Jump to content

Google admin asks 365 Admins a question....


Recommended Posts

Posted

Ok a bit of history, We're a Google site not a 365 site, staff don't have 365 accounts created for them. However, many moons ago it was discovered that lots of staff had managed to register their Google email addresses against our 365 tenant. All services are disabled for those that have managed to do this. We had to "claim" and prove ownership of our domain in 365 admin to enforce these restrictions on the accounts.

 

The restriction was put in place and services disabled as staff were using 365 apps and were storing data there. It was a "No you should be using Google where it can be managed and controlled efficiently", awesome, one less job for me......

 

However, we'd had a couple of scenarios now where staff have been granted "access" to 3rd party systems or onedrives shared from other schools. These systems require you to login in with a microsoft account which is blocked by our settings.......

 

One email exchange from a supplier was "Can you create an account for user X in your Microsoft tenet please" I explained they dont/shouldn't be using Microsoft's accounts. They explain that i could just enable microsoft authentication against the email address (Gmail) that they have setup on their end...... i asked if they support other "SSO" methods such as Google, They said no, their platform doesn't support it.

 

We've also had a staff member today say they have tried to access a onedrive share from school X, but it wont allow her to log in with her (Gmail) email address. She has confirmed school X has added her email to the share.... I assume our restriction is blocking this.

 

Can you 365 Admins explain what they are referring to... as it doesn't make much sense to me. Can i enable authentication so they can access/use a platform without granting them access to the Microsoft accounts directly........ i'm not even sure that makes sense in my own head now!

Posted
If you are using Google as your primary ID you could federate your gmail domain with your 365 tenant. I have had to to this so staff can use O365 on their Chromebooks to access resources that only work correctly in PowerPoint *cough*Whiterose*cough*
Posted
You can configure your M365 accounts to not have mail boxes, or access to apps I suspect. Still leaves the onedrive sharing problem though, not sure how that would work
Posted
it was discovered that lots of staff had managed to register their Google email addresses against our 365 tenant.

 

 

I dont understand this bit and may well be the crux of the issue. Accounts in an O365 tenant can be guests or a member account. Guests would be accounts typically from partner organizations who have their own ID system, and that could be another Microsoft 365 environment, gmail or any email address.

 

You cannot have a member account with a gmail address. A gmail guest account looks something like

 

gmiailuser_gmail.com#EXT#@tennantname.onmicrosoft.com

If this is what we are talking about, you cannot use that to access this system as they will be expecting a Microsoft Azure AD, sorry, Entra ID account

 

You can enable your users to use the O365 account for authentication to third parties only, you should a) set the domain as 'internal relay' so any email generated in O365 gets sent to gmail b) dont license the users for a mailbox. You may want to consider MFA (conditional access) even if it's beleive they are only accesing data in the third party.

Posted

We're primarily a Google school, too, but have an M365 tenancy with accounts for everyone. Accounts are synced using Azure AD Connect (or whatever it's new name is). We minimise the use of 365 but there are a few things where we make use of it (PowerBI being one). It also means that external Teams invitations are a little smoother.

 

The way we do it is to have a staff group on 365, apply the 365 faculty license to that group and then toggle the various apps on/off within that.

 

Azure > Microsoft Entra ID > License > All products > Office 365 A1 for faculty > Licensed groups > {assign to a suitable group to include all your staff} > Select the group name > Licenses > Office 365 A1 for faculty > toggle all your options to disable/enable features (the key one for you being to disable 'Exchange online').

 

You can do that same for student accounts, if you're also including them in your tenancy.

 

Not sure if that solves your SharePoint/OneDrive shadow file storage problem.

Posted
However, many moons ago it was discovered that lots of staff had managed to register their Google email addresses against our 365 tenant.

I also have this happening. How are staff able to create accounts in our 365 domain? Surely it should only be an admin that can create accounts.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...