Jump to content

Recommended Posts

Posted (edited)

Some of you might have read my other threads on here about getting the Word app to work on an iPad and my general O365 woes...

 

It turns out some of it was in part caused by our filtering.

 

We are on LGfL and obviously therefore using WebScreen 2.0.

 

I'm quite strict with the filtering and so have the catagory Web E-mail set as Denied.

 

I ran a report to show what was being blocked and found two URLs:

 

ht tps : / /ocws.officeapps.live . com

 

ht tps : / /ols.officeapps.live . com

 

So my question is to anyone on LGfL using WebScreen 2.0 and O365 is, did you have to allow these (or any other URLs) or allow the Web E-Mail category?

 

There are certain parts of the O365 admin portal that aren't working correctly and I wonder if anything is still somehow being blocked.

 

Specifically it is not reporting that the user has Word installed and activated on their device. Does anyone know if that requires some other communication like the DNS for MDM (which I have not set up)?

Edited by Koldov
Posted
Some of you might have read my other threads on here about getting the Word app to work on an iPad and my general O365 woes...

 

It turns out some of it was in part caused by our filtering.

 

We are on LGfL and obviously therefore using WebScreen 2.0.

 

I'm quite strict with the filtering and so have the catagory Web E-mail set as Denied.

 

I ran a report to show what was being blocked and found two URLs:

 

ht tps : / /ocws.officeapps.live . com

 

ht tps : / /ols.officeapps.live . com

 

So my question is to anyone on LGfL using WebScreen 2.0 and O365 is, did you have to allow these (or any other URLs) or allow the Web E-Mail category?

 

There are certain parts of the O365 admin portal that aren't working correctly and I wonder if anything is still somehow being blocked.

 

Specifically it is not reporting that the user has Word installed and activated on their device. Does anyone know if that requires some other communication like the DNS for MDM (which I have not set up)?

 

It might be more prudent to unblock the whole category for staff as there may be many URLs that you will need to end up unblocking. It might be worth raising a call with Atomwide and asking them to unblock anything related to Office 365. If you don't have luck with Atomwide, call the LGfL Office and ask to speak to Jose Kingsley, who is the Office 365 lead for LGfL, who may be able to help you further.

  • Thanks 1
Posted

I know I've probably been a bit strict with the filtering, but it's always been manageable really as we're a very small school and there isn't much they need access to (apart from that important teaching tool Youtube).

 

I just didn't think I wanted them accessing personal Yahoo/GMail/a n other email provider at work because you know they'd be tempted to email work stuff, so thought it best to block it.

 

Surely O365 URL's should be unblocked anyway?

Posted
Block rules generally trump allow rules. If I blocked the webmail category, I'd be pretty upset if Outlook.com and Hotmail.com (and gmail.com) kept working.
Posted

What will be interesting is how to handle Gmail once we start using it fully with pupils. We migrated from StaffMail to Gmail this summer, so at the moment, my staff users have to do the following:

 

Gmail is blocked on the default category (Student)

Staff have to visit https://block.lgfl.org.uk and then authenticate using their USO

Staff can then access Gmail

 

The trouble is, there is no stopping whether it is corporate Gmail accounts or personal. I'm not too fussed with staff, but there doesn't appear to be a way to block students from accessing personal Gmail accounts either once we allow students to use Gmail for G Suite, because how would the filtering distinguish between corporate and personal Gmail?

Posted
Block rules generally trump allow rules. If I blocked the webmail category, I'd be pretty upset if Outlook.com and Hotmail.com (and gmail.com) kept working.

 

I'm not sure I really get your point. :confused:

 

Maybe I've got the wrong end of the stick, but I don't think block > allow, I think it works the other way round.

 

If I block the Web E-Mail catagory, but then add a local execption of 'Outlook.com' I believe I could then get to Outlook.com.

 

I guess this comes down to the reason I'm having to use O365 at all.

 

Out of everything it offers I just want the Word app, for one user on one iPad.

 

It's too long to go into here, but it turns out the only way I can do it is with O365.

 

All I know is that whilst trying to get the app to recognise the license in the O365 portal, it wouldn't.

 

I ran the report on the iPad's IP and it gave me 2 denied URLs (in the catagory of Web E-Mail), I put those into the local allow and then it worked.

 

To me those URLs aren't Web E-Mail and therefore don't belong in that category (and I don't want to allow that whole category).

 

It seems that honestly 95% of O365 isn't actually Web E-mail and so if I'm blocking that category I don't want it blocking the Word (or any other) app or the communication between the O365 portal and the devices.

Posted
It might be more prudent to unblock the whole category for staff as there may be many URLs that you will need to end up unblocking

 

We allow the webmail category. Office365 works fine.

 

Here is the Microsoft documentation on the URLS etc that are required for Office365:

https://docs.microsoft.com/en-gb/office365/enterprise/urls-and-ip-address-ranges

 

Yup you may be right, that's quite a few URLs.... :getmecoat:

 

However, I'm only looking at the most basic of set-ups.

 

Looking through, I don't need Lync/Sharepoint/Exchange/(Sky)Onedrive/smtp/Outlook/mailprotection/teams/Skype etc...

 

And I still don't understand why any of the ones I DO need would be blocked under the Web E-Mail category?

Posted (edited)
I'm not sure I really get your point. :confused:

 

Maybe I've got the wrong end of the stick, but I don't think block > allow, I think it works the other way round.

 

If I block the Web E-Mail catagory, but then add a local execption of 'Outlook.com' I believe I could then get to Outlook.com.

 

I guess this comes down to the reason I'm having to use O365 at all.

 

Out of everything it offers I just want the Word app, for one user on one iPad.

 

It's too long to go into here, but it turns out the only way I can do it is with O365.

 

All I know is that whilst trying to get the app to recognise the license in the O365 portal, it wouldn't.

 

I ran the report on the iPad's IP and it gave me 2 denied URLs (in the catagory of Web E-Mail), I put those into the local allow and then it worked.

 

To me those URLs aren't Web E-Mail and therefore don't belong in that category (and I don't want to allow that whole category).

 

It seems that honestly 95% of O365 isn't actually Web E-mail and so if I'm blocking that category I don't want it blocking the Word (or any other) app or the communication between the O365 portal and the devices.

 

That's the thing with these services, they are using so many hidden URLs that aren't so obvious. As you've listed in your later posts, "Outlook/Hotmail/Office 365 Mail" is hardly using outlook.com at all. If anything, the sign in page itself is https://login.microsoftonline.com or in some cases live.com. Also, if there are any firewall rules being blocked, then these won't appear in your WebScreen results.

 

If you want to be really granular, than each to their own, but imo, you'd be better off and saving yourself much aggro by unblocking Web Email for staff and asking Atomwide to open all necessary ports on your firewall for Office 365.

 

Yup you may be right, that's quite a few URLs....

 

However, I'm only looking at the most basic of set-ups.

 

Looking through, I don't need Lync/Sharepoint/Exchange/(Sky)Onedrive/smtp/Outlook/mailprotection/teams/Skype etc...

 

And I still don't understand why any of the ones I DO need would be blocked under the Web E-Mail category?

 

Also, if you want to use Word on an iPad using Office 365, would you not want to also allow OneDrive in order for the user to save the files to the cloud as opposed to on the device?

 

Hmmm....

 

It didn't seem to mind some very similar URLs from the same Domain.

 

[ATTACH=CONFIG]51596[/ATTACH]

 

This also kinda proves @psydii's point about Block > Allow. Although the similar URLs exist in categories you have allowed, they will be blocked because the precedence to block rather than allow is usually seen as the safer option.

Edited by Zoom7000
  • Thanks 1
Posted (edited)
That's the thing with these services, they are using so many hidden URLs that aren't so obvious. As you've listed in your later posts, "Outlook/Hotmail/Office 365 Mail" is hardly using outlook.com at all. If anything, the sign in page itself is https://login.microsoftonline.com or in some cases live.com. Also, if there are any firewall rules being blocked, then these won't appear in your WebScreen results.

 

If you want to be really granular, than each to their own, but imo, you'd be better off and saving yourself much aggro by unblocking Web Email for staff and asking Atomwide to open all necessary ports on your firewall for Office 365.

 

Yeah, I get https://outlook.live.com when I search, but as you say I'm sure there's many ways to get to the same thing, it's all becoming a bit blurry with Microsoft when all services starts becoming connected - it's one of the many things I don't like about Apple (but that's for another time). It may work for a lot of people having everything like that, it just doesn't for me. Sure, I probably will end up opening the flood gates, it just winds me up a bit. Absolutely no offence meant to anyone, but I just feel like opening up a whole category for what should be a simple thing may end up biting me is the A$$.

 

Also, if you want to use Word on an iPad using Office 365, would you not want to also allow OneDrive in order for the user to save the files to the cloud as opposed to on the device?

 

Well, no. I see your point and again this is what the whole aggravating thing is. It seems like it's a given now that using Microsoft Word means the online version and storage in OneDrive... Because that's what Microsoft are pushing people into. The point of my original thread was that I didn't want that, as my Headteacher is using it for his work in other school and will be commuting/possibly staying away for a few days and as the iPad is Wi-Fi only it seems beneficial to have it save work to the device itself. Also the work he is doing needs to wiped from the device afterwards not flying about the cloud. Plus I 'm not sure if I would have bothered doing any of this if I didn't need the app to save to the device (with a screen > 10.1"), otherwise he could have used a free Outlook/Hotmail/Microsoft account and I would have had a much less stressful last couple of weeks...

 

 

This also kinda proves @psydii's point about Block > Allow. Although the similar URLs exist in categories you have allowed, they will be blocked because the precedence to block rather than allow is usually seen as the safer option.

 

Not sure it does, but it's a bit... Friday here and been a LOOOOOOOOONG term, so maybe we are talking at cross purposes? The 'category' of Web E-Mail must contain some type of URL list at their end - it just means that they have put:

 

https://odc.officeapps.live.com in an allowed category (General).

https://ols.officeapps.live.com in a denied category (Web E-Mail)...

 

It appears I can punch through that with an allow to a specific URL (so even though they are blocking my URL in a category, I can get to it - so my URL allow is beating their category deny).

The fact that similar URLs are allowed just depends what category they have decided fit to list them in (not sure what decision criteria they have), but even though I have still got the category denied, by setting an allow I can reach the URLs I need.

 

I need coffee.....

Edited by Koldov
Posted

With platforms like Office365, it's not just a black and white case of "this is e-mail, this is word" as they are all interconnected now.

 

Certainly I'd be making use of the OneDrive storage purely for the auditing features incase the device gets misplaced.

While you can remote wipe the ipad, you also have the backup of knowing a) the files are safe still, b) if anyone has accessed them, so you have the extra protection under GDPR if it does disappear (which you wouldn't have been able to do had a free Outlook account been used)

  • Thanks 2

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...