10 | Implementing Directory Synchronization Anthony Steven | Principal Technologist, Content Master Martin Coetzer | Portfolio Architect, Microsoft
Module Overview Manage Active Directory Users and Groups with DirSync In Place
Prepare On-premises Active Directory for DirSync Enabling Active Directory Synchronization
DirSync Overview DirSync enables coexistence 10: Implementing Directory Synchronization DirSync enables coexistence Source of authority: one-way sync by default Email address matching Simple and hybrid scenarios
DirSync Prerequisites 20346A DirSync Prerequisites 10: Implementing Directory Synchronization Domain and forest Hardware Operating System and supporting software DirSync quota limit Network ports Permissions and accounts Database If students are what is current version number of DirSync, and how to display this number, this may help: Current Version is 6567.0018 You can check your DirSync version using Add/Remove Programs, and noting the version history on the installer properties.
Active Directory Cleanup 10: Implementing Directory Synchronization Manual checks to perform Tools to check and remediate Active Directory: IdFix ADModify.Net
UPN Suffixes UPN must not be null 20346A UPN Suffixes 10: Implementing Directory Synchronization UPN must not be null UPN must match any verified public routable domain Default routing domains
Office 365 OnRamp Tool OnRamp checks include: Credentials Network 10: Implementing Directory Synchronization OnRamp checks include: Credentials Network Domains Users and groups Mail Sites Lync User software
Planning Considerations and Best Practices 10: Implementing Directory Synchronization DirSync best practices include: Having a proper project plan If using filtering, setting it up before synchronizing any objects Working with a cloud services partner Performing thorough capacity planning Remediating the Active Directory before building DirSync infrastructure Adding all SMTP domains as verified domains before synchronizing
Enabling Active Directory Synchronization 10: Implementing Directory Synchronization DirSync can be enabled using: Office 365 portal PowerShell May take up to 24 hours to complete
Set up DirSync Password Synchronization
DirSync Installation and Configuration 10: Implementing Directory Synchronization DirSync installation source should be the Office 365 portal DirSync configuration wizard options: Exchange hybrid deployment Synchronization post-configuration Limited management agent customization
Demo: Installing and Configuring DirSync
Hybrid Mode Simple coexistence Hybrid or Rich Coexistence 20346A Hybrid Mode 10: Implementing Directory Synchronization Simple coexistence Hybrid or Rich Coexistence Attribute write back
Filtering and Scoping DirSync filter configuration types: 10: Implementing Directory Synchronization DirSync filter configuration types: Organizational-unit (OU)–based Domain-based User-attribute–based
Demo: Filtering DirSync with the MIIS Client
Initiating Synchronization 10: Implementing Directory Synchronization Initiating synchronization: Windows Azure Active Directory Sync tool Configuration Wizard PowerShell Scheduled synchronization
Verifying Synchronization 10: Implementing Directory Synchronization Check Office 365 for synced Active Directory accounts View synchronization results in Identity Manager View synchronization entries in Event Viewer Last synced time: Office 365 Portal PowerShell
Password Synchronization 10: Implementing Directory Synchronization Password Complexity Password Expiration Enabling Password Sync
Manage Active Directory Users and Groups with DirSync In Place Monitoring and Managing DirSync
Managing Users and Groups 10: Implementing Directory Synchronization Managing Primary SMTP addresses Recovery from Accidental Deletes Recovery from Unsynchronized Deletes Bulk Activation of New Accounts
20346A SMTP Matching 10: Implementing Directory Synchronization SMTP matching is only applicable if the following conditions are met: The user account has an Office 365/Microsoft Exchange Online email address SMTP matching has not previously been used on that account The user account was originally authored by using Office 365 management tools
Monitoring and Managing DirSync 10: Implementing Directory Synchronization Common issues: Installation errors Inadvertently deactivating DirSync Unexpected changes in Active Directory Corrupt Active Directory Deactivating, then reactivating synchronization Use System Center Operations Manager to monitor for problems Upgrading DirSync Always use the latest version
Module Review Manage Active Directory Users and Groups with DirSync In Place