Jump to content

Recommended Posts

Posted

We've had a school O365 tenant for a long time but never used it as we went the Google Apps route however I'm revisiting it as I've wanted to use Azure as part of our backup processes as well as AD sync...

 

However the whole things feels like a dodgy iPhone game full of in-app purchases trying to get my money!

 

I setup AD Sync, I'd hoped to move our ADFS stuff off to Azure however I try and setup Room Booking System and immediately it's wanting me to upgrade to Premium P1 which is £4.50 per user per month, that's nearly £5.5k a month to pass a login request?!

 

I was hoping to back up our critical servers to the cloud and in case of a disaster (e.g. the school burning down) I could boot the SIMS server back up in Azure as a VM and use it to retrieve data, even if that has to be done directly on the server. I'd also hoped to use AD Sign In for Google Apps so that they share the same login details.

 

So my question is what are schools using it for? And more importantly, how much are you paying for it?!

 

Thanks

  • Thanks 1
Posted

Well, you're asking a lot from it; certainly from a "free" point of view. Hosting anything there is usually reasonably cheap. It's probably not the best disaster recovery location though, you'll likely get better pricing from proper systems like Redstor for example.

ADFS though should be easy; no need to use it for Office 365, AzureAD Connect is free and will give you exactly the same as far as 365 is concerned; SSO, same sign on etc.

  • Thanks 1
Posted (edited)

Its true that the SAML support in Azure AD is a Premium P1 feature - but also you should take into account what you're asking of it. The equivalent infrastructure that would allow ADFS to run in Azure, as recommended by MS would be like the example here.

Azure is not a cheap solution for most things - you just have to use it for the bits that are useful to you.

At the moment, we're only using it for the Office 365 AD stuff, DNS for our public facing domains, and for backing up to (It is cheaper than Redstor when you do it the way we have). We will also be using it for integrating auth for MLS soon (once the school who uses it migrates to our new network).

Over time, more features of our network will be cloudified also, but each function will be analysed separately.

 

We paid about £33 last month.

Edited by localzuk
Posted
Its true that the SAML support in Azure AD is a Premium P1 feature - but also you should take into account what you're asking of it. The equivalent infrastructure that would allow ADFS to run in Azure, as recommended by MS would be like the example here.

Azure is not a cheap solution for most things - you just have to use it for the bits that are useful to you.

At the moment, we're only using it for the Office 365 AD stuff, DNS for our public facing domains, and for backing up to (It is cheaper than Redstor when you do it the way we have). We will also be using it for integrating auth for MLS soon (once the school who uses it migrates to our new network).

Over time, more features of our network will be cloudified also, but each function will be analysed separately.

 

We paid about £33 last month.

 

Is the MLS integration going to require you to purchase Premium P1?

 

I've read some things that say you only need Premium P1 for non-gallery applications, others that you need it for any type of user authentication.

Posted
Well, you're asking a lot from it; certainly from a "free" point of view. Hosting anything there is usually reasonably cheap. It's probably not the best disaster recovery location though, you'll likely get better pricing from proper systems like Redstor for example.

ADFS though should be easy; no need to use it for Office 365, AzureAD Connect is free and will give you exactly the same as far as 365 is concerned; SSO, same sign on etc.

 

I don't mind paying for it, but £5 a month a user to take a login request and pass it through is a bit much, especially when we're working on a relatively small scale.

 

We do have an ADFS server and I'd hoped to pass the work off to Azure for the reliability mostly, but now it looks like I'll have to go with plan b and setup two local ADFS servers load balanced with two DMZ ADFS Web Application Proxy servers

  • Thanks 1
Posted
Is the MLS integration going to require you to purchase Premium P1?

I've read some things that say you only need Premium P1 for non-gallery applications, others that you need it for any type of user authentication.

Not that I know of, no. It is set up by adding an "Application that my organization is developing" within the AD.

Posted
Its true that the SAML support in Azure AD is a Premium P1 feature - but also you should take into account what you're asking of it. The equivalent infrastructure that would allow ADFS to run in Azure, as recommended by MS would be like the example here.

Azure is not a cheap solution for most things - you just have to use it for the bits that are useful to you.

At the moment, we're only using it for the Office 365 AD stuff, DNS for our public facing domains, and for backing up to (It is cheaper than Redstor when you do it the way we have). We will also be using it for integrating auth for MLS soon (once the school who uses it migrates to our new network).

Over time, more features of our network will be cloudified also, but each function will be analysed separately.

 

We paid about £33 last month.

 

Hi @localzuk

 

I would be very interested how (and what method) you are using to backup via Azure for only £33 (a month!)

 

I have been using our DPM Server to (additionally) backup to Azure Backup Vault (can't see any files etc. online) for about 8-9x the amount you pay! And to be honest, I am not overly confident about it, in the sense you also need available and additional disk capacity to cache the backups (to Azure) on the DPM Server, and additional disk capacity for the restores too. This all cuts into your Disk Storage Pool allocation (assigned to backups) unless you add, or have additional storage....

 

Sorry to hijack thread....

 

Thanks.

Posted
Hi @localzuk

I would be very interested how (and what method) you are using to backup via Azure for only £33 (a month!)

 

We run Veeam to a local NAS, and then use Cloudberry Ultimate to upload this to Azure storage (cold tier). Got 4TB of data in storage for that price. It does a differential each night, and adds the new data.

  • 2 weeks later...
Posted
What I would like...and perhaps its possible...is to backup to cloud/azure...and in the case of a disaster to be able to recover that backup to a temporary server in the cloud with VPN connection back to our network. And while our internet bandwidth wouldn't allow the same user experience - it would allow office and key users access to a working system until the onsite server was replaced/repaired. Then to copy/clone the temporary server back to the onsite one.
Posted
What I would like...and perhaps its possible...is to backup to cloud/azure...and in the case of a disaster to be able to recover that backup to a temporary server in the cloud with VPN connection back to our network. And while our internet bandwidth wouldn't allow the same user experience - it would allow office and key users access to a working system until the onsite server was replaced/repaired. Then to copy/clone the temporary server back to the onsite one.

 

2 options.

 

1) If you use Veeam, speak to a reseller and use their cloud backup solution. I can't remember what it is called but I seem to recall you backup all or key servers and then if it all goes wrong they can get the infrastructure up and running very quickly.

 

2) A slightly paired down option is to have a single DC in Azure and do exactly what you say, a VPN to connect it to the network. Then if disaster strikes, with a VPN client, PCs will still be able to logon and your AD is ready and waiting to start restoring other servers how ever you want. It effectively means your domain never dies and if the worst happens you use the cloud version as your seed to grow the network again.

 

We are using the 2nd option and it costs about £120 a month, much cheaper than the rough quote we had for our whole network to go through the Veeam system. We count it as an insurance, people may grumble but come a disaster we will be glad of it.

Posted
2 options.

 

1) If you use Veeam, speak to a reseller and use their cloud backup solution. I can't remember what it is called but I seem to recall you backup all or key servers and then if it all goes wrong they can get the infrastructure up and running very quickly.

 

2) A slightly paired down option is to have a single DC in Azure and do exactly what you say, a VPN to connect it to the network. Then if disaster strikes, with a VPN client, PCs will still be able to logon and your AD is ready and waiting to start restoring other servers how ever you want. It effectively means your domain never dies and if the worst happens you use the cloud version as your seed to grow the network again.

 

We are using the 2nd option and it costs about £120 a month, much cheaper than the rough quote we had for our whole network to go through the Veeam system. We count it as an insurance, people may grumble but come a disaster we will be glad of it.

 

What server type you using in Azure as we do the same thing with 11 schools connected and only costs us about £60 per month.

Posted
What server type you using in Azure as we do the same thing with 11 schools connected and only costs us about £60 per month.

Well that is annoying. I will have to dig it out. We were advised by a support company and I assumed we had the cheapest.

Posted
Well that is annoying. I will have to dig it out. We were advised by a support company and I assumed we had the cheapest.

 

We’re only running one server and its a Basic A1

Posted

you have to be weary if your azure environment wasnt set up properly or done by a third party, the one I have inherited at my workplace was and it wasnt done particularly brilliantly, both servers were A2 for a simple DC/ADFS setup that didnt need to be made at all really given how office365 syncs, but they were done that way and it was made with that higher quality of server than needed with the A2s, to which I have toned them down. It was based in the classic environment, I have since setup the entirety of our operations within the Resource Manager side of Azure.

 

I would say it takes a fairly decent amount of time to suss out Azure properly and the more you use it for different things the more it does indeed cost(I am no longer in education, so costs I see may not be comparable, I dont know if MS subsidises Azure for you guys in education these days).

 

Veeam has already been mentioned and it is excellent as a tool, its an excellent tool for exporting VMs to azure also, I have used it for that successfully on two servers now and I am slowly migrating and archiving servers to the cloud for legacy holds rather than keeping aging hardware going.

 

Company I work for has at the moment 11 VMs up the cloud with 8 on regularly(mostly A0/A1/A2, with a couple of D2s and an higher end E class server(the servers can be configured to switch off at times to save money which is a big help and saves big money for some of the high end stuff we use), file and server backups, static IPs and networking, databases and file storage and we are looking at around £800+ a month for our use at the moment.

Posted

What services are your other servers providing?

 

I’m always worried about the speed of the A1/A2 severe as they have very little memory or CPU - specs no one would ever build a server with, let alone if Windows would actually let you!

 

We run a DC on A1 and to work on is very sluggish but generally we never have to do anything to it and it works fine

Posted
I don't mind paying for it, but £5 a month a user to take a login request and pass it through is a bit much, especially when we're working on a relatively small scale.

 

We do have an ADFS server and I'd hoped to pass the work off to Azure for the reliability mostly, but now it looks like I'll have to go with plan b and setup two local ADFS servers load balanced with two DMZ ADFS Web Application Proxy servers

 

As others have said, you don't need SSO to have same user credentials as your on site AD domain.

 

Use AD Sync, you can even have a school.local domain internally and then jus add the Office UPN to the users AD account i.e. [email protected] and this should not cause any problems, I set this up in a previous role.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...