Office 365 tenant administrator roles have changed

For the last 3 years, Office 365 has had a rather poor set of choices for the roles you can assign to your administrators. The old administrator roles for Office 365 are; Billing admin, Global admin, Password admin Service admin, and User management admin. I don’t think that these roles are terribly self-explanatory to most of the people to whom they would be assigned, and they don’t really map to real world jobs that administrators do. The only role there with usable administrate rights is global admin, the other roles are all for some level of running Office 365 itself. The Global admin role has all the rights to all the constituent parts of Office 365; Exchange, Lync, and SharePoint. In the real world, there are not many people who actually know how to work those 3 different technologies. As of this morning, Microsoft has changed the roles groups into something that looks like it makes more sense.

Read more

Office 365 feature release roadmap

I’m a pretty big fan of Office 365, not just because Office 365 migrations are the majority of how I make a paycheck. In general I think Office 365 is the current best example of “the cloud”, meaning Office 365 is the most complete and useable group of workloads that business IT departments can outsource to make both their and their users work lives better. That being said, I do have a few of issues with Office 365 and most of them are communication.

Read more

Exchange Online and the staged migration

I do a lot of Exchange Online migrations. I’m not really sure how many I have done, but I would guess the number is between 50 and 100 over the last 3 years. Over 90% of those migrations have been Hybrid. In fact, I’m pretty sure only one or two of those migrations have not been hybrid. Recently I had occasion to do a staged migration. I’d like to go through that process and discuss why I ended up making the choices I did.

Read more

Self Service Password Reset writeback to Windows Server AD using DirSync

As soon as I heard about password sync for DirSync, my first feature request was password write back. It’s been just about a year since password sync capabilities were added to DirSync and how we have password reset writeback available in public preview. There are a couple of caveats that we need to cover, but for the most part this feature is here and ready to go.

Read more

Recovering a from a datacenter failure

In previous posts (before I got all busy writing my sessions for IT connections), I promised to detail the process for recovering from a datacenter failure. For the purposes of this post I’ll assume we’re talking about a 2 site Exchange deployment with 2 Exchange servers at each site. All 4 Exchange servers are members of the same DAG, and all databases are replicated to all servers. We are also assuming that the DAG in question is running DAC mode.

Read more

My sessions at Exchange Connections conference

As Tony Redmond recently posted on his blog, the sessions for the Exchange Connections conference in Las Vegas have been set for this fall. I was honored to find out that my session submissions were accepted.

My two sessions are titled; “Identity and Authentication Management for Office 365”, and “Performance Counters You Never Knew and Why they are Important”

Even though the conference is a little over four months away, I am starting to work on my sessions now. To that end, if you have any questions that would fit into either session, please email them to me at nathan@mcsmlab.com

Strong speaker line-up for Exchange Connections 2014 | Tony Redmond's Exchange Unwashed Blog

Datacenter Activation Coordination

This might be a controversial statement, but I kind of think it is too easy to setup database availability groups in Exchange 2010 and later. It’s not that I would want DAGs to be harder to setup, it’s just that the ease with which one can setup a basic DAG allows too many people to stop there and not work on really understanding the deeper features and configurations of high availability for mailboxes. With that in mind, I want to cover what I think might be the least understood DAG configuration feature, DAC.

Read more

Setting up 2 factor authentication for Office 365

Recently Microsoft has enabled 2 factor authentication for all Enterprise Office 365 tenants at no additional cost. Their offering is based on PhoneFactor’s 2 factor authentication system, a company Microsoft bought a couple of years ago. Setting this feature up for Office 365 accounts is fairly easy, but there are a couple of “tricky” parts that could use a bit of clarification so I thought I would run through the process for you here.

Read more