ranj Posted April 12, 2018 Posted April 12, 2018 Hi fellow edugeekers We about to embark on an Office 365 rollout to the whole organisation and vastly improve our client estate. So I am looking for some suggestions on some challenges on how best we approach these. Apologises in advance for the technical list.... We have an existing tenant setup (****.onmicrosoft.com) in Azure but is based on our old organisation name. We want to create new tenant name to reflect the new organisation name. The name is yet to be decided. We have a few existing E1 (used) / E3 (not used and recently purchased) under existing tenant and want to understand once new tenant is created, how we would transfer licensing to new tenant. We also have EMS and dynamics 365 licenses setup in existing tenant. We prepared to keep these services in existing tenant and run them simultaneously if that will be the simpler approach. We currently use Azure AD Connect (formerly DirSync), this connects our on premise AD into Azure, it is setup with Filtering so only some OUs are sync to Azure. Our AD as it stands currently is setup with the old domain name. Due to incoming requirement for Office 365, our strategy is to create a new AD domain in the same Active Directory forest as we are also doing a Windows 10 deployment so we see this as the perfect opportunity to start with a new domain. It will be two way Domain trust so all resources in existing domain can be trusted in new domain and vice versa. It is our hope we can then create a second on premise Azure AD connect server using filtering to the new AD Domain and we’ll then move users/computers from the old to the new domain once we port users across to Windows 10. Looking at the Topology best practise guidance I believe this is supported as long as the user only appears in one tenant. Would there be a better way to set this up? Our preference is not to create a new AD forest and new domain as the administration and management of this would be far greater. We plan to use MFA on Office 365, however want to investigate the various avenue’s we can use as not all of our user base have a corporate phone so some will need to use personal phones for SMS or using an authenticator app. Does this need to be setup for all users or can it be switched off at the request of a user? On the back of this we want to investigate the possibility of users resetting their AD passwords through Office 365 so this task can be achieved anywhere on any device without the reliance of internal network. We currently have enabled password write back and password hash sync. We currently have an ADFS 3.0 setup with Web Application proxy and plan to use this to achieve SSO on the internal network for Office 365. We currently make use of the Application proxy feature in our existing tenant to make our internal SharePoint 2013 application available externally. Eventually we like to port over the configuration of this to the new tenant. Would this be possible? Going forward we probably want to make use of SharePoint online but are concerned about the considerations we need to take with regards to backup and recovery. We aware of the security abilities built into Office 365 such as classifications, DLP, data governance, threat management, E discovery. Can these tools be setup after deployment. Is there any requirement to set these up at the start? We currently use Intune and these are managed via EMS licenses in Office 365. The strategy is to move to using an alternative solution using Trend Micro mobile security solution and decommission Intune. Finally our plan is to do a phased approach to Office 365, starting off with One Drive and Share point Online and slowly introduce the new technologies as we become more familiar and iron out any deployment issues. As you can see I have lots of questions and having had a look and done some planning work I sort have an idea of what the options are but its always useful to get some other views on this hence my questions so appreciate any responses on all or some of the questions I have. Many Thanks
oapscarface Posted April 13, 2018 Posted April 13, 2018 Wow, that's a long list but also very thorough. I can't answer all of these with total correct answers but I can try and answer based on my experience (we're a trust of 9 schools and every one that joins we migrate internally to the trust tenant). If you want simple, keep your existing tenant, do you mean A3 rather than E3? I suspect you can move your A3 licenses but it'll be painful! from memory you get A3 for free if you have an EES agreement but I might be wrong there, it's been 4 years since we set this up. Personally when we started the trust we had 3 secondary schools, one of which was already in o365 but rather than use their forest and tenant we started from scratch, new tenant and new forest, you can still setup trusts between the two in the same way you can with 2 domains in a forest, I think if you continue with 1 forest and 2 domains you'll end up wishing you had just one, just my opinion. I don;t know what the forest is called but if it's the old org name you can pretty much hide it but it will always be there. for cross forest to work and to simplify things you might want to look into ADMT this website Plan and Execute an Active Directory Merger, Part 1 | IT Pro helped me get started. You are correct on the AzureADConnect part, note that when you remove somebody from one domain or set a filter, it will automatically delete that user from Office 365. If I read this correctly you thing a new forest/domain would be harder to manage/administer, I think starting from scratch and getting it right will make it easier to manage than a single forest with 2 domains personally. Can't really comment on MFA but I wouldn't use it for students for sure. ADFS.... Has it's benefits, not least password write back, we've choosen not to use it as it requires on premise servers which removes the resiliency benefits of Office 365, have you looked into Seamless Sign/Passthrough https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-aadconnect-sso we're now using that as if it can't contact your DC it reverts to normal o365 auth, it also removes the complexity of ADFS. Look into a product called ShareGate for porting, while we're not using it to port SharePoint we are using it to migrate and pre tag data. As for backups..... Well..... I'm taking the view that there's a 7 year retention option and previous versions so while I will get slaughtered for this, I'm relying on MS! We have a potential capacity on Sharepoint and Onedrive of 1.3 PB, even if that were 500TB I'd NEVER have a means of backing it up! I need to spend more time on Compliance Center but I believe the answer to the question of can you set this up later is yes. I've no experience of either Trend or Intune I'm afraid. OneDrive/SharePoint - big one for us ATM this as it's now our main focus. OneDrive On Demand is a game changer, particularly for students, have a read about that, look into Office 365 Pro Plus Device Based Activation (there's stuff on edugeek about it) as you'll want students and ideally staff running that rather than good old Office 2016, this means Office will Sign in when you open it without needing roaming profiles. As for SHarePoint, we're using a company called Cloud Design Box to help with this, we're going at it as a blank canvas, we're not just copying up Staff and Student Shares and then saying that's it, we're teaching staff about Meta Tagging and using that rather than folders, we're then not mapping any drives or even using OneDrive to present SHarepoint sites, we're going web/cloud first and removing the staff/student shares over the next 3 years from on prem good old fashioned file explorer to SharePoint. Hope that all helps. Good Luck. 1
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now