Jump to content

Recommended Posts

Posted

As per the questions I posted here :

 

[sOLVED]DirSync, without EMC - Supported or not? | Directory integration services | Microsoft Office 365 Community

and here

Dirsync / AAD Sync. - but without EMC on prem...

 

I'd really appreciate anyone in a similar position to give me 10 seconds and vote / comment on a feature request for Microsoft to build this into their 365 roadmap.

 

In a nutshell - if you migrate to 365 and want password sync without implementing ADFS you currently have to keep a version of exchange on premise running and connected to 365 (forever!) to be supported in editing attributes related to exchange (ADSI edit / Active Directory advanced features view is not supported or recommended). - so much for being able to "move" to the cloud..

 

This is the link where you can vote, and hopefully this will push Microsoft to develop further to support people with limited on premise server infrastructure.

 

Remove requirement for onprem Exchange when using DirSync – Customer Feedback for Microsoft Azure

 

Thanks in advance.

 

Ben.

Posted

I don't have an on premise server, but I've had no problems with the functionality of using Office 365 and DirSync which is performing a password sync without the complex ADFS requirements.

 

Having the Exchange Management Console would be really great graphically, but that defeats the purpose of moving to 365 which is cloud based and more powershell oriented.

 

Adjusting user attributes in the active directory for updating SMTP alias etc can be done quickly via the AD Users and Computers interface anyway (the Attribute Editor) and everything else is just as easy in a powershell command away.

Posted (edited)
I don't have an on premise server, but I've had no problems with the functionality of using Office 365 and DirSync which is performing a password sync without the complex ADFS requirements.

 

Having the Exchange Management Console would be really great graphically, but that defeats the purpose of moving to 365 which is cloud based and more powershell oriented.

 

Adjusting user attributes in the active directory for updating SMTP alias etc can be done quickly via the AD Users and Computers interface anyway (the Attribute Editor) and everything else is just as easy in a powershell command away.

 

This is my exact point. - Microsoft do NOT support using the attribute editor. if you edit a users email address and the sync fails, or something else goes wrong, Microsoft will refuse to look into it and support it beacuse you do not have the EMC installed and connected to 365, which is the ONLY supported way of changing something as simple as an SMTP alias :)

 

Sorry if my post was worded incorrectly, you have the EXACT setup I'm talking about. - and should you get issues you are in an unsupported scenario and will not get Microsoft support (I've verified this with the Microsoft Partner network, and technical leads at 365) - leading me to request something that would make you able to be supportable without installing EMC and as you said, defeating the purpose of moving to the cloud.

 

Thanks

 

Ben

Edited by Ben-BSH
Posted

Considering MSFT support members have stated on the community.office365.com site to use ADSI Edit for just this type of modification to a user, and it is a Microsoft application, then claiming it's not supported in the event something goes wrong would appear to be illogical.

 

Maybe @EduTech could prod the support teams into broader support of tools other than EMC if it is the case ;)

Posted
Considering MSFT support members have stated on the community.office365.com site to use ADSI Edit for just this type of modification to a user, and it is a Microsoft application, then claiming it's not supported in the event something goes wrong would appear to be illogical.

 

Maybe @EduTech could prod the support teams into broader support of tools other than EMC if it is the case ;)

 

Exactly :)

 

Decommissioning your Exchange 2010 servers in a Hybrid Deployment - Exchange Team Blog - Site Home - TechNet Blogs

 

As per the bottom of this blog post here (Ignore the Hybrid stuff, but if you scan read it)

 

"Note: Removing or modifying objects with ADSIEDIT isn’t supported."

 

and as per my first link

"Currently, without Exchange management tools, such as EMC, to manage synchronized Office 365 users, is theoretically available. However, it would be very complicated to manage them. Moreover, if issues occur when using this way, Microsoft may provide limited official assistance."

 

Long story short, several customers we have including some schools are refusing to move to 365. As Microsoft have confirmed to them and us, without EMC there is no support if they have problems.

 

Not only that, but what if you are not so technically capable to be playing with ADSIedit? even if Microsoft DID support it, its a tool you can do a lot of damage with, and really something we shouldn't be forced to using for the sake of them building a small dll just like that acctinfo.dll which everyone used to love for getting last login info.

Posted (edited)

Hi All,

 

Sorry for the delay I didn't see you mention me in this post until just now,

 

I just want to make something clear here if you are to edit your user accounts via ADSIEdit or Attribute Editor and you are told by a Microsoft Support Engineer that you are not supported because you did that then please contact me. We do support you making the changes, we would of course prefer you to make the changes via Attribute Editor as oppose to ADSIEdit because it's safer. If you are a customer that has done a Hybrid Migration then it is not supported for you to remove the Exchange Management aspect of your deployment as stated in the Hybrid Deployment Migration Method in that scenario it is important that you continue to manage your users via the Exchange Management Console.

 

If you did not do a Hybrid Migration, and did another method of an Exchange Migration (Staged, Cutover) or if you created new mailboxes and just Synchronized your OnPrem Identities to Azure AD then the only way really for you to manage the identity piece when using Directory Sync is to use Attribute Editor or ADSIEdit and we are Fully Aware of these concerns from customers and it is something that we are actively looking into.

 

I would be very interested to hear your feedback on this method, if you can PM me your business requirements around this feature that would be very much appreciated and I can then ensure this gets into the right hands internally.

 

*If you do remove the exchange server, do not remove the attributes from the schema! because this will then remove the attributes in the AD Objects and cause you a headache! :-)

 

Many Thanks,

James.

 

Exactly :)

 

Decommissioning your Exchange 2010 servers in a Hybrid Deployment - Exchange Team Blog - Site Home - TechNet Blogs

 

As per the bottom of this blog post here (Ignore the Hybrid stuff, but if you scan read it)

 

"Note: Removing or modifying objects with ADSIEDIT isn’t supported."

 

This NOTE is referring to you modifying the connectors that are created in the Exchange Hybrid Deployment Configuration via ADSI Edit that of course is NOT supported.

Edited by EduTech
  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...