Presentation is loading. Please wait.

Presentation is loading. Please wait.

Think You Know How To Manage Office 365?

Similar presentations


Presentation on theme: "Think You Know How To Manage Office 365?"— Presentation transcript:

1

2 Think You Know How To Manage Office 365?
By: Eric Raff

3 Quick Introduction Joined JourneyTEAM in April 2015
In IT industry for 20+ years Cloud Solutions Architect Identity & Access Management Architect SharePoint Architect Exchange Server Engineer OCS/Lync Engineer GroupWise Guy Published Author Teacher

4 Identities in the Microsoft Cloud
Types of Identities Office 365 Services Member Exchange Online SharePoint Online Guest - #EXT# EXO SPO Microsoft Account B2C User (another time) Backend replication AAD Service (Microsoft Accounts) Azure AD Service (Work/school accts) Azure Services Associated AAD Directory Subscription AAD Directory Ericraffoutlook.onmicrosoft.com Associated B2B AAD Directory Subscripton

5 O365 Admin Centers * No Powershell Exchange (EXO)
Skype for Business (S4B) SharePoint (SPO) OneDrive (ODfB) Yammer * PowerApps * Flow * Security & Compliance Azure AD (AAD) – special AD admin center Intune * Cloud App Security * * No Powershell

6 O365 Management Options Powershell O365 Admin Portal
O365 Admin Portal Microsoft Azure Portal (ARM/Ibiza) Windows Azure Portal (OLD - deprecated) O365 Admin Mobile App (W10, Mobile) See this for more info GREAT for cloud only users

7 Powershell Access AzureAD – V1 (SDK) and V2 (Graph API)
V1: Connect-MsolService (Install-module MSOnline) V2: Connect-AzureAD (Install-module AzureAD) Exchange Online – IE/Edge download required Exchange Admin Center | hybrid | Online powershell Connect-EXOPSSession SharePoint Online - Download here $orgName="<your Office 365 tenant>“ Connect-SPOService -Url Skype for Business Online – Download here Import-Module SkypeOnlineConnector Security and Compliance Center – Uses EXO install Connect-IPPSSession Teams – Announced Nov 7th See blog here Install-Module MicrosoftTeams Single script with MFA support here

8 Azure AD General Tenant Settings
Attributes, Attributes, Attributes – Drive Dynamic Groups - Document and Normalize Department, Location, Title, EmployeeID & Type etc. Phone # Format +1 (801) (for MFA calling) Properties Directory Name – very important when B2B in play Global Admin can Manage Azure Subscriptions Company Branding If using ADFS, brand both to match Mobility (MDM and MAM) To Auto Enroll or not?

9 Azure AD User & Groups Settings
User Settings Guest users permissions are limited - YES Guests can invite – Really? Restrict access to AzureAD admin portal – YES Group Settings Who can create/manage Groups? O365 Group Expiration – CONFIGURE THIS! Enable “All users” Group – Includes EVERYONE! TIP: Create “All Members”, “All Guests” dynamic groups Device Settings Who can Join? Require MFA to join - SUGGESTED Sync settings & app data across devices - YES

10 Azure AD Connect Health
AAD Connect Agent Get on latest AAD Connect version. See version history Sync Errors Password Hash Sync AuthN status/state ADFS Agent ADFS servers WAP servers AD DS Agent Install on each DC See info here on agent download and install info. TIP: port 5671 is more efficient for health status but if not open will fall back to 443 for outbound connectivity to Azure services.

11 Licensing - GBL has arrived
Group Based Licensing AAD Basic or Premium required DEMO Powershell script to remove direct assignments is here TIP: At the very bottom of this site.

12 O365 General Tenant Settings
Release Preferences Custom Themes Company Branding A Word on Trusted IE Sites *.microsoftonline.com *.sharepoint.com *.outlook.com *.lync.com *.office365.com *.office.com *.microsoftstream.com *.sway.com *.powerapps.com

13 Exchange Online Settings
Exchange Advanced Threat Protection Enable Modern AuthN Set-OrganizationConfig -OAuth2ClientProfileEnabled $true Get-OrganizationConfig | select *Oauth* SPAM Settings Security SPF DKIM DMARC Conf Rooms for scheduling Working hours, booking options Message Size Limits Get-MailboxPlan | Set-MailboxPlan -MaxSendSize 75MB -MaxReceiveSize 75MB Mailbox Auditing Get-mailbox –ResultSize Unlimited -Filter {(RecipientTypeDetails -eq 'UserMailbox')} | ForEach {Set-Mailbox $_.Identity -AuditEnabled $true -AuditLogAgeLimit AuditOwner MailboxLogin,HardDelete}

14 SharePoint Online Settings
Hide Everyone principles Set-SPOTenant -ShowEveryoneClaim $false Set-SPOTenant -ShowEveryoneExceptExternalUsersClaim $false Set-SPOTenant -ShowAllUsersClaim $false OneDrive Sync Button – Check your tenant Sharing with External users

15 Skype for Business Settings
Enable Modern Authentication Set-CsOAuthConfiguration -ClientAdalAuthOverride Allowed Get-CsOAuthConfiguration Organization profile General External Communications

16

17 THANK YOU


Download ppt "Think You Know How To Manage Office 365?"

Similar presentations


Ads by Google