Andy Malone - The new office 365 for it pro's

58
Andy Malone The New Office 365 for IT Pro’s

description

 

Transcript of Andy Malone - The new office 365 for it pro's

Page 1: Andy Malone - The new office 365 for it pro's

Andy MaloneThe New Office 365 for IT Pro’s

Page 2: Andy Malone - The new office 365 for it pro's

Microsoft MVP (Enterprise Security)

Founder: Cybercrime Security Forum!

Microsoft International Event Speaker

MCT (18 Years)

Winner: Microsoft Speaker Idol 2006

See me speak @ Microsoft TechEd 2014

Andy Malone

Follow me on Twitter @AndyMalone

Page 3: Andy Malone - The new office 365 for it pro's

The Extras…Follow @AndyMalone & Get my SkyDrive Link

Page 4: Andy Malone - The new office 365 for it pro's

Register at the Glasspaper

Booth for more info & a

chance to win tickets!

Page 5: Andy Malone - The new office 365 for it pro's

Goals

Explore Connect Identity SharePoint Online

Administer Secure Tips n Tricks

Page 6: Andy Malone - The new office 365 for it pro's

Explore…

Page 7: Andy Malone - The new office 365 for it pro's

What is Office 365?Latest productivity services in Microsoft’s public cloud + the latest apps

Page 8: Andy Malone - The new office 365 for it pro's

Benefits of Office 365Latest productivity services in Microsoft’s public cloud + the latest apps

Page 9: Andy Malone - The new office 365 for it pro's

Understand where your data is stored

Page 10: Andy Malone - The new office 365 for it pro's

Energy In = Heat Out

Removing heat is critical

Environmental control is a major source of energy and water consumption

Innovative approaches increase overall efficiency over traditional computer room air conditioning (CRAC)

Page 11: Andy Malone - The new office 365 for it pro's

Rack Density and Deployment1.4 –1.6 PUEMinimized Resource Impact

ServerCapacity~2 PUE 20 year Technology

Containers, PODsScalability & Sustainability1.2 –1.5 PUEAir & Water EconomizationDifferentiated SLAs

ITPACs & ColosReduced Carbon, Rightsized1.05 –1.20 PUE Faster Time to Market Outside Air Cooled

Microsoft’s Datacenter Evolution

2011+

Generation 4

2008

Generation 3

1989-2005

Generation 1

2007

Generation 2

Density ContainmentColocation Modular

Page 12: Andy Malone - The new office 365 for it pro's

Office 365 Operates as a Datacenter within Microsoft Datacenters

• Shared Mechanical & Electrical

• Consumer Services:

• Different hardware

• Separate access control

• Separate network

• Separate storage

Page 13: Andy Malone - The new office 365 for it pro's

Office 365: Getting Started

Page 14: Andy Malone - The new office 365 for it pro's

Adding a Domain to Office 365

Page 15: Andy Malone - The new office 365 for it pro's
Page 16: Andy Malone - The new office 365 for it pro's

Identity…

Page 17: Andy Malone - The new office 365 for it pro's

Core identity scenarios with Office 365

Cloud Identity

Single identity in the cloud Suitable for small organizations with no integration to on-premises directories

Directory & Password Synchronization*

Single identitysuitable for medium and large organizations without federation*

Federated Identity

Single federated identity and credentials suitable for medium and large organizations

Page 18: Andy Malone - The new office 365 for it pro's

Windows Azure Active DirectoryOne Cloud Directory for every organization

What it is:

• The identity platform behind Office 365 & other Microsoft Cloud Services

• Able to integrate with enterprise identity platforms

• Enabler of single sign-on for Office 365 and other apps

What it isn’t:

• Windows Azure Active Directory is not your AD Domain Controllers running in the Windows Azure

• We do support AD running as a role on a VM in Windows Azure IaaS – but that is a separate discussion

Page 19: Andy Malone - The new office 365 for it pro's
Page 20: Andy Malone - The new office 365 for it pro's

Protocols to Connect to Windows Azure AD

Protocol Purpose Details

REST/HTTP directory access

Create, Read, Update, Delete directory objects and relationships

Compatible with OData V3Authenticate with OAuth 2.0

OAuth 2.0 Service to service authenticationDelegated access

JWT token format

Open ID Connect Web application authenticationRich client authentication

Under investigationJWT token format

SAML 2.0 Web application authentication SAML 2.0 token format

WS-Federation 1.3 Web application authentication SAML 1.1 token formatSAML 2.0 token formatJWT token format

Page 21: Andy Malone - The new office 365 for it pro's

WAAD Provisioning• Manual

– Simple Web based user interface– Bulk import of user– Best for small customers

• Scriptable– PowerShell module for windows– Programmable REST based API– Limited attribute set/object types

• Automated– Directory Synchronization with delta – Full fidelity of attributes and object types– Optimized for large object sets

Page 22: Andy Malone - The new office 365 for it pro's

Cloud Identity

OAuth2

SAML-P

WS-Federation

Metadata

Graph API

Page 23: Andy Malone - The new office 365 for it pro's

Directory & Password Sync

OAuth2

SAML-P

WS-Federation

Metadata

Graph API

Page 24: Andy Malone - The new office 365 for it pro's

Federated Identity

OAuth2

SAML-P

WS-Federation

Metadata

Graph API

Page 25: Andy Malone - The new office 365 for it pro's

Account Provisioning

Page 26: Andy Malone - The new office 365 for it pro's

What is Dirsync? (Azure Active Directory Sync Tool )

• Enables Simple & Rich Coexistence

– Provisions objects in Office 365 with same email addresses as the objects in the on-premises environment

– Provides a unified Global Address List experience between on-premises and Office 365

• Objects hidden from the GAL on-premises are also hidden from the GAL in Office 365

– Enables coexistence for Exchange

• Works in both simple and hybrid deployment scenarios

– Enabler for mail routing between on-premises and Office 365 with a shared domain namespace

– Enables coexistence for Microsoft Lync

Page 27: Andy Malone - The new office 365 for it pro's

Dirsync Password Synchronization

• No longer requires ADFS to provide SSO

– Does not sync plaintext passwords

– Dirsync syncs hashes of hashes of your user's passwords greatly reducing the risk of a password leaking

– You don't need to install any new software on your DCs or reboot DCs

– Users don't need to change passwords

– Password Syncing is 1 way. Users that have Password Sync enabled are required to change their passwords on premises in an AD connected machine.

– “In my opinion not as secure as ADFS”

Page 28: Andy Malone - The new office 365 for it pro's

Provisioning Office 365 with Dirsync

Page 29: Andy Malone - The new office 365 for it pro's
Page 30: Andy Malone - The new office 365 for it pro's

|Online

Page 31: Andy Malone - The new office 365 for it pro's

SharePoint Cloud Continuum

CONTROL

CO

ST

-EF

FIC

IEN

CY

SharePoint (On-premises)

Value Prop:• Full h/w control – size/scale

• Roll-your-own HA/DR/scale

Value Prop:• 100% of API surface area

• Easy migration of existing apps

• Roll-your-own HA/DR/scale

SharePoint (Windows Azure)

Value Prop:• Auto HA, Fault-Tolerance

• Friction-free scale

• Self-provisioning, mgmt @ scale

SharePoint Online (Office 365)

Page 32: Andy Malone - The new office 365 for it pro's

Layers of SharePoint Online

Services1+ services run within VM role Hundreds of services interacting

Virtual Machine RolesVMs performing different roles Units of scalability called “Networks”

PhysicalDatacenters Machines Physical network

Page 33: Andy Malone - The new office 365 for it pro's

SharePoint Online components• SharePoint – actual bits & features

– Same bits used in on-premises deployments– All features must conform to service fabric horizontals—”cloud ready”

• Service Fabric – components needed to run service– Deployment & Environments – Topology– Identity & Sign In– Provisioning Tenants & Users – Tenant Admin– Upgrade– High Availability & Disaster Recovery– Telemetry, Incident Management, Debugging & Patching Code in the Service

• Zoom in on topology, provisioning & upgrade– Deep dive into system topology & deployment, customers onboarding & upgrades

Page 34: Andy Malone - The new office 365 for it pro's

Office Web Apps• Consumer / Windows Live– Publicly available to any Live ID user– Free with SkyDrive & Outlook.com

(Hotmail)– Iterative release cadence

• On-Premise / Private Cloud– Runs as Office Web Apps Server– Integrates with SharePoint,

Exchange, File shares, etc.

– Minimal changes during life cycle

• Office 365 / Public Cloud– An option within the service– Monthly per-user subscription– 90-day service update cycle

34

Page 35: Andy Malone - The new office 365 for it pro's

Browser Requirements for Office 365

• Internet Explorer 8

• Safari 5

• latest Chrome

• Latest Firefox

Page 36: Andy Malone - The new office 365 for it pro's

SharePoint Online Topology

WFE

App Server

Crawl WFE

CA

Timer Jobs

Sandbox

Content:

Fed App

Fed Query

Fed CA

Fed Idx

Federated Services:

SQL SQL

SQL:

SQL SQL AD AD

Directory:

Stamp 1:

WFE

App Server

Crawl WFE

CA

Timer Jobs

Sandbox

Content:

Fed App

Fed Query

Fed CA

Fed Idx

Federated Services:

SQL SQL

SQL:

SQL SQL AD AD

Directory:

Stamp 2..N:

Network 1..N:

AD Sync

Prov.

SCOM

ULS

SPDiag

WER

DNS

SMTP

Admin

Backup

NLB

NLB

Datacenter 1..N:

WFE

App Server

Crawl WFE

CA

Timer Jobs

Sandbox

Content:

Fed App

Fed Query

Fed CA

Fed Idx

Federated Services:

SQL SQL

SQL:

SQL SQL AD AD

Directory:

Stamp 1:

WFE

App Server

Crawl WFE

CA

Timer Jobs

Sandbox

Content:

Fed App

Fed Query

Fed CA

Fed Idx

Federated Services:

SQL SQL

SQL:

SQL SQL AD AD

Directory:

Stamp 2..N:

Network 1..N:

AD Sync

Prov.

SCOM

ULS

SPDiag

WER

DNS

SMTP

Admin

Backup

NLB

NLB

Disaster Recovery Datacenter 1..N:

Grid Manager

Global Directory

Tenant Admin (UI)

Commerce backend

DNS (multiple)

OrgID Auth, Svc.

Incident Management

Azure (Windows/SQL)

CDN Services

Page 37: Andy Malone - The new office 365 for it pro's

Failure Scope

nonediskrackdc

Copy Count

124610+

Data CenterData Center

Rack 2Rack 1

Keeping Your Data Safe

Rack 3

save

RAID 10

synchronous

mirroring

asynchronous

log shipping

asynchronous

replicationscheduled

backupspoint-in-time

restore

recycle

bin

client side

cache

Page 38: Andy Malone - The new office 365 for it pro's

Office 365 SharePoint

Page 39: Andy Malone - The new office 365 for it pro's

|Online

Page 40: Andy Malone - The new office 365 for it pro's

Exchange —Work Smarter, Anywhere.

Tailor your solution based on your unique needs

Ensure your communications are always available

Manage increasing volumes of communications

Work together more effectively as teams

Protect business communications and sensitive information

Meet internal and regulatory compliance requirements

Do more, on any device

Keep the organization safe

Remain in control, online and on-premises

Page 41: Andy Malone - The new office 365 for it pro's

Copyright© Microsoft Corporation

Inline reply lets you compose

while staying in context

Quick Peeks that give you access to

your calendar, people and tasks

without leaving your inbox

Minimized ribbon is

just one touch away

Improved navigation takes less space

Touch Mode adds more space and

finger-friendly Quick Actions

Consolidate views from different

sources into a single contact card

Page 42: Andy Malone - The new office 365 for it pro's

Email, calendar, and contacts from

Outlook Web App

Additional features through native

integration with the device:

Stored credentials

Voice activated actions

Contact sync to native address book

Apps require Office 365 with the

latest update of Exchange Online

Page 43: Andy Malone - The new office 365 for it pro's

Copyright© Microsoft Corporation

Delegate administrative tasks to specialist users

Systems administrator

All

Page 44: Andy Malone - The new office 365 for it pro's

Copyright© Microsoft Corporation

Sender notifications

Admin notifications

Multi-engine protection from Exchange Online Protection (EOP)

Page 45: Andy Malone - The new office 365 for it pro's

Copyright© Microsoft Corporation

Block email based on language

Block email based on geography

New fingerprinting techniques from Exchange Online Protection (EOP)

Page 46: Andy Malone - The new office 365 for it pro's

Copyright© Microsoft Corporation

Policy details transparently

displayed to end user

Right click to assign policy to an

item, folder or to all your email

Centrally managed or user-assigned policies

Automated data retention and deletion

Page 47: Andy Malone - The new office 365 for it pro's

Copyright© Microsoft Corporation

A PolicyTip notifies you of a policy

violation while composing an email

Outlook PolicyTips notify users of policy violations before they happen

Page 48: Andy Malone - The new office 365 for it pro's

Copyright© Microsoft Corporation

DLP policy templates support major regulatory requirements

DLP reporting provides insight into organizational compliance

Templates based on regulatory

requirements

DLP reporting

Page 49: Andy Malone - The new office 365 for it pro's

Get instant

statistics

Use proximity searches to

understand context

Query results across

Exchange, Lync &

SharePoint

Laser focused refiners to help

find the data you need

Fine tune

complex queriesSearch Exchange, SharePoint, and Lync data from a single interface

Page 50: Andy Malone - The new office 365 for it pro's

Copyright© Microsoft Corporation

Update hybrid settings

Page 51: Andy Malone - The new office 365 for it pro's

experiences

Lync

Page 52: Andy Malone - The new office 365 for it pro's

Exchange Online

Page 53: Andy Malone - The new office 365 for it pro's

Top Tips & Final Thoughts• Choose Correct 365 Solution

• Sign up for a free trial

• Subscriptions yearly

• Options available for• Kiosk Plans (Basic browser based,

pop email etc)

• Home Premium

• Small Business (P Plans)

• Enterprise (E Plans)

Page 54: Andy Malone - The new office 365 for it pro's

Top Tips & Final Thoughts

• Product V.s. Service

• Clean House, users, mailboxes etc

• To SSO or not to SSO?

• Read the Planning Guides

• Region V.s. Compliance!

• Get your DNS Correct

• Watch out for Expiring SSL Certs

• Beware the Deleted Domains!

Page 55: Andy Malone - The new office 365 for it pro's

Review…

Page 56: Andy Malone - The new office 365 for it pro's

The Extras…Follow @AndyMalone & Get my SkyDrive Link

Page 57: Andy Malone - The new office 365 for it pro's

Tools

Exchange Remote Connectivity Analyzerhttps://www.testexchangeconnectivity.com/

Exchange Client Network Bandwidth Calculatorhttp://gallery.technet.microsoft.com/Exchange-Client-Network-8af1bf00

PST Capturehttp://www.microsoft.com/en-us/download/details.aspx

PowerShell Scriptshttp://technet.microsoft.com/en-us/library/hh974318.aspx

Page 58: Andy Malone - The new office 365 for it pro's

Please evaluate the sessionbefore you leave