity Federation Explain how Identity Federation.
Verify Hardware Requirements Install Windows Server 2008 R2 Configure Active Directory Install SQL Server 2008 Install SharePoint Server 2010 Configure.
Deploying Chromebooks RICK NICHOLAS A.
Julien “Superman” Stroheker and Nicolas “Batman” Georgeault Negotium
11 MANAGING AND DISTRIBUTING SOFTWARE BY USING GROUP POLICY Chapter 5.
…. PrePlanPrepareMigratePost Pre- Deployment PlanPrepareMigrate Post- Deployment First Mailbox.
Riva Managed Identity Integration for Active Directory and Novell ® GroupWise ® Aldo Zanoni CEO, Managing Director Omni Technology Solutions
Microsoft ® Official Course Module 13 Implementing Windows Azure Active Directory.
Empowering people-centric IT Unified device management Access and information protection Desktop Virtualization Hybrid Identity.
Paul Andrew. Recently Announced… Identity Integration Options 2 3 Identity Management Overview 1.
Module 2 Creating Active Directory ® Domain Services User and Computer Objects.
MCSE Guide to Microsoft Exchange Server 2003 Administration Chapter Five Managing Addresses.
Version 2.0 for Office 365. Day 1 Administering Office 365 Day 2 Administering Office 365 Office 365 Overview & InfrastructureAdministering Lync Online.
Get identities to the cloud Mix on-premises and cloud identity for improved PC, mobile, and web productivity Cloud identities help you run your business.
Module 9 User Profiles and Social Networking. Module Overview Configuring User Profiles Implementing SharePoint 2010 Social Networking Features.
GOOMAZURE Mannheim, 6 th October 2015 Stamitz Saal, 2:30 – 3:15 pm.
Microsoft ® Official Course Module 6 Managing Software Distribution and Deployment by Using Packages and Programs.
Identities and Azure AD Premium
ITS Lunch & Learn November 13, What is Office 365? Office 365 is Microsoft’s software as a service offering. It includes hosted and calendaring.
BE-com.eu Brussel, 26 april 2016 EXCHANGE 2010 HYBRID (IN THE EXCHANGE 2016 WORLD)
Agenda  Microsoft Directory Synchronization Tool  Active Directory Federation Server  ADFS Proxy  Hybrid Features – LAB.
Office 365 is cloud- based productivity, hosted by Microsoft. Business-class Gain large, 50GB mailboxes that can send messages up to 25MB in size,
Managing Office 365 Identities and Requirements Question Answer
Managing Office 365 Identities and Requirements.
 Step 2 Deployment Overview  What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Understanding.
 What is DirSync?  Purpose – What does it do?  Understanding Synchronization  Understanding Coexistence  Demo.
Productivity Architect Meet Chris Bortlik Author, Blogger, Speaker.
MCSA Windows Server 2012 Pass Upgrading Your Skills to MCSA Windows Server 2012 Exam By The Help Of Exams4Sure Get Complete File From
Office 365 Migration Ridgewater College. What is Office 365? A collection of Microsoft applications and services located in the “cloud”. Accessible anywhere.
Office 365 Upsell Paths.
Planning, Implementing and Supporting Office 365
Microsoft Azure Active Directory Identity Solutions
IT06 – HAVE YOUR OWN DYNAMICS NAV TEST ENVIRONMENT IN 90 MINUTES
File Management in the Cloud
Get to know SQL Manager SQL Server administration done right 
Microsoft - Managing Office 365 Identities and Requirements
Using Microsoft Identity Manger with SharePoint 2016 to fill the User Profile Sync Gap Max Fritz Senior Systems Consultant Now Micro.
Directory Synchronization in Office 365
Exam in just 24 hours!!! Pass your exam in first attempt by the help of our latest braindumps
VIDIZMO Deployment Options
Design and Implement Cloud Data Platform Solutions
IT Connects: Lync and Box Staff Association Council
Deploying Office 365 ProPlus
PSJA AUTOMATION WORKFLOW AND LESSONS LEARNED
Dev Test on Windows Azure Solution in a Box
Local AD, Azure AD, & Google Suite User Management
File Manager for Microsoft Office 365, SharePoint, and OneDrive: Extensible Via Custom Connectors in Enterprise Deployments, Ideal for End Users OFFICE.
Hybrid Search Planning Implementation.
Hybrid Search Technical Guidance.
PSC Group, LLc Office 365/SharePoint Online Migration traps and tricks
05 | AD to Windows Azure AD IT Professionals
Migrating to Office 365 from Google mail and exchange
SharePoint Online Hybrid – Configure Outbound Search
Matthew Levy Azure AD B2B vs B2C Matthew Levy
M6: Advanced Identity Management topics for Office 365
Administrator’s Manual
10 | Implementing Directory Synchronization
SysKit Security Manager
Presentation transcript:

O365 & AD Integration January 2017

Benefits of Office 365 for Education Install Office on up to 5 PC’s/Macs + 5 tablets + 5 smartphones per user Access to Office Online OneDrive for Business 1 TB online personal storage

Benefits of Office 365 for Education Email Sway (Report and presentation creator) SharePoint Sites Yammer (Social Networking) Skype for Business (Web conferencing, IM, Video, presence) 24\7 phone support from Microsoft

Sampl Slide 3

Office 365 Benefits Colleges even if they do not use Cloud Exchange. Colleges using Gmail can now offer Microsoft Office Applications to all Faculty, Staff and Students. Cloud based and full Applications are available at no additional charge when the college maintains a Campus Agreement licensing 100% of the staff for office. * Office 365 can be deployed fully self-service without AD Integration.

A few answers and a lot of networking! Pros and Cons of Office 365 Questions or Comments A few answers and a lot of networking!

Benefits of Active Directory Integration AD Connect Access On Premise Applications and Cloud Services with Single Identity Single Tool for deployment

Synchronization of Specified Organizational Units from your on-premise Active Directory to the cloud. Allows synchronization of Specified AD Attributes Allows timed synchronizations, every 30 minutes is the default.

User Information and changes occur in only one location User Information and changes occur in only one location. On-Premise Active Directory Usernames Passwords Addresses Groups Mail list Attributes

User Passwords can be set once for an Active Directory User and the change automatically occurs at Office 365. Office 365 uses local AD password policy. Passwords synchronize immediately Any AD Password Reset Server that resets the AD password can be used as the tool to reset AD integrated Office 365 Users.

Ease of Implementation AD Connect runs on Windows 2008R2, 2012R2 or 2016 Dedicated Server on same vlan as at least one Domain Controller Be sure to physically and cyberly SECURE access to this server. It contains your AD Database. (Treat it like a domain controller.)

AD Connect server can be Virtual (recommended to be virtual) Provision as follows: 100GB Disk (Thin Provisioned) 16GB RAM 2-4 CPU (Over 10,000 users, Less Ram and CPU will slow sync, Over 50,000 users should have 32GB+ Ram)

Installation and Configuration of AD Connect Discussion

How Azure AD works Azure AD is made up of 3 components https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect Azure AD is made up of 3 components The Synchronization Module Active Directory Federation Services (Optional) The Monitoring component

Azure Powershell vs Windows Powershell Windows Powershell Windows PowerShell is a scripting platform. You can run various commands using it. You can also write scripts which are a set of commands. Those scripts are called Cmdlets. You can find a lot of Cmdlets written by others. For example, the Windows Azure team has written some Cmdlets, which they call Windows Azure PowerShell. So Windows Azure PowerShell is a set of scripts that rely on Windows PowerShell platform to run. But it also relies on the Windows Azure SDK, just like you can write your own PowerShell script that uses a third party SDK, thus the script requires both Windows PowerShell and that third party SDK (aka a Software Development Kit).

Windows Powershell Is installed as a part of Windows Server 2008R2 and newer Windows Server OS Location: C:\WINDOWS\system32\WindowsPowerShell\v1.0 Manages all Active Directory Attributes Create, Modify, Delete (some can only be modified via powershell) Can Manage other Applications with imported modules

Windows Powershell can and should be upgraded to the latest: Windows Management Framework (4.0 at least) Should almost always be: Run as Administrator Can be automated with Task Scheduler Windows Powershell can manage most of the AD Connect components without installing Azure Powershell (AD Connect installation adds necessary SDK’s)

Windows Azure Active Directory Powershell Best to install Windows AZURE Active Directory Powershell on AD Connect Server Also install Windows AZURE Active Directory Powershell on at least one Domain Controller (This server will run scheduled task involving both AD and O365…ie licensing O365 users by OU.)

Azure powershell is a subset of scripts pre-populated specifically for managing Office 365 Set number of Deletions in a 24 hour period Manual Synchronizations Single Sign on and Federation of Tenant Many other management options Change User Principal Names Verify user information Proxy addresses Applied Licenses Apply Address Book separations Many more available options

Verification and Modification of AD or O365 object information Export information via .csv or email Examples of items for verification, modification and export Proxy addresses Licenses Address Book attributes Group Memberships User Counts per OU or Domain

Questions A few answers A lot of comments Powershell scripting is one item that could be discussed for weeks…months…. You can accomplish almost anything with a script 

AD and Office 365 Integration should be an extension of your Colleague Webadvisor and AD LDAP integration Colleague Webadvisor User creation drives creation of Active Directory Accounts. Accounts are placed in Active Directory OU’s based on Colleague Users HR.STATUS (Other options are available) SE or NULL becomes a Student, Everything else is an employee

Faculty\Staff go into a single OU: newemp Once we distinguish between Students and Employees we can further divide into OU’s Faculty\Staff go into a single OU: newemp (users easily located to assign other AD rights and permissions then moved to proper OU) Students A B C etc (users are easily located to assign other AD rights and permissions then moved to proper OU) (based on first or last name, This will normally make the OU have less than 5000 objects, thus working around some LDAP limitations)

Once we have users in an OU we can proceed to manage things such as: Type of O365 license Members of Groups can be based on OU Students_A, Students_B Eliminates the >5000 user send issue associated with most mail servers UPN (Universal Principal Name) userid@domain.edu userid@students.domain.edu ETC…!!!

A lot of NETWORKING (find some peer partners) Lots of Discussion Maybe a few answers A lot of NETWORKING (find some peer partners) A great deal of food for thought! I like food….let’s have ice cream (my favorite…Heavenly Hash)

All cartoons thankfully copied from internet! O365 and AD Integration Presentation to lead discussion Compiled by: Sherry Johnson EIS Data Systems, Inc. January 2017 All cartoons thankfully copied from internet! Thank you Google!