Jump to content

Recommended Posts

Posted (edited)

Hi,

 

I am investigating moving from Exchange to Office 365. One thing we want is to restrict it so only schools computers can connect via outlook. We don't want schools data on peoples personal devices.

 

Is it possible to set this somehow? Maybe restrict it so only connections from our IP are allowed?

 

Thanks

Edited by FN-GM
Posted

That only works if you go down the full FS route and not just DirSync though.

You could always set the autodiscover DNS setting only on your local DNS server and not on your main domain hosting DNS.

 

It won't stop devices connecting altogether but will cause more of a headache.

And it does not stop users accessing the e-mails via the OWA and mobile devices.

 

Surely a better route is educating the staff only to use Outlook in school, or to configure cacheless mode on Outlook if they need it on workstations outside of the school environment so that there is nothing stored locally?

  • Thanks 1
Posted (edited)

It won't stop devices connecting altogether but will cause more of a headache.

And it does not stop users accessing the e-mails via the OWA and mobile devices.

 

We want them to use OWA

 

Surely a better route is educating the staff only to use Outlook in school, or to configure cacheless mode on Outlook if they need it on workstations outside of the school environment so that there is nothing stored locally?

 

Education isn't good enough, if they do download the data and it gets in the wrong hands we are in trouble. They might not even intend to do it. We can't control external devices so can't turn it off for them. So its needs to be blocked.

 

If you tell them not to do it, they will know they can do it.

Edited by FN-GM
Posted

"We can't control external devices so can't turn it off for them."

 

This may help:

 

Managing Exchange ActiveSync Devices: Exchange 2010 Help

 

Exchange Active Sync can be used to enforce a passcode on mobile devices, has remote wipe “Nuke the entire site from orbit--it's the only way to be sure” capability and office 365 control panel can be used to recreate policies for different users\devices to enforce it.

 

we allows staff and students access to OWA - as without it they used personal emails at home to communicate - and configure active sync policies to address safety concerns, not saying it will tick all your boxes but I think active Sync has allowed us to move forward without our plan for:

 

Office 365 + OWA + SkyDrive Pro = blocking pen drives and PST creation on site for everyone, so a lot more secure than it was.

  • Thanks 1
Posted
We want them to use OWA

 

Education isn't good enough, if they do download the data and it gets in the wrong hands we are in trouble. They might not even intend to do it. We can't control external devices so can't turn it off for them. So its needs to be blocked.

 

If you tell them not to do it, they will know they can do it.

 

Well you could put it into your Staff Agreement Policies that they only use Outlook on school devices. Education and policies should be sufficient unless you decide to switch to full ADFS as the whole purpose behind 365 is to make connectivity easier =/

  • Thanks 1
Posted
"We can't control external devices so can't turn it off for them."

 

This may help:

 

Managing Exchange ActiveSync Devices: Exchange 2010 Help

 

Exchange Active Sync can be used to enforce a passcode on mobile devices, has remote wipe “Nuke the entire site from orbit--it's the only way to be sure” capability and office 365 control panel can be used to recreate policies for different users\devices to enforce it.

 

we allows staff and students access to OWA - as without it they used personal emails at home to communicate - and configure active sync policies to address safety concerns, not saying it will tick all your boxes but I think active Sync has allowed us to move forward without our plan for:

 

Office 365 + OWA + SkyDrive Pro = blocking pen drives and PST creation on site for everyone, so a lot more secure than it was.

 

Outlook doesn't use ActivSync, so we can't use that.

Posted

This is a huge topic that's not just technical.

 

You can restrict connection protocols so that POP, IMAP etc. can't be used to connect to a mailbox - thereby limiting folks to ActiveSync. You can then set policies for connection (i.e. device must have a PIN, etc.) to ensure that devices accessing mailboxes are not unsecured. The connecting devices must enforce policies that support the ability to remote wipe the device if needs be (again this can all be set in policy).

 

That means you can securely allow folks to connect to Exchange Online with the ability to wipe that data/device in an emergency.

 

You can also go down the more complex route of ADFS and you can then really simply limit connection to inside the school network.

 

The BIG question is: why not let staff/students access school mail on their device IF you can mandate a degree of security on that device?

  • Thanks 1
Posted
The BIG question is: why not let staff/students access school mail on their device IF you can mandate a degree of security on that device?

 

School policy. We don't want data stored on devices that are not encypted. Outlook uses IMAP so it doesn't have the features to enforce the encyption.

Posted
Outlook uses IMAP so it doesn't have the features to enforce the encyption.

 

Only if that's how you set it up - 2007, 2010 and 2013 should all connect using ActiveSync or Outlook Anywhere. As I say, you can disable IMAP and POP and prevent anyone connecting that way.

  • Thanks 1
  • 3 months later...
Posted (edited)

Hi all, i have just come back to this. We are using ADFS so it will make things easier. Looking at this link i should be able to do it. I want to allow ActivSync and OWA for external users. This is so smartphones can get email via and app and then other users can access email from home via a web interface. However we don't want them to connect via outlook using ActivSync, can i put a policy in place to prevent outlook as a client via Activesync? Then use outlook anywhere internally? But block Outlook Anywhere externally?

 

Using the stuff in the link should i be able to achieve blocking outlook externally but still other services?

 

Would merging Scenario 2 & 3 do it?

 

What protocol does the OWA app for iPhone and Android use please? Thinking i could just set the policy to only allow web based externally and use the dedicated app for smartphone users.

 

Thanks

Edited by FN-GM
  • 1 month later...
Posted
Hi all, i have just come back to this. We are using ADFS so it will make things easier. Looking at this link i should be able to do it. I want to allow ActivSync and OWA for external users. This is so smartphones can get email via and app and then other users can access email from home via a web interface. However we don't want them to connect via outlook using ActivSync, can i put a policy in place to prevent outlook as a client via Activesync? Then use outlook anywhere internally? But block Outlook Anywhere externally?

 

Using the stuff in the link should i be able to achieve blocking outlook externally but still other services?

 

Would merging Scenario 2 & 3 do it?

 

What protocol does the OWA app for iPhone and Android use please? Thinking i could just set the policy to only allow web based externally and use the dedicated app for smartphone users.

 

Thanks

 

 

BUMP :) :) :)

Posted
School policy. We don't want data stored on devices that are not encypted. Outlook uses IMAP so it doesn't have the features to enforce the encyption.

 

Maybe MS can do a domain app like Google do so it enforces things like encryption and passwords before they are given access to schools data.

Posted
Maybe MS can do a domain app like Google do so it enforces things like encryption and passwords before they are given access to schools data.

 

Even if it is encrypted it still doesn't comply. School data is not permitted on personal devices.

 

Please can we try and keep on topic?

  • 2 years later...
Posted

Apooogies for resurrecting an old thread but did you get anywhere with restrictions Outlook?

 

I'm in the same boat as I too am looking to lock down access to Office 365 mail via Outlook on personal computers.

 

I've come across the same searches on Google for Client Access Policies but none of the ones listed seemed to fit my requirements.

 

Did you have to create your own policy or merge two of the example scenarios?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...