Jump to content

Recommended Posts

Posted

Hi,

 

bit late to the party as usual but did my first test install / upgrade today to

Office LTSC 2021 following this guide

 

https://learn.microsoft.com/en-us/deployoffice/ltsc2021/deploy

 

actually went better than expected :) Included my xml config below.

 

We are still on windows 10 1809 LTSC with Office pro plus 2016.

 

Was thinking about going with latest i.e. Microsoft 365 Apps but as I read it

that isn't supported on windows 10 1809 LTSC, and Office LTSC 2021 is (until Oct 2026)

https://www.microsoft.com/en-gb/microsoft-365/microsoft-365-and-office-resources

 

Couple of things: on starting e.g. word it auto "signs in" with the users domain account.

(i.e. the account used to log on to the PC). We have on-premise AD only at the moment.

I can't find any way of stopping this. Is it possible e.g. via group policy ?

 

Only solution I've found is to sign out and then sign in with the users office 365 account

I also signed in to the standalone one drive client (was already installed on PC but not signed in).

Both of these sign ins gave me an error :

 

sign-err.png

 

but word does seem to be working and can open files from one drive.

 

Also not sure about values for DeviceBasedLicensing and SharedComputerLicensing

What is the difference anyway as they sound quite similar?

 

I thought we could use SharedComputerLicensing but not DeviceBasedLicensing as you need EES license for

that and we're on OVS. Just wary of getting caught out by the "5 device logins limit"

 

My auto-generated xml has 0 (these options were greyed out in the wizard)

which is the default e.g. if you omit them (https://learn.microsoft.com/en-gb/deployoffice/office-deployment-tool-configuration-options)

I also tried with DeviceBasedLicensing set to 1 just to see what would happen and install worked so maybe that setting

is not used / relevant for an LTSC/perpetual install?

 

 
   
     
     
     
     
     
     
     
     
   
 
 
 
 
 
 
 
 
 
   
   
   
 
 

Posted

You don’t get any KMS keys by default anymore, but you can request them still. Did this recently for office 2021

 

Regarding the OP, those licenses are for 365 not 2021 (if you used the generator tool it adds them all in)

 

Shared is still checking that the user who’s logged on is licensed to use 365 (eg a guest account wouldn’t be able to launch it)

Device is l licensing the device, so whoever logs on can use it even without the licenses

 

But 2021 is still MAK or KMS related so leave those as empty/0

 

Regarding the logins, it should default to 365 logins not AD - so you might have it not setup in AD where the login/email/upn matches their 365 accounts to sign in automatically

 

Steve

  • Thanks 1
Posted

Thanks Steve21 that is helpful

 

those licenses are for 365 not 2021 (if you used the generator tool it adds them all in)

 

yes I used the generator tool, you mean the DeviceBasedLicensing and SharedComputerLicensing are only

relevant for "latest" ie. microsoft 365 apps for enterprise ?

 

So it sounds like if I go 2021 with a MAK key I effectively get "device based" e.g. anyone can log on to

a device and use word 2021 LTSC without signing in? I.e. won't get bitten by "5 device logins limit" ?

 

If they do sign in (to word) with their 365 account they will also be able to access one drive / teams etc, I guess at this point

it would check their license but even the free A1 plus for faculty would allow access to onedrive/ sharepoint ?

 

Regarding the logins, it should default to 365 logins not AD - so you might have it not setup in AD where the login/email/upn matches their 365 accounts to sign in automatically

 

No I don't have anything in the on-premise AD to do with 365 accounts !

We aren't azure hybrid / don't have AD connect set up .

 

Are you saying I can still fix by adding user's 365 accounts to their local AD user ?

 

Which field/attribute do I need to add it to in the user's properties (in ADUC console) ?

e.g. typically we have in AD:

user logon name: stafftest1

samaccountname: stafftest1

E-mail: not populated

UPN (from attribute editor): [email protected]

 

and their 365 account would be

[email protected]

Posted
Is it a problem their end or am I doing something wrong?

It's working for me. Here's the direct link to the EXE...

 

https://download.microsoft.com/download/2/7/A/27AF1BE6-DD20-4CB4-B154-EBAB8A7D4A7E/officedeploymenttool_16327-20214.exe

  • Thanks 1
Posted

at first I was a bit dubious, "why can't they just give me an msi ?" but I can see how using the

ODT with custom xml files could be quite powerful.

 

Can anyone clarify/confirm on the licensing? e.g. from my last post above :

 

So it sounds like if I go 2021 with a MAK key I effectively get "device based" e.g. anyone can log on to

a device and use word 2021 LTSC without signing in? I.e. won't get bitten by "5 device logins limit" ?

 

If they do sign in (to word) with their 365 account they will also be able to access one drive / teams etc, I guess at this point

it would check their license but even the free A1 plus for faculty would allow access to onedrive/ sharepoint ?

Posted
at first I was a bit dubious, "why can't they just give me an msi ?" but I can see how using the

ODT with custom xml files could be quite powerful.

 

Can anyone clarify/confirm on the licensing? e.g. from my last post above :

 

Yep, same as if it was 2019 etc :) It’s only 365 that makes it different

 

Steve

  • Thanks 1
Posted
Couple of things: on starting e.g. word it auto "signs in" with the users domain account.

(i.e. the account used to log on to the PC). We have on-premise AD only at the moment.

I can't find any way of stopping this. Is it possible e.g. via group policy ?

 

I have a similar but slightly different issue with it that I posted about a while ago, but didn't really get any answers for, so it's stopped my plans for a roll-out' for the time being....

 

It seems to be the 'Office' way, but a bit like you I wanted machine installs (although it's doubtful that our users will go into 5 device territory anyway as we have 1-1 teacher and admin devices).

 

Anyway, bear with me for relevance...

 

When I open Outlook, I have 4 accounts... 1 of which I sign in with an 80s-style grey box (no problem), but 3 of which require some sort of sign-in to a portal (Modern Auth...?).

 

This is where it gets complicated as I think the 'grey box' account one must be some sort of Exchange set-up and the portal one goes to O365.... I have also tried turning off Modern Auth on these accounts (O365 tenancy), but found I couldn't even sign-in then and it got too complicated to mess with a 'live' prod system...

 

So, once all signed-in to the email accounts in Outlook everything is fine, but then I open Excel and find I have been signed into those as well (with the first account I sign-in to Outlook with)...

 

However, if I sign-out of that Excel still works fine obviously and that is how I want them to work...

 

Outlook vs Office.jpg

 

Unfortunately, I will now find I am signed-out of that account in Outlook AND signed-in to Excel with the next account I used for Outlook!!!!!

Posted

What’s the actual issue? :p that seems to be working as expected

 

It you sign into any office apps it has that account across them all. If you sign out of one in reverse the same happens

 

You can be signed in with multiple accounts and you just get the drop down profile chooser in office etc

 

Steve

Posted (edited)

Actually, you're right.... I'm not sure it actually creates any 'issue' as such and this may be how it is expected to work, but coming from Office 2016 where this didn't happen it just surprises me that it feels it needs to now, it was more a question of what's the point?

 

I also really see it as 'not' signing into to Office if you see what I mean...? I'm just using Outlook to access various email accounts in a combined format... and I'm signing into to various email accounts through Outlook, I'm not signing into Office... maybe that's just me? I guess it comes from the type of email account I'm signing into (as I believe they are O365 accounts), the 'Exchange' type account (grey box auth) doesn't appear in the other Office apps.

 

I don't see the need for it and I guess this may be as we don't use all the fully featured 'benefits' this behaviour brings. It doesn't sync with OneDrive (as we don't have it), there aren't any fancy personalised templates, or customisations, nothing that 'signing-in' to Office improves for us.

 

It doesn't need to be signed in to validate a license or account as it's activated by a MAK key... we don't even really have control of these accounts as such, as they were (in fact the whole MS tenancy was) created for us purely for email accounts by a 3rd party provider. I can't get the SLT to move away from this set-up and so there is no point in using any O365 apps from it considering the disaster that would ensue from it's removal at some point in the possible future (in fact this is one of the reasons I've always preferred a static on-prem solution - it's bad enough that when the internet goes down they can't email or show YouTube videos, but if I were to add to that no (O365) office apps and no (OneDrive) file access.... that and the fact that I'm stuck in the past and don't trust that new fangled cloud thingy...), or trying to get a whole new tenancy created and have email from one source and O365 from another.

 

So anyway there is no reason I can see for 'signing-in' to Microsoft Office (especially as it uses the accounts I've mentioned).

Edited by Koldov
Posted (edited)

Koldov, sounds like your staff are mainly using office to edit docs locally / on server share ?

so in that case Office LTSC 2021 will work fine until end of support in Oct 2026 and like you

say no need to sign in to office. I'm trying to move stuff to cloud / get rid of server share

so different set of issues!

 

After Oct 2026 we may all have to go to 365 anyway! e.g. take a look here:

https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2OqRI

 

Surprised to see windows 10 EOS is Oct 25 so will people be "forced" to win 11 ?!

 

We are on windows 10 LTSC 2019 which is ok until 2029 :) but assumed "n/a" means 365

not officially supported (though I installed it as a test and it "seemed" ok with limited testing)

But think I'll probably go with Office LTSC 2021 as that is officially supported until Oct 2026.

Edited by mrstrong
Posted

done some testing and it looks like office auto signs in with the UserPrincipalName which for us is

e.g. [email protected]

 

So I added a UPN suffix to domain and updated a test user's UPN as described here:

https://learn.microsoft.com/en-us/microsoft-365/enterprise/prepare-a-non-routable-domain-for-directory-synchronization?view=o365-worldwide

 

e.g. UPN now [email protected]

 

this then allows log in to PC via UPN or SamAccountName and office auto signs in with UPN

but of course this doesn't help as we are not syncing on-premise AD to azure :doh:

(need to look into AD connect)

 

What I have found is if you sign out it stays signed out

(https://learn.microsoft.com/en-us/microsoft-365/troubleshoot/sign-in/office-365-users-not-signed-in-office)

 

Also if you sign in to the OneDrive desktop app first, then open word, word auto signs you in with

your 365 account (not your UPN) so that is a manual "fix" for now :)

Posted

done a few installs now, just manually running this .bat:

 

pushd \\server\share\Office2021
setup /configure config-1.xml
popd

 

any ideas and how to mass deploy ?

 

I suppose a computer startup script via GPO would take too long ?

 

Thought about getting teachers to run the .bat themselves (when its convenient for them) but

as the .bat needs local admin and runs from a share not sure if that is possible.

Think there used to be a hack where you created a shortcut and set it to run as admin from properties ?

Posted

tried a computer startup script but it didn't work:

it left office 2016 half uninstalled / in an inconsistent state.

I was unable to manually remove it from control panel afterwards.

Had to use the ms office scrub tool to get rid of it.

 

I was running setup.exe direct from script perhaps start /wait setup.exe

would have worked but just found a thread on here about using scheduled task

so will try that next.

Posted

done some more testing based on a scheduled task at startup

from here http://www.edugeek.net/forums/windows-11/231620-office-2021-install-via-gpo-2.html#post1985610

 

Having issues with it not working on laptops over wifi (task scheduler return code 2147942401)

I'm installing from a server though, i.e. not robocopying to client so maybe that would fix.

 

Also tried this approach https://lwnetworks.org/deploy-office-2019-via-gpo/

i.e. a scheduled task at logon and that works even over wifi.

 

Only issue is as they both run as SYSTEM you can't display any messages / progress to user

i.e. command prompt running the .bat file doesn't display and

has no effect.

 

Not sure what would happen if users try to use the old version of office / start new one mid install ?

I do have

 

Slowest install so far is nearly 20 minutes!

 

Toying with idea of letting users install when its convenient for them, e.g. email saying double click this bat file

and giving them a local admin user/pass :eek:

Posted
Koldov, sounds like your staff are mainly using office to edit docs locally / on server share ?

so in that case Office LTSC 2021 will work fine until end of support in Oct 2026 and like you

say no need to sign in to office. I'm trying to move stuff to cloud / get rid of server share

so different set of issues!

 

After Oct 2026 we may all have to go to 365 anyway! e.g. take a look here:

https://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2OqRI

 

Surprised to see windows 10 EOS is Oct 25 so will people be "forced" to win 11 ?!

 

We are on windows 10 LTSC 2019 which is ok until 2029 :) but assumed "n/a" means 365

not officially supported (though I installed it as a test and it "seemed" ok with limited testing)

But think I'll probably go with Office LTSC 2021 as that is officially supported until Oct 2026.

 

I'm assuming reading that matrix, that Office 2019 will be unable to connect to onedrive/sharepoint after this October?

Posted
I'm assuming reading that matrix, that Office 2019 will be unable to connect to onedrive/sharepoint after this October?

 

Correct, we're also in the process of moving to 2021 now.

Posted
I thought I had until 2025 in totality but it looks like I might have to bring that forward then. Windows 11 rollout bundled with 2021 Office might be the way to go for us for now.
Posted
I thought I had until 2025 in totality but it looks like I might have to bring that forward then. Windows 11 rollout bundled with 2021 Office might be the way to go for us for now.

Windows Server 2012 R2 is also EOL on the same date as Office 2019

 

2025 for Windows 10 22H2 - I am really hoping they extend the support though..

Posted
So office 2013 pro got about 8 years, but Office 2019 gets about 4 years, is that correct?

 

Some of my schools have already jumped to Google, this might push the other schools over.

 

I'm considering bringing this up to my SLT. Microsoft keep giving me more and more reasons.

Posted

Works out at 5 years.

 

I’m having decent success rolling out 2021 with a startup script on 22H2. It is working on 20H2 as well but that’s EOL so will update them both. Thankfully I’ve done a couple of suites already.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...