Jump to content

Recommended Posts

Posted

Just been doing some testing for migrating all the students out of my on prem over to office 365, the only thing that's currently stopping me from migrating all 1000+ of them is my understanding of how outlook will work in school for the kids.

 

Up until now I've always had a prf file with the connection settings to our exchange, the shortcut has the importprf flag on, they login do a mandatory profile, click the shortcut, outlook opens up to their mailbox. No settings or windows to click on. Googling around seems to suggest that a prf isn't necessary with office 365 mailboxes, however with no prf outlook just fails to load up with an error.

 

Any suggestions on the best way of achieving the same user experience? Can i continue to use a prf if i want? (No idea what settings i need to connect O365 that way however) I'm still keeping staff mailboxes on prem for the time being.

Posted

I can't see why you can't continue to use the prf file. But I have never used them. I always use group policy to control all the settings, makes it easier. This one in particular.

 

User Configuration -> Administrative Templates -> Microsoft Office Outlook XXX -> Tools \ Account Settings -> Exchange “Automatically configure profile based on Active Directory Primary SMTP address”

 

The end user experience is like yours. They click Outlook and it just opens, not wizard etc.

  • Thanks 1
Posted (edited)

Confused as to why i can't get this working.

 

So I've migrated a test user into office 365 successfully, I've made a shortcut without the prf and removed my usual "office" policies and just applied a test one with just the setting above (and one other setting to disable cached exchange mode, forcing it to use online mode) and i get this error every time: "Cannot start microsoft outlook. Cannot open the outlook window. The set of folders cannot be opened. Your profile is not configured"

 

I've tested that i can add the account manually to an admin login, i've tested that i can get to autodiscover.domain.com fine both inside the network and outside and the account appears to be in office365 list with the correct settings. I must be missing just one piece of the puzzle to get this working but I'm not understanding what >_< (ADFS and ADFS Proxy are setup and working too)

 

Have you setup modern authentication so users are not prompted for credentials?

 

I hadn't but i have now.

Edited by mrbios
Posted

Is there any way to verify that modern authentication is enabled and working?

 

I've enabled it on both Exchange online and i've deployed the various registry settings to my test client. However i still have this problem that the client doens't automatically know where to look for the mailbox....only when i configure a prf file pointing at outlook.office365.com does it actually then prompt me for the username and password and open the correct mailbox. What am i missing?

Posted (edited)
Just to check, you have their email address set within the AD account profile don't you?

 

Yea, all that appears to be fully automated when the account is actually created, so I've never had to manually enter anything, and for the particular account I'm using to test it's all there as expected.

 

TargetAddress in the attribute list shows as SMTP:[email protected] rather than [email protected], but I think that's to be expected as part of the migration? (primary SMTP is still [email protected] after migration, as is the address in the AD profile, it just happens to have multiple smtp addresses now instead)

 

EDIT: reading through this: https://support.office.com/en-us/article/Using-Office-365-modern-authentication-with-Office-clients-776c0036-66fd-41cb-8928-5495c0f9168a i notice that groove.exe doesn't exist within my office installation, most likely as onedrive wasn't selected as an install option.......is that likely the issue I'm seeing? Why should i need that for this to work!?

Edited by mrbios
Posted (edited)

I wonder if i have autodiscover setup correctly. I've got split DNS, and on my external DNS autodiscover has a CNAME to autodiscover.outlook.com. Internally should this be the same or should i point that at my internal server? Prior to using O365 it always had an A record pointing at my internal exchange address.

EDIT: saying that browsing to autodiscover.outlook.com as that user works fine and loads up the mailbox...so i guess that's fine, and all the testexchangeconnectivity tests for autodiscover work fine.

Edited by mrbios
Posted
Interesting, running outlook in safemode allows me to select to create a new profile, it takes a while to respond but then when it does it pops up with a security alert with the correct address of autodiscover.domain.net (being my down, the CNAME that redirects to outlook.com) but it tells me the name on the security certificate does not match the name of the site....and it's my smoothwall certificate that's intercepting it, however every possible domain name including my own is listed in the "do not decrypt" list. I wonder if this i the only thing blocking me....
Posted

Once you get your modern authentication working correctly you can use group policy preferences to set a registry value that automatically creates an Outlook profile without clicking through the wizard, effectively doing away with prf files.

Key Path (for Office 2016, change section in bold to 15.0 for Office 2013):HKEY_CURRENT_USER\Software\Microsoft\Office\16.0\Outlook\Autodiscover

Value Name: ZeroConfigExchange

Value Type: REG_DWORD

Value Data (Decimal): 1

  • Thanks 1
Posted

I've just installed Office 2016 on to one PC as a test, works perfectly. So it looks like my only issue now is that modern authentication isn't working on my office 2013 install, however i think that could be due to groove.exe not existing in my install folder.

 

Just completely removed office from one PC, reinstalling it with every component selected and groove.exe now exists, running the office updates then i'll be able to test it :)

Posted (edited)

It works! Reinstalled office 2013, installed updates and it works.

 

So the issue, is that groove.exe is missing from my base installs of office, which means i've left off onedrive when selecting the options to install...however if i run the office installer it thinks onedrive is already installed. How can i deploy this component without completely redeploying office!?

 

EDIT: ahhhhh groove is part of the business connectivity services component within shared office components, which appears to be unticked. So i need to deploy that!

Edited by mrbios
Posted

Just posting this here in case anyone gets any ideas as to why this is the case, but I've just spent hours testing this:

Current office install, doesn't work

Uninstall office, leave project on, doesn't work

Uninstall office, uninstall project, reinstall just office (haven't tried putting project back on yet) run windows updates to ensure the various files are at the right level, everything works perfectly.

Run an office repair, doesn't work

Run office install over the top of existing to add any missing components, doesn't work

 

So only if i completely remove office and project THEN reinstall it, does it actually work! >_< Effing make believe deity above this is frustrating.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...