Jaan Posted October 17, 2023 Posted October 17, 2023 Ok a bit of history, We're a Google site not a 365 site, staff don't have 365 accounts created for them. However, many moons ago it was discovered that lots of staff had managed to register their Google email addresses against our 365 tenant. All services are disabled for those that have managed to do this. We had to "claim" and prove ownership of our domain in 365 admin to enforce these restrictions on the accounts. The restriction was put in place and services disabled as staff were using 365 apps and were storing data there. It was a "No you should be using Google where it can be managed and controlled efficiently", awesome, one less job for me...... However, we'd had a couple of scenarios now where staff have been granted "access" to 3rd party systems or onedrives shared from other schools. These systems require you to login in with a microsoft account which is blocked by our settings....... One email exchange from a supplier was "Can you create an account for user X in your Microsoft tenet please" I explained they dont/shouldn't be using Microsoft's accounts. They explain that i could just enable microsoft authentication against the email address (Gmail) that they have setup on their end...... i asked if they support other "SSO" methods such as Google, They said no, their platform doesn't support it. We've also had a staff member today say they have tried to access a onedrive share from school X, but it wont allow her to log in with her (Gmail) email address. She has confirmed school X has added her email to the share.... I assume our restriction is blocking this. Can you 365 Admins explain what they are referring to... as it doesn't make much sense to me. Can i enable authentication so they can access/use a platform without granting them access to the Microsoft accounts directly........ i'm not even sure that makes sense in my own head now!
PrimaryNetMan Posted October 17, 2023 Posted October 17, 2023 If you are using Google as your primary ID you could federate your gmail domain with your 365 tenant. I have had to to this so staff can use O365 on their Chromebooks to access resources that only work correctly in PowerPoint *cough*Whiterose*cough*
mavhc Posted October 17, 2023 Posted October 17, 2023 You can configure your M365 accounts to not have mail boxes, or access to apps I suspect. Still leaves the onedrive sharing problem though, not sure how that would work
chaplic Posted October 23, 2023 Posted October 23, 2023 it was discovered that lots of staff had managed to register their Google email addresses against our 365 tenant. I dont understand this bit and may well be the crux of the issue. Accounts in an O365 tenant can be guests or a member account. Guests would be accounts typically from partner organizations who have their own ID system, and that could be another Microsoft 365 environment, gmail or any email address. You cannot have a member account with a gmail address. A gmail guest account looks something like gmiailuser_gmail.com#EXT#@tennantname.onmicrosoft.com If this is what we are talking about, you cannot use that to access this system as they will be expecting a Microsoft Azure AD, sorry, Entra ID account You can enable your users to use the O365 account for authentication to third parties only, you should a) set the domain as 'internal relay' so any email generated in O365 gets sent to gmail b) dont license the users for a mailbox. You may want to consider MFA (conditional access) even if it's beleive they are only accesing data in the third party.
jthompson Posted October 23, 2023 Posted October 23, 2023 We're primarily a Google school, too, but have an M365 tenancy with accounts for everyone. Accounts are synced using Azure AD Connect (or whatever it's new name is). We minimise the use of 365 but there are a few things where we make use of it (PowerBI being one). It also means that external Teams invitations are a little smoother. The way we do it is to have a staff group on 365, apply the 365 faculty license to that group and then toggle the various apps on/off within that. Azure > Microsoft Entra ID > License > All products > Office 365 A1 for faculty > Licensed groups > {assign to a suitable group to include all your staff} > Select the group name > Licenses > Office 365 A1 for faculty > toggle all your options to disable/enable features (the key one for you being to disable 'Exchange online'). You can do that same for student accounts, if you're also including them in your tenancy. Not sure if that solves your SharePoint/OneDrive shadow file storage problem.
TwistedHelixis Posted October 23, 2023 Posted October 23, 2023 However, many moons ago it was discovered that lots of staff had managed to register their Google email addresses against our 365 tenant. I also have this happening. How are staff able to create accounts in our 365 domain? Surely it should only be an admin that can create accounts.
jthompson Posted October 23, 2023 Posted October 23, 2023 Have a look at Azure > Microsoft Entra ID > User settings. The toggles under the heading "Default user role permissions" might be governing this behaviour.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now