jamesbmarshall Posted October 15, 2012 Posted October 15, 2012 Can anyone tell me what the limitations are with using Dirsync as appose to using FIM. FIM isn't supported. (By which I mean that there is no user-configurable management agent for FIM supplied by Microsoft. DirSync is the only solution unless you want to engage the services of a Microsoft partner) What's the concern over using DirSync?
staylor1972 Posted October 16, 2012 Posted October 16, 2012 so DirSync is the only way to go then! i look at this link Improving Office 365 manageability using Forefront Identity Manager 2010 | TechNet Video One of the things it was saying was that there were limitations with Dirsync and a better option was to use FIM! Not installed or tested Dir Sync yet! does it give you the option of syncing individual OU's?
gshaw Posted October 16, 2012 Posted October 16, 2012 (edited) I'm still a bit confused about the Sharepoint My Site for students (effectively replacing SkyDrive Office Web Apps, which were really easy to use) as every time I've trialled 365 I can never find an easy way to get there from the welcome screen. It seems to be obsessed with Team Sites (which I'm not bothered by right now) but doesn't focus on the user's personal space (which they definitely need!) Have I missed something really obvious? Edit: OK I've found the link https://yourdomain-my.sharepoint.com/ but why isn't this on the front page when you login and can I add the link? Edited October 16, 2012 by gshaw
jamesbmarshall Posted October 16, 2012 Posted October 16, 2012 Not installed or tested Dir Sync yet! does it give you the option of syncing individual OU's? No* - DirSync does a sync of your full AD. You don't have to provide licences or services to every user it synchronises across though. FIM is a more flexible solution, but there is no freely available Microsoft-supported management agent for FIM. For this you'd need the services of a partner. *sort of. Edit: OK I've found the link https://yourdomain-my.sharepoint.com/ but why isn't this on the front page when you login and can I add the link? You can't change the links unfortunately; take a look at the Office 365 preview if you're interested to see where the future lies; I believe your problem is addressed somewhat.
staylor1972 Posted October 16, 2012 Posted October 16, 2012 Thanks for the quick reply James! oh and the really useful link! Steve
gshaw Posted October 16, 2012 Posted October 16, 2012 (edited) You can't change the links unfortunately; take a look at the Office 365 preview if you're interested to see where the future lies; I believe your problem is addressed somewhat. Installed this on my Windows 8 laptop the other day to get Office 2013, looks more like the Outlook.com redesign which is cool, although not sure if it's just my demo account but I don't have any services apart from email on there at the moment. Edit: makes sense now, 365 ProPlus is just the local office and you need to be in the 365 Enterprise demo to get everything... For anyone who doesn't fancy setting up a demo account just done a quick blog post on the 365 Preview, I'm impressed http://gshaw0.wordpress.com/2012/10/16/office-365-enterprise-preview-hands-on/ Edited October 16, 2012 by gshaw 2
Jollity Posted November 4, 2012 Posted November 4, 2012 (edited) I did my second update to Office 365 last week, on a domain that was actually in use. The actual update process went very smoothly: each of the two stages only took under half an hour (with under 300 users). However the overall migration was not smooth, because the eduupgrade.office365.com site to reset passwords failed to work at all. I was able to log into the site with my test users, using their Live@Edu passwords, but it would not actually let then change the password. I got an error "We can't process your request at the moment" with detail "We are sorry we can't process your request at this time". Microsoft support could not come up with anything, at least not within that afternoon, so I had to arrange to distribute temporary passwords after all. The problem that I mentioned in my earlier post was definitely occurring consistently: if a user went to the Office 365 login page they would be presented with their email address saved from Live@edu, but if they clicked on it to log in, it would attempt log in to Live@Edu and fail. I also found that if the user had checked the box to save their password on Live@edu, they would get stuck in a redirect loop (with the page blank and repeatedly refreshing) on going to the Office 365 login page - clearing cookies fixes that. Edited November 4, 2012 by Jollity 2
zag Posted November 5, 2012 Author Posted November 5, 2012 However the overall migration was not smooth, because the eduupgrade.office365.com site to reset passwords failed to work at all. Sounds like a nightmare I can't even load that site at the moment!!
Jollity Posted November 5, 2012 Posted November 5, 2012 I can't even load that site at the moment!! It needs an https. https://eduupgrade.office365.com will at least load for me. It was after logging in that the problems started! 1
zag Posted November 22, 2012 Author Posted November 22, 2012 @jamesbmarshall would you recomend I start asking users to change their passwords now to the new requirements or wait until the actual changeover? Our SMT are asking me for a date of our change over and pressuring me to "prepare" for it but i'm a bit lost on what timelines Microsoft has in mind. I don't want to go early after hearing the problems above to be honest.
vikpaw Posted November 23, 2012 Posted November 23, 2012 there's not much point changing your passwords now as they'll have to change again and it will confuse them, even though you could keep the same password if it meets the complexity requirements. it's worth checking the docs about what dns changes might be required, and if it works start getting them used to the new domain, and don't forget to clear out all cookies, so a little training on that wouldn't go amiss.
Michael Posted February 20, 2013 Posted February 20, 2013 I've upgraded several schools from Live@Edu to Officee 365. From an admin perspective it was very smooth, but I've had a lot of users unable to login succesfully. I've updated licenses so pupils and staff are using Exchange A2 (top of my head). I've then set the homepage to login.microsoftonline.com but I've seen two problems - As soon as the user navigates to login.microsoftonline.com they receive an error 'Sorry that didn't work' and they cannot do anything other than close the browser. Previously they would of logged straight into outlook.com (I'm speculating). Secondly, the user sees just their e-mail address on the Office 365 page. Clicking on their e-mail address stupidly sends them to outlook.com which of course no longer works. The fix for this is to click 'Sign in with a different user ID'. This is going to create me a big headache to sort out. Any easy fixes anyone can share?
jamesbmarshall Posted February 21, 2013 Posted February 21, 2013 Have you tried deleting all the cookies? Users can still login at outlook.com as long as they use the correct structure of http://outlook.com/yourdomain.com.
Michael Posted February 21, 2013 Posted February 21, 2013 @jamesbmarshall - I could get users to do that, but why is it happening in the first place do you think? I migrated three sites at the same time, all with the same/similar problems. When the user sees 'sorry that didn't work' Microsoft provide no help to the end user to get back to the Office 365 login page. As as I say, all they can do is close the browser. I think this is why it's creating a lot of confusion. Also what about when users click their e-mail address which is already populated (on the Office 365 login page) they're re-directed to outlook.com? Surely this has to be a bug?
jamesbmarshall Posted February 21, 2013 Posted February 21, 2013 If it has cached credentials from before the upgrade then that may be part of the problem. The upgrade involves changing the identity platform to Office 365 - hence clearing the cookies to see if that helps. If you've had this experience with a few upgrades then I'd recommend flagging this with support - if there is a problem that needs addressing in the platform they'll need a service request (or several if it affects lots of customers) in order to track it. My gut feeling is that clearing cookies will solve it. 1
Jollity Posted February 21, 2013 Posted February 21, 2013 I've upgraded several schools from Live@Edu to Officee 365. From an admin perspective it was very smooth, but I've had a lot of users unable to login succesfully. I've updated licenses so pupils and staff are using Exchange A2 (top of my head). I've then set the homepage to login.microsoftonline.com but I've seen two problems - As soon as the user navigates to login.microsoftonline.com they receive an error 'Sorry that didn't work' and they cannot do anything other than close the browser. Previously they would of logged straight into outlook.com (I'm speculating). Secondly, the user sees just their e-mail address on the Office 365 page. Clicking on their e-mail address stupidly sends them to outlook.com which of course no longer works. The fix for this is to click 'Sign in with a different user ID'. This is going to create me a big headache to sort out. Any easy fixes anyone can share? Your experience is very similar to mine. The first one could be from those who have a saved user password from Live@Edu. The only way I found to make it work again was to delete cookies, as jamesbmarshall says. We also had a couple of staff members with links to personal hotmail accounts, which every time they used, next time they went to Office 365 it would get stuck in an infinite redirect loop until cookies were cleared. I think we fixed by recreating the hotmail links. Your second issue occurred consistently when there was a saved user name from Live@Edu - you could tell that the saved login name would not work because it said something about logging in to partnerdomain under the user name. As you say, it is then necessary to use "sign in with a different user ID". I just put up a detail help file to walk the staff through this and had the IT teacher talk the pupils through it. Another one that we saw was that after Office 365 had been added to favourites, the favourite would sometimes send the user back to the Live@Edu login page for no apparent reason. I never got to the bottom of that - it seems to have gone away on its own. 2
Michael Posted February 25, 2013 Posted February 25, 2013 Just to confirm it's definitely a cookie issue. Question is, why do Microsoft think it's best two slightly different e-mail solutions share the same cookies? Live@Edu and Office 365 should have separate cookies to avoid these kind of problems.
vikpaw Posted February 25, 2013 Posted February 25, 2013 I think it's all been confused because live@edu was basically hotmail, and then office365 was separate, and now hotmail is becoming outlook, but you can use outlook.com/domain for office365 but only if you have an account, but your original account's skydrive will stay separate, and the password for that won't change, but you do have to change your password for O365, so then, no hang on, let me start again... I blame the EU and cookie legislation, that's easier!
Michael Posted March 7, 2013 Posted March 7, 2013 Well two weeks on things have certainly settled. I ended up creating a user guide so staff could delete cookies themselves. Next question is, when's the new Office 365 2013 refresh arriving? I think new customers can sign into it, but when are existing Office 365 2010 customers being upgraded? I hope the URL will be staying the same this time!!!
jamesbmarshall Posted March 7, 2013 Posted March 7, 2013 Soon! Office 365 Service Upgrade Center for Enterprise - Office 365 Service Updates - Office 365 - Microsoft Office 365 Community - check this out for a view of how things are for enterprise customers; I can't see it being wildly different for education. 2
Michael Posted March 11, 2013 Posted March 11, 2013 Sounds all good. Do you have any screenshots of Exchange 2013 Office 365?
jamesbmarshall Posted March 12, 2013 Posted March 12, 2013 I don't have any screenshots handy, but if you check out the blog (UK Education Cloud Blog - Site Home - MSDN Blogs) there's lots of information on the new Office 365 Education.
Jollity Posted March 12, 2013 Posted March 12, 2013 Sounds all good. Do you have any screenshots of Exchange 2013 Office 365? I was going to post some for you, but then I remembered the trial agreement says " you shall treat the design and performance of the Online Services that are accessible to you only via password protected access and any documentation or materials we make available to you under this agreement as confidential and shall not disclose them to any third party except in the furtherance of the parties' business relationship with each other." Not sure if that means I cannot put up screenshots.
Michael Posted March 13, 2013 Posted March 13, 2013 That's fair enough but thank you! I was just curious how different it is compared to Office 365 2010
staylor1972 Posted March 13, 2013 Posted March 13, 2013 (edited) i've set up a trial Office365 account so i can try and set up SSO with ADFS2.0 server are installed and i'm getting the xml page like i should. I'm using this article to help Set up a trust between AD FS and Windows Azure AD. I'm trying to get the domain to federate but as of yet i'm having no luck. i'm putting in the following cmd Convert-MsolDomainToFederated –DomainName our domain name but get the following error message: Convert-MsolDomainToFederated : You cannot convert the specified domain to use identity federation because the account you are currently signed in with is a member of the domain ourdomainname.onmicrosoft.com. Please sign in to the service using an account that is a member of the company administrators role and is not part of the domain ourdomainname.onmicrosoft.com, and then try again. At line:1 char:30 + Convert-MsoldomaintoFederated <<<< -DomainName ourdomainname.onmicrosoft.com + CategoryInfo : InvalidOperation: ( [Convert-MsolDomainToFeder ated], FederationException + FullyQualifiedErrorId : CannotConvertDomainToFederatedAsADomainUser,Microsoft.Online.Identity.Federation.Powershell.ConvertDomainToFederated I set up Dirsync thinking it needed one of our onpremises account to complete the conversion but get the same error message. Anyone any ideas??? I've logged a case with MS on the 28th febbut have not heard anything from them since last Thursday. i know its only a trial account that i've got but i'm trying to get all the things in place before we convert the domain over to Office 365. Any ideas would be greatly appreaciated!!! Edited March 13, 2013 by staylor1972
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now