FN-GM Posted February 6, 2014 Posted February 6, 2014 (edited) Hi, I am investigating moving from Exchange to Office 365. One thing we want is to restrict it so only schools computers can connect via outlook. We don't want schools data on peoples personal devices. Is it possible to set this somehow? Maybe restrict it so only connections from our IP are allowed? Thanks Edited February 6, 2014 by FN-GM
fairm010 Posted February 6, 2014 Posted February 6, 2014 How strange i was wondering the same thing too! I'm curious to see if this is possible.
fairm010 Posted February 6, 2014 Posted February 6, 2014 After a bit of Google Fu! Limiting Access to Office 365 Services Based on the Location of the Client 1
Boredguy Posted February 6, 2014 Posted February 6, 2014 That only works if you go down the full FS route and not just DirSync though. You could always set the autodiscover DNS setting only on your local DNS server and not on your main domain hosting DNS. It won't stop devices connecting altogether but will cause more of a headache. And it does not stop users accessing the e-mails via the OWA and mobile devices. Surely a better route is educating the staff only to use Outlook in school, or to configure cacheless mode on Outlook if they need it on workstations outside of the school environment so that there is nothing stored locally? 1
FN-GM Posted February 6, 2014 Author Posted February 6, 2014 It doesn't shown is how to do only outlook. Plus you seem to need ADFS.
fairm010 Posted February 6, 2014 Posted February 6, 2014 Meh I knew it. I agree though, staff need to be educated not to use outlook on personal hardware. 1
FN-GM Posted February 6, 2014 Author Posted February 6, 2014 (edited) It won't stop devices connecting altogether but will cause more of a headache. And it does not stop users accessing the e-mails via the OWA and mobile devices. We want them to use OWA Surely a better route is educating the staff only to use Outlook in school, or to configure cacheless mode on Outlook if they need it on workstations outside of the school environment so that there is nothing stored locally? Education isn't good enough, if they do download the data and it gets in the wrong hands we are in trouble. They might not even intend to do it. We can't control external devices so can't turn it off for them. So its needs to be blocked. If you tell them not to do it, they will know they can do it. Edited February 6, 2014 by FN-GM
jbailey Posted February 7, 2014 Posted February 7, 2014 "We can't control external devices so can't turn it off for them." This may help: Managing Exchange ActiveSync Devices: Exchange 2010 Help Exchange Active Sync can be used to enforce a passcode on mobile devices, has remote wipe “Nuke the entire site from orbit--it's the only way to be sure” capability and office 365 control panel can be used to recreate policies for different users\devices to enforce it. we allows staff and students access to OWA - as without it they used personal emails at home to communicate - and configure active sync policies to address safety concerns, not saying it will tick all your boxes but I think active Sync has allowed us to move forward without our plan for: Office 365 + OWA + SkyDrive Pro = blocking pen drives and PST creation on site for everyone, so a lot more secure than it was. 1
Boredguy Posted February 7, 2014 Posted February 7, 2014 We want them to use OWA Education isn't good enough, if they do download the data and it gets in the wrong hands we are in trouble. They might not even intend to do it. We can't control external devices so can't turn it off for them. So its needs to be blocked. If you tell them not to do it, they will know they can do it. Well you could put it into your Staff Agreement Policies that they only use Outlook on school devices. Education and policies should be sufficient unless you decide to switch to full ADFS as the whole purpose behind 365 is to make connectivity easier =/ 1
FN-GM Posted February 7, 2014 Author Posted February 7, 2014 "We can't control external devices so can't turn it off for them." This may help: Managing Exchange ActiveSync Devices: Exchange 2010 Help Exchange Active Sync can be used to enforce a passcode on mobile devices, has remote wipe “Nuke the entire site from orbit--it's the only way to be sure” capability and office 365 control panel can be used to recreate policies for different users\devices to enforce it. we allows staff and students access to OWA - as without it they used personal emails at home to communicate - and configure active sync policies to address safety concerns, not saying it will tick all your boxes but I think active Sync has allowed us to move forward without our plan for: Office 365 + OWA + SkyDrive Pro = blocking pen drives and PST creation on site for everyone, so a lot more secure than it was. Outlook doesn't use ActivSync, so we can't use that.
jamesbmarshall Posted February 7, 2014 Posted February 7, 2014 This is a huge topic that's not just technical. You can restrict connection protocols so that POP, IMAP etc. can't be used to connect to a mailbox - thereby limiting folks to ActiveSync. You can then set policies for connection (i.e. device must have a PIN, etc.) to ensure that devices accessing mailboxes are not unsecured. The connecting devices must enforce policies that support the ability to remote wipe the device if needs be (again this can all be set in policy). That means you can securely allow folks to connect to Exchange Online with the ability to wipe that data/device in an emergency. You can also go down the more complex route of ADFS and you can then really simply limit connection to inside the school network. The BIG question is: why not let staff/students access school mail on their device IF you can mandate a degree of security on that device? 1
FN-GM Posted February 7, 2014 Author Posted February 7, 2014 The BIG question is: why not let staff/students access school mail on their device IF you can mandate a degree of security on that device? School policy. We don't want data stored on devices that are not encypted. Outlook uses IMAP so it doesn't have the features to enforce the encyption.
Boredguy Posted February 7, 2014 Posted February 7, 2014 (edited) Strange, our Outlook clients are not using IMAP to connect to Office 365. Also you can disable protocols for users via Powershell http://support.microsoft.com/kb/2573225 Edited February 7, 2014 by Boredguy 1
jamesbmarshall Posted February 7, 2014 Posted February 7, 2014 Outlook uses IMAP so it doesn't have the features to enforce the encyption. Only if that's how you set it up - 2007, 2010 and 2013 should all connect using ActiveSync or Outlook Anywhere. As I say, you can disable IMAP and POP and prevent anyone connecting that way. 1
FN-GM Posted June 7, 2014 Author Posted June 7, 2014 (edited) Hi all, i have just come back to this. We are using ADFS so it will make things easier. Looking at this link i should be able to do it. I want to allow ActivSync and OWA for external users. This is so smartphones can get email via and app and then other users can access email from home via a web interface. However we don't want them to connect via outlook using ActivSync, can i put a policy in place to prevent outlook as a client via Activesync? Then use outlook anywhere internally? But block Outlook Anywhere externally? Using the stuff in the link should i be able to achieve blocking outlook externally but still other services? Would merging Scenario 2 & 3 do it? What protocol does the OWA app for iPhone and Android use please? Thinking i could just set the policy to only allow web based externally and use the dedicated app for smartphone users. Thanks Edited June 7, 2014 by FN-GM
FN-GM Posted July 21, 2014 Author Posted July 21, 2014 Hi all, i have just come back to this. We are using ADFS so it will make things easier. Looking at this link i should be able to do it. I want to allow ActivSync and OWA for external users. This is so smartphones can get email via and app and then other users can access email from home via a web interface. However we don't want them to connect via outlook using ActivSync, can i put a policy in place to prevent outlook as a client via Activesync? Then use outlook anywhere internally? But block Outlook Anywhere externally? Using the stuff in the link should i be able to achieve blocking outlook externally but still other services? Would merging Scenario 2 & 3 do it? What protocol does the OWA app for iPhone and Android use please? Thinking i could just set the policy to only allow web based externally and use the dedicated app for smartphone users. Thanks BUMP :)
edutech4schools Posted July 21, 2014 Posted July 21, 2014 School policy. We don't want data stored on devices that are not encypted. Outlook uses IMAP so it doesn't have the features to enforce the encyption. Maybe MS can do a domain app like Google do so it enforces things like encryption and passwords before they are given access to schools data.
FN-GM Posted July 21, 2014 Author Posted July 21, 2014 Maybe MS can do a domain app like Google do so it enforces things like encryption and passwords before they are given access to schools data. Even if it is encrypted it still doesn't comply. School data is not permitted on personal devices. Please can we try and keep on topic?
AngryITGuy Posted November 6, 2016 Posted November 6, 2016 Apooogies for resurrecting an old thread but did you get anywhere with restrictions Outlook? I'm in the same boat as I too am looking to lock down access to Office 365 mail via Outlook on personal computers. I've come across the same searches on Google for Client Access Policies but none of the ones listed seemed to fit my requirements. Did you have to create your own policy or merge two of the example scenarios?
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now