pantscat Posted June 7, 2013 Posted June 7, 2013 Hello all, I'm certain that all the information is out there somewhere, but to be completely honest I'm struggling to find where it is - so I wonder if anyone else has done something similar? I currently have Exchange 2010 on site and am considering a Hybrid deployment with Office365. This is what I want to do: - Different domain name and GAL for staff and students - From what I've read I believe that I'll need two different tenancies to do this - is that correct? (And how would that affect DirSync?) - Use DirSync to sync usernames and passwords (I've looked at ADFS and at present I don't have the spare capacity to provide all the additional boxes that it requires) - Keep some staff mailboxes locally (but use an online archive mailbox to help to eliminate PST usage locally!) So... if anyone has done this, or something similar I'd be very glad to hear from you. Thanks!
jamesbmarshall Posted June 7, 2013 Posted June 7, 2013 I can't stress enough how important it is to keep your deployment as simple as possible. That said, my thoughts are below. I currently have Exchange 2010 on site and am considering a Hybrid deployment with Office365. Exchange Hybrid is awesome, but complex. Are you intending to keep your local Exchange server (I mean, really really - can't you move all your mailboxes into Exchange Online?)? This is what I want to do: - Different domain name and GAL for staff and students - From what I've read I believe that I'll need two different tenancies to do this - is that correct? (And how would that affect DirSync?) You could have two tenants. Don't. Exchange Online now supports address book policies that you can use to segregate the GAL if you need to. Going down the route of two separate tenants might seem simpler logically, but has a big impact. - Use DirSync to sync usernames and passwords (I've looked at ADFS and at present I don't have the spare capacity to provide all the additional boxes that it requires) Good move - AD FS is a great SSO solution, but requires a lot of time and potentially some investment to pull off properly. DirSync + Password Sync is a really simple and elegant solution for keeping your IDs in sync. - Keep some staff mailboxes locally (but use an online archive mailbox to help to eliminate PST usage locally!) You can do this, but there is a cost. To loop back to my point above, do you really really need to keep mailboxes on-premises? If you do you could look at Exchange Online Archiving, but it would be far simpler to keep your mailboxes in one place as this would remove the need for you to keep an Exchange org on-premises (i.e. saves you time, money and makes management easier). If you do need to keep Exchange for whatever reason then you can set up hybrid coexistence and use ECP to manage your users and migrating mailboxes between the two environments is simple enough (i.e. OST files do not need rebuilding, etc.). Configuring it is easier than it's ever been with the Hybrid Config Wizard. I just think that the best advice is to keep it simple. 3
pantscat Posted June 7, 2013 Author Posted June 7, 2013 Hi @jamesbmarshall - thanks for the very useful reply! Exchange Hybrid is awesome, but complex. Are you intending to keep your local Exchange server (I mean, really really - can't you move all your mailboxes into Exchange Online?)? Yes, I know it's pretty complex. It's a mixture of mangement attitude to cloud solutions (they're a bit reluctant) and that at present we only have an ADSL backup to our main leased line (although I'm looking into swapping this for a 10mpbs EFM), not that we've really had any internet outages (thanks Vaioni!), but it's the peace of mind that it would offer! You could have two tenants. Don't. Exchange Online now supports address book policies that you can use to segregate the GAL if you need to. Going down the route of two separate tenants might seem simpler logically, but has a big impact. That's excellent - I wasn't exactly thrilled with the concept of having two tenants, I'd much rather split the GAL. Good move - AD FS is a great SSO solution, but requires a lot of time and potentially some investment to pull off properly. DirSync + Password Sync is a really simple and elegant solution for keeping your IDs in sync. Excellent! You can do this, but there is a cost. To loop back to my point above, do you really really need to keep mailboxes on-premises? If you do you could look at Exchange Online Archiving, but it would be far simpler to keep your mailboxes in one place as this would remove the need for you to keep an Exchange org on-premises (i.e. saves you time, money and makes management easier). If you do need to keep Exchange for whatever reason then you can set up hybrid coexistence and use ECP to manage your users and migrating mailboxes between the two environments is simple enough (i.e. OST files do not need rebuilding, etc.). Configuring it is easier than it's ever been with the Hybrid Config Wizard. I just think that the best advice is to keep it simple. I agree with keeping things simple if possible. Clearly I need to think further about our plans and consider moving mail completely online. If we were to go completely cloud based, what would be the mechanism to move mailboxes over? Setup a hybrid co-existance and then "break" it and decomission the local exchange box? I know that with Exch2007 you'd do a cutover migration, but not sure about 2010.
sukh Posted June 9, 2013 Posted June 9, 2013 you can either do a staged or cutover migration this depends on your goal on if you want to have a hybrid solution or not.
rbance Posted June 9, 2013 Posted June 9, 2013 I have a hybrid model in my environment. Staff use on premise exchange and students use Office365. I did migrate from Live@EDU though....having moved here previously). Things to note; 1. You have to Federate the whole domain (in my case domain.school.com and stu.domain.school.com ...as an example). 2. All users have a onmicrosoft account (cloud based). 3. ADFS and ADFS proxy in DMZ (note: it did not work for 2012 last time I looked). 4. Using DIRSYNC, but am moving to FIM 2010 5. Need a cert for FS portal I can provide my build doco if that helps... Things to consider; 1. Reasons to keep staff email on premise (compliance and archiving was my driver...and cost of Office365 service). 2. Really wanted to separate staff from students. 3. Be flexible as staff may move to cloud eventually if things change.... Richard 1
rbance Posted June 9, 2013 Posted June 9, 2013 Mind you..in saying this...the move to Google is looking really compelling, especially if the driver is BYOD and considering a WEB App only model for app delivery...
Norphy Posted June 9, 2013 Posted June 9, 2013 3. ADFS and ADFS proxy in DMZ (note: it did not work for 2012 last time I looked). Richard We have our ADFS servers running on 2012, works absolutely fine. Reason I did it was because ADFS is a builtin role in 2012 rather than a downloadable plugin so that just simplified things
rbance Posted June 9, 2013 Posted June 9, 2013 We have our ADFS servers running on 2012, works absolutely fine. Reason I did it was because ADFS is a builtin role in 2012 rather than a downloadable plugin so that just simplified things Pretty sure Office365 only works with ADFS 2.0 in 2008R2....not Server 2012...That was the case in January at least anyway according to Microsoft... Would be interested if you have it all working properly with 2012 ADFS and Office365...
Norphy Posted June 9, 2013 Posted June 9, 2013 Yes, we do. We initially had some trouble when authenticating clients from the internal network but it's all working fine now.
rbance Posted June 10, 2013 Posted June 10, 2013 When did you actually transition? My guess is that MS do not support that config at the time (I was looking online to see if they do yet and could not see it). Is your domain on 2012 or 2008 R2 function? (I am hoping to go to 2012 in December...and this was the only issue. (the rest is really a simple upgrade process)). Or did you just use a 2012 server with ADFS 2.0 (but still a 2008 R2 domain).
Norphy Posted June 10, 2013 Posted June 10, 2013 We put it in in late April I think. All of our DCs are running 2012 but we're still at 2008 R2 level functionality. I don't think you can install ADFS 2.0 on a 2012 server, you have to install ADFS as a role. In any case, we have two servers set aside solely for ADFS functionality, one runs the actual ADFS server and the other is a proxy in the DMZ. Both are running Windows 2012.
kmount Posted June 10, 2013 Posted June 10, 2013 When did you actually transition? My guess is that MS do not support that config at the time (I was looking online to see if they do yet and could not see it). Is your domain on 2012 or 2008 R2 function? (I am hoping to go to 2012 in December...and this was the only issue. (the rest is really a simple upgrade process)). Or did you just use a 2012 server with ADFS 2.0 (but still a 2008 R2 domain). I couldn't find it online either so I asked them on twitter and got a DM back yesterday that it was supported .
pantscat Posted June 10, 2013 Author Posted June 10, 2013 lots of useful stuff A copy of your build doc would be helpful if you don't mind? That's very useful info, thanks. Ant
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now