o365con14 - moving from on-premises to online, the road to follow

107

Upload: nccomms

Post on 09-May-2015

1.332 views

Category:

Presentations & Public Speaking


4 download

DESCRIPTION

European Office 365 Connect 2014 Presentation

TRANSCRIPT

Page 1: O365con14 - moving from on-premises to online, the road to follow
Page 2: O365con14 - moving from on-premises to online, the road to follow
Page 3: O365con14 - moving from on-premises to online, the road to follow
Page 4: O365con14 - moving from on-premises to online, the road to follow
Page 5: O365con14 - moving from on-premises to online, the road to follow

http://technet.microsoft.com/en-us/office365/fp123607

Page 6: O365con14 - moving from on-premises to online, the road to follow
Page 7: O365con14 - moving from on-premises to online, the road to follow

ActiveDirectory.Local

AzureAD.OnMicrosoft.Com

Page 8: O365con14 - moving from on-premises to online, the road to follow

ActiveDirectory.Local

AzureAD.OnMicrosoft.Com

Wait a Minute....

Page 9: O365con14 - moving from on-premises to online, the road to follow

ActiveDirectory.Local

AzureAD.OnMicrosoft.Com

Wait a Minute....

Your.Domain

Page 10: O365con14 - moving from on-premises to online, the road to follow
Page 11: O365con14 - moving from on-premises to online, the road to follow
Page 12: O365con14 - moving from on-premises to online, the road to follow

ActiveDirectory.Local

AzureAD.OnMicrosoft.Com

But... Wait Another Minute....

Your.Domain

Page 13: O365con14 - moving from on-premises to online, the road to follow
Page 14: O365con14 - moving from on-premises to online, the road to follow
Page 15: O365con14 - moving from on-premises to online, the road to follow

http://support.microsoft.com/kb/2256198

Page 16: O365con14 - moving from on-premises to online, the road to follow
Page 17: O365con14 - moving from on-premises to online, the road to follow
Page 18: O365con14 - moving from on-premises to online, the road to follow

Prepare for

dirsync

Activate

dirsync

Setup

dirsync

Synchronize

directories

Activate

synced users

Manage

dirsync

Page 19: O365con14 - moving from on-premises to online, the road to follow
Page 20: O365con14 - moving from on-premises to online, the road to follow

Service Protocol Port

LDAP TCP/UDP 389

Kerberos TCP/UDP 88

DNS TCP/UDP 53

Kerberos Change Password

TCP/UDP 464

RPC TCP 135

RPC randomly

allocated high TCP ports

TCP1024 - 65535

49152 - 655351

SMB TCP 445

SSL TCP 443

SQL TCP 1433

Page 21: O365con14 - moving from on-premises to online, the road to follow

http://www.microsoft.com/en-us/download/details.aspx?id=36832

Page 22: O365con14 - moving from on-premises to online, the road to follow
Page 23: O365con14 - moving from on-premises to online, the road to follow
Page 24: O365con14 - moving from on-premises to online, the road to follow
Page 25: O365con14 - moving from on-premises to online, the road to follow
Page 26: O365con14 - moving from on-premises to online, the road to follow
Page 27: O365con14 - moving from on-premises to online, the road to follow
Page 28: O365con14 - moving from on-premises to online, the road to follow
Page 29: O365con14 - moving from on-premises to online, the road to follow
Page 30: O365con14 - moving from on-premises to online, the road to follow
Page 31: O365con14 - moving from on-premises to online, the road to follow
Page 32: O365con14 - moving from on-premises to online, the road to follow
Page 33: O365con14 - moving from on-premises to online, the road to follow
Page 34: O365con14 - moving from on-premises to online, the road to follow
Page 35: O365con14 - moving from on-premises to online, the road to follow
Page 36: O365con14 - moving from on-premises to online, the road to follow
Page 37: O365con14 - moving from on-premises to online, the road to follow
Page 38: O365con14 - moving from on-premises to online, the road to follow
Page 39: O365con14 - moving from on-premises to online, the road to follow

Attribute Object Type

MSExchArchiveStatus User

MSExchBlockedSendersHash User

SExchSafeRecipientsHash User

MSExchSafeSendersHash User

MSExchUCVoiceMailSettings User

ProxyAddresses User, Contact, Group

Page 40: O365con14 - moving from on-premises to online, the road to follow

http://technet.microsoft.com/en-us/library/dn246918.aspx

http://technet.microsoft.com/en-us/library/jj710171.aspx

Page 41: O365con14 - moving from on-premises to online, the road to follow
Page 42: O365con14 - moving from on-premises to online, the road to follow
Page 43: O365con14 - moving from on-premises to online, the road to follow
Page 44: O365con14 - moving from on-premises to online, the road to follow
Page 45: O365con14 - moving from on-premises to online, the road to follow
Page 46: O365con14 - moving from on-premises to online, the road to follow
Page 47: O365con14 - moving from on-premises to online, the road to follow
Page 48: O365con14 - moving from on-premises to online, the road to follow
Page 49: O365con14 - moving from on-premises to online, the road to follow
Page 50: O365con14 - moving from on-premises to online, the road to follow
Page 51: O365con14 - moving from on-premises to online, the road to follow
Page 52: O365con14 - moving from on-premises to online, the road to follow
Page 53: O365con14 - moving from on-premises to online, the road to follow
Page 54: O365con14 - moving from on-premises to online, the road to follow
Page 55: O365con14 - moving from on-premises to online, the road to follow
Page 56: O365con14 - moving from on-premises to online, the road to follow
Page 57: O365con14 - moving from on-premises to online, the road to follow

Microsoft Online Services

Logon Enabled User Object (Unlicensed)

Mail-Enabled User (not Mailbox-Enabled)

ProxyAddresses:

SMTP: [email protected]

smtp: [email protected]

TargetAddress:

[email protected]

On-premises

Active

Directory

Exchange

Server

DirSyncOnline

Directory

DirSync

Web Service

SharePoint

Online

Live ID

Exchange

Online

Lync Online

Sync Cycle Step 1:

Import Users, Groups,

and Contacts from source

Active Directory forest

Sync Cycle Step 2:

Imports Users, Groups, and

Contacts from Microsoft

Online Services via AWS

Sync Cycle Step 3:

Export Users, Groups, and

Contacts that do not already

exist in Microsoft Online

Services

User Object

Mailbox-Enabled

ProxyAddresses:

SMTP: [email protected]

Page 58: O365con14 - moving from on-premises to online, the road to follow

http://365lab.net/2014/01/07/managing-office-365-e-mail-addresses-easy-with-powershell-when-using-dirsync/

Page 59: O365con14 - moving from on-premises to online, the road to follow
Page 60: O365con14 - moving from on-premises to online, the road to follow
Page 61: O365con14 - moving from on-premises to online, the road to follow
Page 62: O365con14 - moving from on-premises to online, the road to follow
Page 63: O365con14 - moving from on-premises to online, the road to follow
Page 64: O365con14 - moving from on-premises to online, the road to follow
Page 65: O365con14 - moving from on-premises to online, the road to follow
Page 66: O365con14 - moving from on-premises to online, the road to follow
Page 67: O365con14 - moving from on-premises to online, the road to follow

Prepare for

dirsync

Activate

dirsync

Setup

dirsync

Synchronize

directories

Activate

synced users

Manage

dirsync

Page 68: O365con14 - moving from on-premises to online, the road to follow
Page 69: O365con14 - moving from on-premises to online, the road to follow
Page 70: O365con14 - moving from on-premises to online, the road to follow
Page 71: O365con14 - moving from on-premises to online, the road to follow
Page 72: O365con14 - moving from on-premises to online, the road to follow

Scenario Description

Block all external access to Office 365

Office 365 access is allowed from all clients on the internal

corporate network, but requests from external clients are

denied based on the IP address of the external client.

Block all external access to Office 365, except Exchange

ActiveSync

Office 365 access is allowed from all clients on the internal

corporate network, as well as from any external client

devices, such as smart phones, that make use of Exchange

ActiveSync. All other external clients, such as those using

Outlook, are blocked.

Block all external access to Office 365, except for browser-

based applications such as Outlook Web Access or

SharePoint Online

Blocks external access to Office 365, except for passive

(browser-based) applications such as Outlook Web Access

or SharePoint Online.

Block all external access to Office 365 for members of

designated Active Directory groups

This scenario is used for testing and validating client access

policy deployment. It blocks external access to Office 365

only for members of one or more Active Directory group. It

can also be used to provide external access only to

members of a group.

Page 73: O365con14 - moving from on-premises to online, the road to follow

http://technet.microsoft.com/library/dn509539.aspx

Page 74: O365con14 - moving from on-premises to online, the road to follow

AD FS

AD FS

AD FS Proxy

AD FS Proxy

Active Directory

Directory Synchronization

Page 75: O365con14 - moving from on-premises to online, the road to follow

DATA CENTER 1

AD FSAD FS

Proxy

Directory

synchronizationActive

Directory

AD FS

VPN

Tunn

el

VPN

VPN

Active Directory

Page 76: O365con14 - moving from on-premises to online, the road to follow

VPN

Tunn

el

VPN

AD FS Proxy

AD FS Proxy

Active Directory

Directory Synchronization

AD FSAD FS Proxy

Directory synchronization

Active DIrectoryVPN

AD FS

AD FS

AD FS

Page 77: O365con14 - moving from on-premises to online, the road to follow

Cloud identity

Single identity in the cloud

Suitable for small organizations

with no integration to on-

premises directories

Cloud identity with directory synchronization

Single identity

suitable for medium

and large organizations

without federation*

Federated identity

Single federated identity

and credentials suitable

for medium and large

organizations

Page 78: O365con14 - moving from on-premises to online, the road to follow

Federation options

Suitable for educational organizations

j

Recommended where customers may use existing

non-ADFS Identity systems

Single sign-on

Secure token based authentication

Support for web clients and outlook only

Microsoft supported for integration only, no

shibboleth deployment support

Requires on-premises servers & support

Works with AD and other directories on-premises

Shibboleth

Works with AD & Non-AD

Suitable for medium, large enterprises

including educational organizations

Recommended option for Active Directory (AD)

based customers

Single sign-on

Secure token based authentication

Support for web and rich clients

Microsoft supported

Works for Office 365 Hybrid Scenarios

Requires on-premises servers, licenses & support

Works with AD

Suitable for medium, large enterprises

including educational organizations

Recommended where customers may use existing

non-ADFS Identity systems with AD or Non-AD

Single sign-on

Secure token based authentication

Support for web and rich clients

Third-party supported

Requires on-premises servers, licenses & support

Verified through ‘works with Office 365’ program

Works for Office 365 Hybrid Scenarios

Works with AD & Non-AD

Page 79: O365con14 - moving from on-premises to online, the road to follow

What is it?• Qualification of third party identity

providers for federation with Office 365. Microsoft supports Office 365 only when qualified third party identity providers are used.

Program Update Jan 2014:• Published Qualification

Requirements

• Published Technical Integration Docs

• Automated Testing Tool

• Self Testing work by Partner

• Predictable and Shorter Qualification

WS-Trust & WS-Federation

WS-Federation

SAML

Active Directory with ADFS

Customer Benefits

• Flexibility to reuse

existing identity

provider investments

• Confidence that the

solution is qualified by

Microsoft

• Coordinated support

between the partner

and Microsoft

Page 80: O365con14 - moving from on-premises to online, the road to follow

http://blogs.office.com/2014/03/06/announcing-support-for-saml-2-0-federation-with-office-365/

Page 81: O365con14 - moving from on-premises to online, the road to follow
Page 82: O365con14 - moving from on-premises to online, the road to follow
Page 83: O365con14 - moving from on-premises to online, the road to follow
Page 84: O365con14 - moving from on-premises to online, the road to follow
Page 85: O365con14 - moving from on-premises to online, the road to follow

Two or more of the following factors:

Types of multi-factor authentication:Hardware OTP Tokens

Certificates

Smart Cards

Phone-Based Authentication:

Phone Call, Text Message, and Push

Software OTP Tokens

Multiple factors are required for sign-InFamiliar to consumer cloud service users such as the Microsoft Account

Simple block to password compromise from another country

Addresses regulatory compliance and high risk user scenarios

AKA two-factor, 2FA, MFA, strong authentication

Page 86: O365con14 - moving from on-premises to online, the road to follow

Powered by PhoneFactor, acquired by Microsoft in 2012

Trusted by thousands of enterprises to authenticate employee, customer, and partner access

Secures applications and identities in the cloud and on-premises

Page 87: O365con14 - moving from on-premises to online, the road to follow

App Passwords

Page 88: O365con14 - moving from on-premises to online, the road to follow
Page 89: O365con14 - moving from on-premises to online, the road to follow

Multi-Factor

Authentication for Office

365

Windows Azure Multi-

Factor Authentication

Administrators can Enable/Enforce MFA to end-users Yes Yes

Use Mobile app (online and OTP) as second authentication

factor

Yes Yes

Use Phone call as second authentication factor Yes Yes

Use SMS as second authentication factor Yes Yes

App passwords for non-browser clients (e.g. Outlook, Lync) Yes Yes

Default Microsoft greetings during authentication phone calls Yes Yes

Custom greetings during authentication phone calls Yes

Fraud alert Yes

Event Confirmation Yes

Security Reports Yes

Block/Unblock Users Yes

One-Time Bypass Yes

Customizable caller ID for authentication phone calls Yes

MFA Server - MFA for on-premises applications Yes

MFA SDK – MFA for custom apps Yes

Page 90: O365con14 - moving from on-premises to online, the road to follow

http://blogs.msdn.com/b/ramical/archive/2014/01/30/under-the-hood-tour-on-multi-factor-authentication-in-ad-fs-part-1-policy.aspx

http://blogs.office.com/2014/02/10/multi-factor-authentication-for-office-365/

Page 91: O365con14 - moving from on-premises to online, the road to follow
Page 92: O365con14 - moving from on-premises to online, the road to follow

http://technet.microsoft.com/en-us/library/hh852542.aspx

http://gallery.technet.microsoft.com/office/Exchange-Client-Network-8af1bf00

http://technet.microsoft.com/en-us/library/jj204570.aspx

Page 93: O365con14 - moving from on-premises to online, the road to follow

http://trippams.online.lync.com/

http://technet.microsoft.com/en-us/library/jj688118.aspx

http://www.microsoft.com/en-us/download/details.aspx?id=19011

Page 94: O365con14 - moving from on-premises to online, the road to follow

http://onlinehelp.microsoft.com/en-us/office365-enterprises/hh373144.aspx

http://technet.microsoft.com/en-us/exchangelabshelp/gg263350

http://go.microsoft.com/fwlink/?linkid=236301

http://onlinehelp.microsoft.com/en-us/office365-enterprises/hh416761.aspx

Page 95: O365con14 - moving from on-premises to online, the road to follow

https://sls.microsoft.com

http://officecdn.microsoft.com

http://go.microsoft.com/

https://sls.microsoft.com/

http://crl.microsoft.com/pki/crl/products/MicrosoftRootAuthority.crl

http://crl.microsoft.com/pki/crl/products/MicrosoftProductSecureCommunications.crl

http://www.microsoft.com/pki/crl/products/MicrosoftProductSecureCommunications.crl

http://crl.microsoft.com/pki/crl/products/MicrosoftProductSecureServer.crl

http://www.microsoft.com/pki/crl/products/MicrosoftProductSecureServer.crl

https://activation.sls.microsoft.com

Page 96: O365con14 - moving from on-premises to online, the road to follow

http://technet.microsoft.com/en-us/library/hh852551.aspx

Page 97: O365con14 - moving from on-premises to online, the road to follow
Page 98: O365con14 - moving from on-premises to online, the road to follow
Page 99: O365con14 - moving from on-premises to online, the road to follow

http://office.microsoft.com/en-001/sharepoint-server-help/what-is-skydrive-pro-HA102822076.aspx

Page 100: O365con14 - moving from on-premises to online, the road to follow
Page 101: O365con14 - moving from on-premises to online, the road to follow

ActiveDirectory.Local

AzureAD.OnMicrosoft.Com

[email protected]

Msbelux.be

Page 102: O365con14 - moving from on-premises to online, the road to follow
Page 103: O365con14 - moving from on-premises to online, the road to follow

ActiveDirectory.Local

AzureAD.OnMicrosoft.Com

Msbelux.be

Page 104: O365con14 - moving from on-premises to online, the road to follow

http://office.microsoft.com/en-001/office365-sharepoint-online-small-business-help/let-users-create-their-own-team-sites-HA102844581.aspx

http://office.microsoft.com/en-001/office365-sharepoint-online-enterprise-help/manage-my-site-settings-HA102459836.aspx

Page 105: O365con14 - moving from on-premises to online, the road to follow
Page 106: O365con14 - moving from on-premises to online, the road to follow

http://blogs.technet.com/b/office_resource_kit/archive/2013/01/21/office-2013-click-to-run-customization.aspx

http://blogs.technet.com/b/office_resource_kit/archive/2013/04/17/the-new-office-garage-series-click-to-run-customization-and-deployment-deep-dive-part-1-with-high-g-aerobatics.aspx

http://blogs.technet.com/b/office_resource_kit/archive/2013/04/23/the-new-office-garage-series-click-to-run-customization-and-deployment-deep-dive-part-2-workarounds.aspx

http://blogs.technet.com/b/office_resource_kit/archive/2013/04/30/the-new-office-garage-series-click-to-run-customization-and-deployment-deep-dive-part-3-integration-and-automation-with-software-distribution-tools.aspx

Page 107: O365con14 - moving from on-premises to online, the road to follow

Ilse Van Criekinge

Technology Advisor Business Productivity

@ivcrieki, [email protected]