Jump to content

Recommended Posts

Posted

So i have a school looking to remove RM unify. Once removed federation my understanding is that users can continue to login to office 365 to access mail , one drive etc.

However once this is removed, this will then remove the RM unify sync tool from the local server.

In place of this, I would install Microsoft AD azure sync tool and configure to connect to 365.

However, before i make any changes, will the sync tool match up local usernames and remote username and not touch the existing records, or will it end up creating duplicates?

Has anyone done this, as looking for a definite answer before making these global changes.

thanks in advance.

Posted (edited)
So i have a school looking to remove RM unify. Once removed federation my understanding is that users can continue to login to office 365 to access mail , one drive etc.

.

 

Once federation is removed unless the RM tool sync passwords to Office 365 you will find that the passwords are random generated or the last password set before unify as your federation (RM) probably just SAMLs the Email address or UPN over to login the account into Office 365.

 

Have you seen this: https://support.rm.com/TechnicalArticle.asp?cref=TEC3229605

 

Last bit says: RM Unify will no longer be authenticating these accounts and so the user's password will change from being the RM Unify/AD password, to being the password actually set by and stored in Office 365.

 

I would make sure that you have a onmicrosoft account set in the tenant as a global admin before un-federating.

 

 

However, before i make any changes, will the sync tool match up local usernames and remote username and not touch the existing records, or will it end up creating duplicates?

 

ID Fix is useful for find issues with Data in AD before syncing with office 365: https://docs.microsoft.com/en-us/office365/enterprise/install-and-run-idfix

 

This might give you an idea on the field looks like they use Email Address from Unify: https://support.rm.com/NewsAndAlerts.asp?cref=NWS3442877&Referrer=Portal&nav=0

Edited by willtech
Posted
Once federation is removed unless the RM tool sync passwords to Office 365 you could find that the passwords are random generated as your federation (RM) probably just SAMLs the Email address or UPN over to login the account into Office 365.

 

Have you seen this: https://support.rm.com/TechnicalArticle.asp?cref=TEC3229605

 

Last bit says: RM Unify will no longer be authenticating these accounts and so the user's password will change from being the RM Unify/AD password, to being the password actually set by and stored in Office 365.

 

 

 

ID Fix is useful for find issues with Data in AD before syncing with office 365: https://docs.microsoft.com/en-us/office365/enterprise/install-and-run-idfix

 

This might give you an idea on the field looks like they use Email Address from Unify: https://support.rm.com/NewsAndAlerts.asp?cref=NWS3442877&Referrer=Portal&nav=0

 

 

the RM unify sync tool does do passwords also - if i change a password in AD, the sync tools picks this up and changes the RM unify password and o365 password to the same as local so i'll be ok?

Posted
the RM unify sync tool does do passwords also - if i change a password in AD, the sync tools picks this up and changes the RM unify password and o365 password to the same as local so i'll be ok?

 

No from the look at their documents: https://support.rm.com/NewsAndAlerts.asp?cref=NWS3442877

 

 

Do passwords synchronise between RM Unify and Office 365?

No. Although AD Sync synchronises passwords from your local network to RM Unify, there is no passing, or synchronising, of passwords on to Office 365.

 

When Office 365 is federated to RM Unify, it is RM Unify which authenticates your login and passes an authentication token to Office 365 in order to allow access to your account (this is single sign-on, or SSO). Office 365 itself does not know, and does not need to know, your password.

 

When configuring a mail client with your Office 365 credentials, you enter your Office 365 email address and your RM Unify password. Again, it is RM Unify which authenticates your login and passes a token to Office 365 in order to allow your mail client access to your Office 365 mailbox.

 

Although an administrator may be able to reset the password of a federated user using the Office 365 Admin Centre, the user's password held by RM Unify takes precedence. The user will not be able to authenticate to Office 365 services unless they use their RM Unify password.

 

Additionally, a federated user will not be able to change their own password from within Office 365 and instead they will see the following message: "Your organisation doesn't allow you to change your password on this site. Please change your password according to the method recommended by your organisation".

Posted
Once federation is removed unless the RM tool sync passwords to Office 365 you will find that the passwords are random generated or the last password set before unify as your federation (RM) probably just SAMLs the Email address or UPN over to login the account into Office 365.

 

Have you seen this: https://support.rm.com/TechnicalArticle.asp?cref=TEC3229605

 

Last bit says: RM Unify will no longer be authenticating these accounts and so the user's password will change from being the RM Unify/AD password, to being the password actually set by and stored in Office 365.

 

I would make sure that you have a onmicrosoft account set in the tenant as a global admin before un-federating.

 

 

 

 

ID Fix is useful for find issues with Data in AD before syncing with office 365: https://docs.microsoft.com/en-us/office365/enterprise/install-and-run-idfix

 

This might give you an idea on the field looks like they use Email Address from Unify: https://support.rm.com/NewsAndAlerts.asp?cref=NWS3442877&Referrer=Portal&nav=0

ok so the users password will not actually be stored in office 365 as its being redirected to RM unify for authentication? So this means once rm is removed from federation all users would get new passwords? Marvellous if thats the case as how do i get the passwords to the users if rm has gone.!

 

RM is so complicated so say the least with what i've found when decommissioning RM servers.

Posted
ok so the users password will not actually be stored in office 365 as its being redirected to RM unify for authentication? So this means once rm is removed from federation all users would get new passwords? Marvellous if thats the case as how do i get the passwords to the users if rm has gone.!

 

RM is so complicated so say the least with what i've found when decommissioning RM servers.

 

So if your users match up and you have password sync turned on in Azure AD connect it will use the AD passwords for their accounts. I guess that AD password currently sync to RM unify ?

Posted
So if your users match up and you have password sync turned on in Azure AD connect it will use the AD passwords for their accounts. I guess that AD password currently sync to RM unify ?

 

Yes, the AD password syncs to RM unify for 365 login.

Posted
No from the look at their documents: https://support.rm.com/NewsAndAlerts.asp?cref=NWS3442877

 

 

Do passwords synchronise between RM Unify and Office 365?

No. Although AD Sync synchronises passwords from your local network to RM Unify, there is no passing, or synchronising, of passwords on to Office 365.

 

When Office 365 is federated to RM Unify, it is RM Unify which authenticates your login and passes an authentication token to Office 365 in order to allow access to your account (this is single sign-on, or SSO). Office 365 itself does not know, and does not need to know, your password.

 

When configuring a mail client with your Office 365 credentials, you enter your Office 365 email address and your RM Unify password. Again, it is RM Unify which authenticates your login and passes a token to Office 365 in order to allow your mail client access to your Office 365 mailbox.

 

Although an administrator may be able to reset the password of a federated user using the Office 365 Admin Centre, the user's password held by RM Unify takes precedence. The user will not be able to authenticate to Office 365 services unless they use their RM Unify password.

 

Additionally, a federated user will not be able to change their own password from within Office 365 and instead they will see the following message: "Your organisation doesn't allow you to change your password on this site. Please change your password according to the method recommended by your organisation".

 

So am i correct in the following:

- 1st step - remove RM federation - once done, no users will be able to login using AD password

- INstall MS AD Sync tool and run sync

- Once sync completed, passwords will sync from AD to 365 and users will be able to login again.

 

What will the tool use to match local users to existing 365 users, as in each AD users account their email address is not their UPN suffix and email address is not in AD either.

Posted (edited)
So am i correct in the following:

- 1st step - remove RM federation - once done, no users will be able to login using AD password

- INstall MS AD Sync tool and run sync

- Once sync completed, passwords will sync from AD to 365 and users will be able to login again.

 

What will the tool use to match local users to existing 365 users, as in each AD users account their email address is not their UPN suffix and email address is not in AD either.

 

Does the start of the UPN match their username in Office 365 ? as adding in the domain suffix is quite easy: https://docs.microsoft.com/en-us/office365/enterprise/prepare-a-non-routable-domain-for-directory-synchronization

Edited by willtech
Posted
Just found this:

RM Unify - Attributes used by RM Unify and Office 365 https://support.rm.com/TechnicalArticle.asp?cref=TEC4699981

 

Office 365: If mail attribute** not configured in RM Unify AD Sync, it will be generated internally by RM Unify, using sAMAccountName@O365 domain

brill thank you currently i believe the upn is the same as their username @ domain.internal so I could change this upn to be the proper email domain.

can the ms sync tool be run in simulate mode first to see what would happen before running properly before I decomission rm

Posted (edited)
brill thank you currently i believe the upn is the same as their username @ domain.internal so I could change this upn to be the proper email domain.

can the ms sync tool be run in simulate mode first to see what would happen before running properly before I decomission rm

 

Their is a powershell script to move over the domain suffixes: https://docs.microsoft.com/en-us/office365/enterprise/prepare-a-non-routable-domain-for-directory-synchronization#you-can-also-use-windows-powershell-to-change-the-upn-suffix-for-all-users

 

Their is a staging mode in Azure AD Connect https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sync-staging-server

 

Also useful in the future is assigning licences by group: https://docs.microsoft.com/en-us/azure/active-directory/users-groups-roles/licensing-groups-assign

 

And if you are interested SSO: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-sso

Edited by willtech
  • Thanks 1
Posted

To confirm a few things from experience of doing this.

RM Unify does not sync passwords to Office 365, if you remove federation, you will need to assign people passwords until you link up AD Connect.

There is something called Soft Match and Hard Match when adding AD Connect. Soft Match is based on the UPN which has to be exact between AD and Office 365. You might decide to match based on the mail attribute in local AD to Azure AD UPN so you can keep the UPN the local domain name and save a little hassle.

For hard match, there is a ID that is placed on the user that matches the source it is coming from (the sync source). RM Unify will have a different ID for the user as AD will. in Azure AD this attribute is the ImmutableId. For a hard match, clear this attribute after you have turned dirsync services off in Azure AD, then add the objectid of the Azure AD user to the matching user you want. The objectid need converting to Base64 code.

 

Hard match will give you a higher chance of a success rate of a match . YOu can script all this ready to run and do it as an over night process.

 

oh and don't forget to turn password sync on when installing AD Connect

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...