Jump to content

Recommended Posts

Posted

Good afternoon,

 

Could anyone tell me if there is a Windows 7 client that can be used for logging into an Office 365 domain? I know it can be done with Windows 10 but what am I missing in Windows 7? It's probably really obvious.

 

Cheers

 

Gareth

Posted (edited)

Do you mean like using Azure AD Domains? If so you can't unless they changed something. It's not a full domain environment and only supports Win10 (Ok not 100% true you can do split hybrids etc, but if you mean a clean neat Azure AD)

 

Steve

Edited by Steve21
Posted
Good afternoon,

 

Could anyone tell me if there is a Windows 7 client that can be used for logging into an Office 365 domain? I know it can be done with Windows 10 but what am I missing in Windows 7? It's probably really obvious.

 

Cheers

 

Gareth

 

Hi Gareth,

I'm afraid this isn't available or something you can purchase and add to Windows 7.

 

Alex

Posted

Cheers guys. I'm guessing then the only way is with a WIndows 10 machine that picks up GPOs and settings via InTune for Education.

 

Okay - so what about a windows 10 machine that picks up it's account from an Azure/Office 365 domain but it's GPOs - like printers and mapped drives from a local DC (as we do not have ITfE)? Can that be done?

 

Gareth

Posted

What exactly are you trying to do in regards to this? :p The main purpose of Azure AD Joins are for people who aren't often on site or using their own machines etc.

 

If the machines are going to be on-site and able to connect to a local DC for GPOs/drives etc, generally I wouldn't say you'd need Azure AD. If you want to go the Azure AD route you could just create the printer mappings etc in Azure AD as GPOs

 

Steve

Posted

You're looking at Azure AD for the login, and InTune policies (which acts more like MDM) for a GPO replacement.

 

How about connecting devices back to your on-prem network using DirectAccess? You keep your own AD domain and policies that way, with the connectivity. It works very well for a few of our staff that are based at other schools around the borough. A bit more difficult with Windows 7 (but doable) and very easy with Windows 10.

Posted
What exactly are you trying to do in regards to this? :p The main purpose of Azure AD Joins are for people who aren't often on site or using their own machines etc.

 

If the machines are going to be on-site and able to connect to a local DC for GPOs/drives etc, generally I wouldn't say you'd need Azure AD. If you want to go the Azure AD route you could just create the printer mappings etc in Azure AD as GPOs

 

Steve

 

Hi Steve,

 

The situation is - we have our own domain. Each user has an account on this domain. Their work is stored on our main server. All is good.

 

In Wales - everyone has what is called a Hwb account. Different username and password. We have been asked to migrate all of our files to OneDrive which we are given as part of this Office 365 tenancy.

 

It means users have to remember two sets of passwords/two usernames etc.

 

What I want is to use one username/password combo to log into Hwb so that users can access their work without a second logon. A sort of SSO - however all of our GPOs are kept on the local domain.

 

Did that make sense?

 

Gareth

Posted
You're looking at Azure AD for the login, and InTune policies (which acts more like MDM) for a GPO replacement.

 

How about connecting devices back to your on-prem network using DirectAccess? You keep your own AD domain and policies that way, with the connectivity. It works very well for a few of our staff that are based at other schools around the borough. A bit more difficult with Windows 7 (but doable) and very easy with Windows 10.

 

The Office 365/Axure tenancy that we are part of does not have Intune. I'm happy to jump to WIndows 10 if this direct access is possible to link back to our GPOs. Can you tell me more?

Posted

Do you have any real admin access to the hwb side? As in is it per school or is it just one large setup?

 

Just even azure AD you'd need admin access to setup the win 10 ones properly. If all you have is a login per person and all admin is on their end you'd be pretty stuck tbh

 

If you have admin access to your own part of it you could always setup a federated tenant (or simple password write back) then use the normal SSO for when accessing it online etc

 

Steve

Posted

Hwb do not support SSO and have no plans to at the moment. We use hwb for OneNote etc for some lessons and after a while the pupils just remember the two usernames so keeping them separate is definitely the way to go. If you use Office 2016 you could look at getting that to auto sign in to the hwbcymru account for easy access to one drive etc but I haven’t had time to explore that yet.

 

Luke

Posted
Gareth, I'm sure you're more up to speed on the long-term 'stability' of Hwb, but I'd still advise caution here. Moving everything to Hwb Onedrive sounds like a huge backward step for performance and manageability, even if some convenience is gained. Your own separate tenancy would probably be superior. If the use of Hwb is really being pushed from above, try to work out where that's coming from as Estyn don't seem to give a stuff.
Posted
Gareth, I'm sure you're more up to speed on the long-term 'stability' of Hwb, but I'd still advise caution here. Moving everything to Hwb Onedrive sounds like a huge backward step for performance and manageability, even if some convenience is gained. Your own separate tenancy would probably be superior. If the use of Hwb is really being pushed from above, try to work out where that's coming from as Estyn don't seem to give a stuff.

 

HI mate - From what I gather the whole of Wales will be pushed to Hwb and everyone will have to use it. I have heard that Hwb won the contract for the National Tests - so make of that what you want.

 

We have our own tenancy but have been forced along the Hwb tracks - it's ok to be honest and no different to Office 365 on our own tenancy - just without the control.

 

Gareth

Posted
We certainly have to use it, and we issue logins out to students and staff, but we were always assured that we didn't have to use it instead of our existing systems. We stated pretty firmly that we didn't want to use the email functionality and we were told that was fine.
Posted
We certainly have to use it, and we issue logins out to students and staff, but we were always assured that we didn't have to use it instead of our existing systems. We stated pretty firmly that we didn't want to use the email functionality and we were told that was fine.

 

Different in Swansea - we have been told be have to use it. All our staff and pupil email has been migrated. Of course the driving factor was Lindsay Harvey (hwb) became our Education Executive on the Council and so pushed it. A lot of us were against it but he managed to secure the Headteacher buy in.

Posted
My sincere condolences. When it all finishes and the central funding dries up, make sure you've got your separate domain and tenancy to fire back up. That should also give you the flexibility you need for this plan - there was talk of us all gaining access to the Office Admin Centre in Hwb for each school but that has gone quiet.
Posted
My sincere condolences. When it all finishes and the central funding dries up, make sure you've got your separate domain and tenancy to fire back up. That should also give you the flexibility you need for this plan - there was talk of us all gaining access to the Office Admin Centre in Hwb for each school but that has gone quiet.

 

Who told you about that last bit?

Posted
The Office 365/Axure tenancy that we are part of does not have Intune. I'm happy to jump to WIndows 10 if this direct access is possible to link back to our GPOs. Can you tell me more?

 

I'm not sure how you're going to get SSO into HWB (I'm not well versed on what happens in Wales, sorry) since it sounds as if they have an Office365 tenant they want you to be a part of, am I right?

 

I mean, in our setup we have Windows 10 laptops that are on our domain as normal. These then use DirectAccess (a new fangled VPN basically) to connect back into our school. Now, we run Azure AD Connect on our domain controllers to sync all our Active Directory users into Office365 and provide single sign on. This works flawlessly, but I'm not sure you'd ever be able to do it with HWB unless they specifically set up a service with something like ADFS so everyone could federate their domains with their HWB Office365 tenant.

 

I'm not sure what you're asking is going to be possible, to be honest. It sounds like other people's policies are going to make your life unnecessarily difficult.

Posted

Sounds like you're pretty stuffed if you can't do any admin stuff on it :p Only kind of way to do it would be some epic scripting to set cached credentials for everyone, but not sure you'd really want to do that if it even works!

 

What I don't understand (unless it's just a wales thing! :p) is why you'd want to move your stuff over to them. Even if you "need" to use it for some stuff like exams, surely those users just have a login, and your 99% normals use your local domain and your own 365?

 

Steve

Posted

I think there have been a few things that have allowed this to become an issue:

 

1) Many of the primaries had absolutely shocking resources before Hwb. No or little email access, no Office, all run on web string for internet access. Hwb was a driver for improved internet access in all schools across Wales - even larger secondaries like us received grant money to upgrade our fibre, wifi and switches. This was good.

2) Many of the people involved with IT in schools have it tacked on to their existing jobs. They may not understand some of the points made when Hwb was being rolled out, so 'you must use Hwb' became 'you must only use Hwb'. This snowballed.

3) SLT in many schools has the impression that they'll fail an inspection if Hwb is not deeply ingrained within the school. I know for a fact that this is not the case - remember that Estyn and Welsh Government are not closely linked.

4) Hwb was set up by LP+. This meant that a commercial entity was involved, which was fine initially, but their interest in pushing it onwards waned as soon as additional funding cooled. Some parts of the system feel very tired (and slow) now.

 

The way that users are synced to Hwb is almost unuseable, IME (it happens via PLASC). We can't just bulk upload year 7s for instance, because these wouldn't be 'their' accounts that have moved from primary. Therefore, we have to wait until January for their accounts to be manageable via our dashboard (we can do basic password resets).

 

Basically, we have just given users access to their Hwb login details (they click a link and it emails them their details). They know how to use these, and can do so pretty easily. For those staff that use it, they get on well with it. For those that don't, it can easily be ignored.

 

As an aside, I asked a collaborative student from another school for their email address to put into AD - saves making them a separate account on our system which many not get checked. Despite having an account for several years, the student wasn't sure of their email address (this was a non-dozy sixth former too).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...