Jump to content

jamesbmarshall

Members
  • Posts

    562
  • Joined

  • Last visited

Everything posted by jamesbmarshall

  1. I know it might feel that way, but I can promise you that education has most definitely not been left last. A huge number of customers have already received their service upgrades, with more and more going through all the time. You should receive notification very soon if you've not already. You can also check to see the status of your upgrade in the admin portal.
  2. I try not to chip in here unless I've got something pretty cool to say (which usually means it's in response to something people have asked for a lot!), but I thought I'd let you know that the default storage quota for SkyDrive Pro has changed to 25 GB per user: Microsoft UK Education Cloud Blog - Learn About Office 365 Education Hope it's useful to know!
  3. Try resetting the password for the user in any case, even if it hasn't or isn't due to expire. You'll need to run through the DirSync config again just to be on the safe side. I hit this issue the other day, bugged the hell out of me. Resetting the Office 365 user password sorted it.
  4. The best thing to do here is to contact Microsoft support. Support for Office 365 Education is free and 24x7 - you can log a service request via the admin portal, and from there you can also find the phone number.
  5. I have no experience with it, but Cloud Storage | Cloud-Integrated Storage | StorSimple could be a good option?
  6. Are you planning to deploy ADFS after the upgrade? Are you running OLSync at the moment?
  7. What scripts?
  8. I don't think Microsoft Support will do that (not ordinarily anyway). How do you handle your licensing at the moment, given that you have fully automated account creation? The steps above, broadly speaking, are what you need to build a script to assign sub-components of the A2 plan if you don't want to assign the full plan. It would be fairly straightforward to build a script that reads an attribute from your users (lets say you populate customAttribute1 with "student" or "teacher") and then assigns the correct workloads from that.
  9. I have some PowerShell snippets that can help... I'm in a call right now but will writ e it up when I'm done
  10. Obviously, Exchange Server rocks but there are very good reasons for going to Exchange Online. First, and foremost in the education world, is total cost of ownership. Forget feature differences, one is free and gives everyone a 25GB mailbox, and the other costs money for tin, licences, air con, power, disk space, backup, etc. Unless you're a really advanced Exchange customer and make extensive use of third party tooling that requires direct access to an Exchange server (i.e. to customise or extend the OWA experience), or some of the less well-known capabilities of Exchange, then Exchange Online can pretty much cover everything you need. It's possible to support custom address lists, address book policies and GALs. It can also handle auditing and investigation, bad word lists, transport rules, public folders, disclaimers, ActiveSync, archiving (some options cost though), etc. The list gets bigger and bigger with every iteration. If I had my network manager hat on (which is getting pretty dusty sitting in the corner looking neglected) and I had to pick between running a full-blown Exchange org on-prem, or moving it out to "the cloud" then I think it would be a no-brainer. AND if you are the type who has cold feet about the cloud, you can do Exchange Hybrid if you wanted to keep some users (i.e. staff) on-prem and some (i.e. students) in the cloud. The biggest pushback I hear about moving to an online provider is "what if my broadband goes down, my users still need to communicate, especially staff". My argument back is that if your broadband is that bad that it goes down that often then you have bigger problems to worry about, and Exchange Server is still a fantastic product.
  11. Nothing specific that I can share at the moment I'm afraid.
  12. Exactly, and like I say it would also reduce the local infrastructure burden and make it a lot easier to manage! Not yet, no. I'll let you have that one, as it's a good point. ADFS would be the only way to make this a bit easier for your users, and you can use smart links to redirect your users from, say, mail.llanfyllin-hs.powys.sch.uk directly to your ADFS servers, and straight into OWA rather than having to hit the Microsoft portal first and then get re-directed to your ADFS server. I just get twitchy when I hear people say ADFS in the same sentence as "one server" because it is the single point of failure, but if you're willing to manage the risks of doing it that way then go for it!
  13. Ok, with this in mind, I might ask what the point is in using ADFS? Only having 1 server, and not even for the purpose of integrated auth for your domain joined users, introduces a huge amount of risk when it comes to outages as all of your users are wholly reliant on that one server being available 100% of the time - not to mention the additional overheads associated with running extra servers, etc. If you just want users to have the same username and password in both places, in sync, and easy to manage then you can do this with just DirSync and Password Sync (via the latest version of the DirSync appliance). You don't need to maintain the ADFS piece. One server, doesn't have to be highly available, and it's practically zero admin. Much more elegant that a single ADFS server exposed to the web!
  14. How have you got ADFS configured? I have an ADFS environment, used purely for testing*, which is just one ADFS server configured for forms-based auth, and I can sign into the SkyDrive Pro iOS app with a federated user without issue on an iPod Touch (5th gen) from an external network. It's a quick-and-dirty test but it shows that the apps should work - have you contacted support about this issue? *It's actually two VM roles in Windows Azure IaaS hosting Windows Server 2012, ADFS 2.1, and DirSync. I use it to demo SSO capabilities with customers. It's not the best practice way to configure ADFS as I don't use a proxy. You should have your internal ADFS servers configured for integrated auth, and proxies for forms-based.
  15. If it's a widespread problem I'd suggest logging a support request. Maybe, maybe not. I am running Windows 8.1 Preview with IE11 and it works. I haven't tried any other browsers, and I don't have another PC running a different OS build to test it on - all I can say is that it works on my system. If you're having issues with Windows 7 and IE9 (both of which are fully supported), then support are there 24x7 to help with this type of thing. It might be something simple, and if it's not then customer feedback is important and support is the right channel to track the issue.
  16. This isn't the case; just tested selecting three documents and attaching in one go. Worked just fine. I can select multiple files using Ctrl or Shift. The new OWA experience, whether you like the more modern interface or not (and that's entirely subjective), does bring some pretty neat enhancements that people have asked for.
  17. You can route mail into and out of Exchange Online however you like, so you could continue to use your on-prem solution for now. You just need to set up connectors in EOP. You can also use EOP to protect your on-prem Exchange server too, if you like. If the plan is to remove the Barracuda appliance then it might be worth "architecting" it out of the equation early rather than trying to take it out later on; EOP can probably pick up most things you need unless you're doing anything particularly funky with your mail (like address re-write).
  18. If it helps build an argument, traffic is secured regardless of which protocol you use with Office 365: Settings for POP and IMAP access - Outlook - Office.com If not, oh well!
  19. Just chiming in with my two cents... Rather than trying to configure any fancy forwarding etc. (although still a valid approach), have you looked at connected accounts? Learn About Connected Accounts Users can hook up their old account from their new mailbox; might be quicker/simpler to configure given that this would be a short-term solution regardless?
  20. You only need A3 to use Office Mobile for iOS; other apps should work fine as far as I know.
  21. Sorry, no idea! Of course, you could upgrade to Windows 8... ...
  22. The SkyDrive Pro client isn't really designed to be used in this way. Users can drag and drop content directly into SkyDrive Pro via the browser, and of course if they're using a compatible version of Office they can save Office documents directly to their SkyDrive Pro document library. As @AngryTechnician says, the SkyDrive Pro client uses a local folder to sync to.
  23. Check out: Office 365 Adapter: Deploying Office 365 Single Sign-On using Windows Azure - UK Education Cloud Blog - Site Home - MSDN Blogs Depending on your budget (and how well you can spin it to those who control the purse strings) you could always look at the Office 365 Adapter to use the VM roles in Windows Azure to remove the dependency on your local AD availability.* Obviously, if your power goes out during the school day everyone is stuffed (except those on 3G), but outside hours or over holiday periods this could be more of a problem. The Office 365 Adapter side-steps the issue by hosting enough infrastructure components in Windows Azure VMs. Obviously it's not a free solution, but it's a solution. *Assuming you can't otherwise convince them that you don't need ADFS in the first place!
  24. There's a few different things going on there! First, the ADFS bit. ADFS at a minimum needs an ADFS server internally to provide SSO into Office 365. If you don't make that available to the outside world (which you shouldn't!) then nobody outside of your network will be able to authenticate with Office 365 since your ADFS server is unavailable to them. To support external users you can do one of two things: 1) Deploy an ADFS proxy (or as many as you need, load balanced) to sit in your DMZ. This provides ADFS access to your external users (i.e. from home) and also allows you to offer integrated authentication internally, and forms-based authentication externally. 2) Expose your internal ADFS server's endpoints via your firewall. Again, this provides access from external networks but you lose the flexibility of integrated vs. forms-based auth since an ADFS server can only really support one type at once. (Obviously, hacks are available but not recommended). So, to your question about whether or not you can get rid of your proxy: it depends. If SSO is a requirement (read on), then I would say that best practice says no. Second, the Password Sync bit. Password sync is not ADFS. They're not even closely related. Not even distant cousins! ADFS = Single Sign-On Password Sync = Same Sign-On If you deploy ADFS then password sync is irrelevant since all credentials and authentication are managed by your local AD. Passwords are not stored in the cloud, and users in your federated domain namespace will be required to authenticate against your ADFS server every time. What you could do is move away from ADFS and only have Password Sync. This then keeps your AD and AAD users in sync, but removes the need for any ADFS infrastructure. To your last point about needing SSO internally I say this: I'm going to be really honest and say that in schools, 99% of the time, I think ADFS is not what's needed. The two use cases are typically staff and students. Staff: usually use the same machine all the time, or have a dedicated device they take with them everywhere. In this scenario they're probably using Outlook client, and even if they're not they can always tick the "remember me" box in both OWA and Outlook client. Students: usually use multiple devices throughout the day. Unlikely (not impossible) to be using Outlook client, so probably using OWA. *generalisation warning* Students these days are very used to entering credentials (think Twitter, Facebook, MyFace, FriendFace, myFriend, and so on...) so as long as their credentials are the same (i.e. using Password Sync) I'm going to put my neck on the line and say that the few seconds it takes them to log in is worth not having the headache and infrastructure burden of running full-blown ADFS. Just my two cents though - and I understand most IT folks are in an un-winnable battle with the SMT, so don't take that ranty bit above personally. I've just needed to say it for a while now!
  25. Without getting into the ecumenical debate about which service or device is better, I'm interested to read your thoughts... Straight out of the gate you say that you purchase refurbished PCs with older processors, etc. and you say that they're overkill for most of what you need. But very quickly your argument turns to the speed element, and how booting a Chromebook is quick, etc. I'm not going to try and bang the drum for Windows because that's not why I'm commenting (and it wouldn't be appropriate)! I am interested to know whether or not you'd re-evaluate your position if you purchased newer hardware on which to run Windows? Is the perception of Windows gained from the previous experiences with older OS versions and hardware eclipsing the experience of Windows 8 on the latest devices? I'm not trying to change your mind, by the way, but I'm hugely interested to know what influences peoples decisions! (Although, if you are interested in this sort of thing, check out this, and keep an eye on Microsoft UK Schools blog today too)
×
×
  • Create New...