Jump to content

jamesbmarshall

Members
  • Posts

    562
  • Joined

  • Last visited

Everything posted by jamesbmarshall

  1. The process for signing up for Live@edu meant that unless you had a domain spare you couldn't really get access to the service, even if you just wanted to evaluate. By doing it this way round with Office 365 it allows customers to evaluate the service for 30 days without needing their own domain name, as well as being able to just get started from day one. The .onmicrosoft.com domain that you get as part of signing up is a requirement, and has no impact on your ability to use any other domain names (in fact, it's very useful when it comes to federating). You should keep your "super admin" in your .onmicrosoft.com domain as you will always be able to access this even if you chose to federate any other domains that subsequently suffer an outage (i.e. because your local federation server goes down). The administrator roles are there to allow you to devolve power to others, but purchasing licences carries a potential cost which is why it is restricted. Generally speaking, you don't need to adjust your licence count on a daily, or even monthly, basis. You can bulk assign licences after you create your users as well - just select multiple users in the portal and you can edit them together. The GUI is just one way to do this - if you're looking for something more easily automated look at DirSync to handle user provisioning, and Windows PowerShell to manage passwords and licences. You don't need an administrator account for every domain. Your .onmicrosoft.com administrator account will be able to administer users in other namespaces, and as previously mentioned, it's advisable to keep your admin in that namespace. The solution is DirSync. Managing your tenant exclusively using CSV imports is possible, but I strongly recommend DirSync to sync your local AD with Office 365 - this will handle that sort of thing automatically; it also means you have one single place to manage your users: your local AD. It's possible to write yourself a little PowerShell script to import users, set their password, dictionary language and regional settings, and any other details. The logic being: Import users from CSV For each user imported run a bunch of configuration settings If you want to dictate your own password strength policies you can deploy AD FS 2.0 or Shibboleth; this moves the authentication to your local AD and users will be required to adhere to whatever local password policy you have in place. Obviously, we strongly recommend that you adopt a strong password policy. Thanks for all your points Michael; you've certainly given some great feedback. Hopefully my comments are useful - I accept that there are differences between Live@edu and Office 365 that take some getting used to. If you're already on Live@edu have you given any thought to upgrading?
  2. I'd love to see them if you do.
  3. Sorry to hear you hit a few bumps along the way to deploying - but glad to see that you've finally been able to purchase the licenses you require. The reason they're not there be default is because we need to go through a process of verifying that you're eligible for the free service (by adding a education domain). Once you've verified a domain, and are logged in using an appropriate account you'll have access to purchase all the free and paid-for SKUs. Licensing is handled on a per-user basis. It is possible to select multiple users from the GUI, or you could use Windows PowerShell to assign licences. As an example: Synchronise your tenant with your local AD using DirSync. Populate an attribute, say customattribute1, with some information (i.e. 1 = students, 2 = staff, etc.). Decide that students will get the Exchange Online component of Plan A2, staff will get Exchange Online, and Lync Online, etc. Write a PowerShell script that looks for newly provisioned users, reads the customattribute1 attribute, and then assigns corresponding licence SKUs depending on the value of the attribute. Scripting licence assignment is fairly straightforward, and I've written a blog post that should help you get started.
  4. No* - DirSync does a sync of your full AD. You don't have to provide licences or services to every user it synchronises across though. FIM is a more flexible solution, but there is no freely available Microsoft-supported management agent for FIM. For this you'd need the services of a partner. *sort of. You can't change the links unfortunately; take a look at the Office 365 preview if you're interested to see where the future lies; I believe your problem is addressed somewhat.
  5. FIM isn't supported. (By which I mean that there is no user-configurable management agent for FIM supplied by Microsoft. DirSync is the only solution unless you want to engage the services of a Microsoft partner) What's the concern over using DirSync?
  6. Currently it can happen whenever you like. There'll be a point in time when you'll be scheduled at which time you'll be able to pull forward whenever you like, but only push back by a limited window. As for waiting a while - I'd say do it ASAP rather than during a holiday. It's not as painful as you think!
  7. There are lots of things to consider in this scenario - more than I can cover properly here unfortunately. If you're looking at this level of complexity (i.e. multiple tenants, single sign-on, different domains, etc.) then I'd really recommend you look into using a partner company to help you deploy if you don't feel you can pull it off on your own! There is lots of documentation available online, and I've tried to bring it all together under one roof to make it easier to find: Office 365 for education Deployment Resources - UK Education Cloud Blog - Site Home - MSDN Blogs Briefly, it is possible to have two tenants and staff and students split between the two but there are technical trade-offs in doing this. If it were me doing this in my school I'd try and tackle the cultural argument of whether or not there should be a shared GAL separately from the technology. You need to thoroughly evaluate how important a split GAL (and therefore, separate tenants) is vs. the ease of being able to share information, communicate and collaborate with services like Lync Online and SharePoint Online - both services that would be affected by your tenancy design. Hope that helps!
  8. Unless you move to federation, nobody will be able to log in via any protocol until they've reset their password. Mail flow inbound is not affected.
  9. Depends - how are they currently configured? The answer could be as simple as there is no change. Are you going to move to AD FS 2.0? Which version of Outlook are you running? Mailboxes don't move as part of the upgrade so server names shouldn't really change, but the auth details might. If a user changes their password to something different, or you deploy single sign-on, etc.
  10. Each Office 365 tenant has one GAL - if you add multiple domains to a tenant they'll all share the same GAL. It is possible to hide users from the GAL, but you cannot prevent users from seeing the GAL; so if you hide staff your students will see each other, and staff will still see the students. On the one hand, supporting custom address book policies in Exchange Online would be a great thing, and whenever I get feedback about this I always pass it on. On the other hand, there is the camp, as this thread has thrown up, which thinks that actually preventing users from appearing in the GAL serves little-to-no purpose but actually negatively impacts productivity (after all, if you use a consistent naming convention for your users, it doesn't much to work out a user's email address...).
  11. Drop me a PM and we can talk about the upgrade process in more detail if you like. The upgrade splits out the mailbox from the other Microsoft services. Existing users will have their Microsoft Accounts, and their Office 365 accounts going forward. At the moment passwords have to be reset because we can't copy them between the two services but resetting is a one-time process and you can bypass this entirely by moving straight to AD FS or Shibboleth as this negates the need to store any credentials in Office 365; users just authenticate against your local AD.
  12. While the licences, for the most part, are free you should still be accurate and honest. You can scale up and down as you need. There is no benefit to you in having 500 licences when you only need 200 - and if you need more it takes seconds via the admin portal to get them.
  13. What do you mean the trial login?
  14. Which version of IE are you running?
  15. Compare Office 365 Plans and Pricing for Schools - Office 365 There are licensing plans available (A2 through A4), and these are made up from individual components. For example, A2 includes Exchange Online Plan 2, Lync Online Plan 2, SharePoint Online Plan 1 and the Office Web Apps. If you assign the whole plan to a user, they get all those services. You can elect to only assign individual parts of the plan (i.e. Exchange only) and the user will only get those services. The difference between "SharePoint Online Plan 1" and "Office Web Apps with SharePoint Online Plan 1" is in the name. Whether or not changing licences affects the users depends on what data they have in the system - if you remove an Exchange Online licence the user will lose access to their mailbox; similarly if you remove a SharePoint Online licence the user will lose access to SharePoint. If you've been through the upgrade all your users will have come across onto Exchange Online Plan 1 which is just an individual component SKU; you can now "purchase" the A2 plan if you wish and assign it to your users to offer the other services or just leave it as it is.
  16. Live@edu has a service health dashboard: https://status.eduadmin.live.com/ If you sign in as an administrator you can find out more information.
  17. You need to sign up at http://www.microsoft.com/uk/office365edu, click compare plans, and then the link will say that it's a 30 day trial; however that is just a 30 day preview of the A3 licence - this is also the way to get the free service. Once you've added and verified an academic domain you'll be able to get access to all the free parts.
  18. The SSO toolkit will still work for Live@edu customers until they upgrade. If you're having problems you really need to contact Live@edu support. You should also familiarise yourself with the upgrade, too; Live@edu Upgrade to Office 365 for education (English) - Live@Edu Upgrade to Office 365 for education - Office 365 - Microsoft Office 365 Community.
  19. Live@edu has 24x7 free support by phone and by email; you can find out the details via http://eduadmin.live.com. (Sign in as the admin account for your tenant)
  20. Live@edu used FIM which had a special license that didn't require CALs, the cost was quite low. Office 365 uses DirSync, a free tool. DirSync is required if you want to use AD FS for single sign-on.
  21. Set Up a Shared Mailbox
  22. If you want to use DirSync, which is a pre-requisite for AD FS, then your users on-premise will need a UPN that matches up with what's in Office 365 which in your case would want to be @students.organisation.org.uk. Could you change the UPNs for your student users? It is possible to have users with a different UPN to their primary SMTP address (i.e. UPN: [email protected], SMTP: [email protected]) in Office 365 but this is really not recommended.
  23. OK - I'm working on it. As soon as I find out the exact steps, I'll post them here. Edit: If you're not seeing additional licensing options post-upgrade please contact Office 365 support (phone number available via the admin portal).
  24. In the Office 365 Admin Portal, under the Subscriptions section, under Purchase you should have options to purchase the full variety of plans?
  25. For those interested and who don't know, the education templates are not built in; you can download them here: Office 365 for education
×
×
  • Create New...