Jump to content

Recommended Posts

Posted (edited)

I am genuinely sorry for creating a thread just to ask daft questions, but between live@edu, Office 365 for Business, Office 365 for education and two versions of DirSync, I've gotten completely lost in Google tabsplosion hell.

 

At the moment I have an onsite Exchange 2007 server. I want to either a) move to Office 365 or b) upgrade to Exchange 2010/3 on Server 2012. I'm investigating a) first.

 

All our users have their own mailbox - about 1400 people total. These would need to be migrated over fully - mail, calendar, contacts - and automatically - I'm not talking 1400 people through PST files. From what I can see about cutover migrations, these are one single migration limited to 1000 users; I want to do it in chunks and for 1400 people.

 

Ideally I want to do it bit by bit so I can test, but I don't see how I can do this without changing the MX records and breaking Exchange. If I can at least test with my spare domain (more below) that will do, then I can upgrade everyone else in the summer.

 

Users must still be able to use Outlook seamlessly - on-site SSO and everything.

 

I'll still need full control over transport rules and the ability to grant access to view mailboxes and - ideally - run PowerShell scripts to forcibly remove messages etc. I like the control Exchange gives me, I just hate the administrative burden of the damn thing.

 

Ideally I'd also like to set up alternate email addresses for everyone, based on the Office field of AD (where I store their code e.g. JBL for Joe Bloggs) and another (shorter) domain we own. This alternate domain isn't currently used for mail, so if it can be used for testing, say so.

 

Can all the above be done, and if so, has anyone got a handy deployment guide for me to follow? I've found about 4 and I don't know which one to follow whilst I test :(

 

(on a related note, is the Exchange Online Protection free to use against onsite Exchange, thus rendering the CAL included in the more-expensive version of EES unnecessary?)

Edited by sonofsanta
Posted

I don't have time right now to address your post fully, but check out:

 

Office 365 Education Deployment Resources - UK Education Cloud Blog - Site Home - MSDN Blogs

 

There's a whole bunch of useful links to get you started.

 

You need to look at the staged migration option, or depending on your longer term plans, Exchange Hybrid.

 

Also, SSO is a big deal and not usually what most people actually require (even if they think they need it). I'd take some time to look at DirSync & Password Sync as I think it is a far simpler approach and ticks most boxes for people.

 

Best advice: keep it as simple as you can, as long as you can.

  • Thanks 1
Posted

Thanks James. If I was going to switch, I'd switch fully - no hybrid deployment. You're preaching to the choir with advice on simplicity as well.

 

Regarding SSO: I need it to be as seamless as possible for users. If they suddenly have to start logging in again everytime they open Outlook they will all complain and ask why we cant go back to the old system, regardless of any other benefits. Sort of a corollary to KISS, I suppose: Keep It Even Simpler For Users (KIESFU sounds rubbish, though)

Posted (edited)
Thanks James. If I was going to switch, I'd switch fully - no hybrid deployment. You're preaching to the choir with advice on simplicity as well.

 

Regarding SSO: I need it to be as seamless as possible for users. If they suddenly have to start logging in again everytime they open Outlook they will all complain and ask why we cant go back to the old system, regardless of any other benefits. Sort of a corollary to KISS, I suppose: Keep It Even Simpler For Users (KIESFU sounds rubbish, though)

 

I had exactly the same questions when we moved, but in hindsight.... ;)

 

We moved to logging in via webmail again and nobody had a problem with it at all, its quite normal now. They don't have to login when using outlook 2010, just the webmail.

 

Setting up SSO is HUGELY complicated requiring extra servers, software, and all sorts. It also introduces a single point of failure to your login systems that may bring webmail down in the future. One of the biggest advantages of cloud email is its independent, run by microsoft not us :) I really wouldn't recommend going SSO at first, do it in steps.

 

Saying all that, the migration is very easy and your joining at a time when dirsync has been updated to make it much more useful.

 

I personally wouldn't go anywhere near a local exchange server, the idea seems ridiculous to me now :)

Edited by zag
  • Thanks 1
Posted
I had exactly the same questions when we moved, but in hindsight.... ;)

 

We moved to logging in via webmail again and nobody had a problem with it at all, its quite normal now. They don't have to login when using outlook, just the webmail.

 

Setting up SSO is HUGELY complicated requiring extra servers, software, and all sorts. I really wouldn't recommend going that way at first, do it in steps.

 

It's only Outlook I'm concerned with, so if I don't need SSO for that then I am happy to drop it :) students are already used to logging in via webmail.

 

Another question I forgot to ask - can I disable students from logging in via Webmail? It's the easiest way of blocking them from email when they've broken the AUP and earnt themselves a ban from the relevant system.

Posted
It's only Outlook I'm concerned with, so if I don't need SSO for that then I am happy to drop it :) students are already used to logging in via webmail.

 

Another question I forgot to ask - can I disable students from logging in via Webmail? It's the easiest way of blocking them from email when they've broken the AUP and earnt themselves a ban from the relevant system.

 

Don't forget, people can always tick the box to remember credentials in Outlook. So they might have to enter them once, but they can just tick the box. Obviously, if your students are using OWA that's even better.

 

You don't have to disable OWA - in fact, just disabling OWA doesn't block access. Instead you can use the Office 365 admin portal to disable their logon capabilities altogether. Also, if you did go down the AD FS route then you could just lock the account in AD.

Posted
Thanks James. If I was going to switch, I'd switch fully - no hybrid deployment. You're preaching to the choir with advice on simplicity as well.

 

Regarding SSO: I need it to be as seamless as possible for users. If they suddenly have to start logging in again everytime they open Outlook they will all complain and ask why we cant go back to the old system, regardless of any other benefits. Sort of a corollary to KISS, I suppose: Keep It Even Simpler For Users (KIESFU sounds rubbish, though)

 

If your going to do a full migration to the cloud (365) you need to set up a hybrid deployment if you want a smooth translation.

 

I have just completed ours and you literally connect to 365 through the exchange console and migrate mail boxes at will.

 

We had to upgraded to exchange 2010 to do it though, it can be done in 2007 but its no where near as slick

Posted
If your going to do a full migration to the cloud (365) you need to set up a hybrid deployment if you want a smooth translation.

 

Respectfully, I have to disagree. Hybrid is not well suited for deployments where the target is to remove the on-premises Exchange server in the short term.

 

You're right insofar as hybrid allows silky-smooth mailbox migrations, but it requires a lot of configuration and potential investment in your local infrastructure. For a simple migration, I'd say that this is not best use of resources.

Posted
I'm in exactly the same boat. I shall watch this thread with interest.

 

Likewise. I've taken the decision not to replace our Exchange 2007 Server this year and look to migrate to Office365 next summer instead. I'll more than likely just migrate staff mailboxes only but setup new ones for Students. The SSO is going to be the key for this to work effectively.

 

Pete

Posted
Likewise. I've taken the decision not to replace our Exchange 2007 Server this year and look to migrate to Office365 next summer instead. I'll more than likely just migrate staff mailboxes only but setup new ones for Students.

 

Thats what we did. Worked well.

  • Thanks 1
Posted
You don't have to disable OWA - in fact, just disabling OWA doesn't block access. Instead you can use the Office 365 admin portal to disable their logon capabilities altogether. Also, if you did go down the AD FS route then you could just lock the account in AD.

 

The problem with locking the account in AD is that it stops them logging in altogether - we tend to use a system of targeted punishment, so we block webmail where a student has abused their email privilege (with timewasting, bullying, spamming etc.) but don't block the account so they can still work in IT lessons etc. This is why we only allow students access to webmail, so that we can block them in this way - if they had Outlook, we couldn't stop it. Could we still do this with O365? (I'm hoping that's disabling logon capabilities in the admin portal)

 

I would, I think, agree that hybrid would be complicated if we're removing on-site - there's especially no point in upgrading to Exchange 2010 to do it, as I'm wanting to migrate to avoid the pain of an upgrade to 2010 :) so what's going to be the best way to migrate mailboxes, if cutover is limited to 1000?

Posted

You can disable OWA via the Exchange admin web console, or via the following powershell Set-CASMailbox -Identity [email protected] -OWAEnabled $false

 

When the user trys to log in to OWA they get the following message

:-(

something went wrong

Your account has been disabled.

 

It does not stop them logging into the actual Office365 portal, but Outlook, Calendar and people are certainly blocked :D

  • Thanks 1
Posted
Likewise. I've taken the decision not to replace our Exchange 2007 Server this year and look to migrate to Office365 next summer instead. I'll more than likely just migrate staff mailboxes only but setup new ones for Students. The SSO is going to be the key for this to work effectively.

 

Pete

 

Same as me although im still keeping my options open with having exchange still on site but moving to 2013.

  • 4 weeks later...
Posted

I am being really thick here and struggling to get started. Once I get going I'll be on my way, but at the moment I can't spot an obvious route in to get some momentum (and motivation) going.

 

How do I test a user without changing DNS about? Do I need to use an alternate domain (I have one to hand anyway) or can I use the .sch.uk address? The staged migration document seems to say that email gets forwarded on from Exchange for now. Presumably then when I've moved everyone over, I update the DNS, and cut the Exchange box out of the picture?

 

Do I need to create the user account on Office 365 before the staged migration or is this done by DirSync? How do I configure Outlook to point to 365 for the email - is there a *.prf file or do I have to configure autodiscover on my internal DNS?

 

/feeling very stupid in the heat

 

I have Outlook Anywhere set up anyway, which is something at least!

Posted
Documentations advises it not to be installed on a DC.

 

Presumably it needs to be on a server though, not just a workstation?

 

/getting lost in tab explosion hell trying to work all this out

  • 5 months later...
Posted

Bit of a necro, but I've just picked this job up again and it seems silly creating a whole new thread just to document my ongoing idiocy.

 

I've got a handle on what I'm doing and where I'm going now, I think - dirsync is working (without breaking my SCCM install this time, seriously, it would be lovely if the dirsync installer could at least check if I had SQL Server installed already and ask if I wanted to use that instead of assuming I knew to launch from the command line with a flag. It seemed like such an obvious question for an installer to ask I didn't even think to read up first :() and I've got a few sets of instructions on doing a staged migration, so I'm happy there.

 

Questions I have now are operational, really, as I'm still not commited to this path over Exchange 2013 onsite:

* Can I get access to other user's mailboxes without just resetting their password? Obviously important when dealing with children.

* Can I run cmdlets to search & remove messages from all mailboxes, as I can now with 2007? It doesn't come up often but it has covered backsides in the past and it'd be very useful to have this still (not a deal breaker, though)

* How do backups work if a user accidentally deletes an email? Does O365 store a certain backup range automatically? And, in all honesty, I need to know if we as schools are expected to retain this data for a set amount of time, and if so how does O365 jive with that?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...