presentation title goes here - microsoft azuremsservicesday.azurewebsites.net/content... · yammer...

50

Upload: others

Post on 16-Jul-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an
Page 2: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

About

SharePoint Online and On-Premises

Development & Infrastructure

Doing SharePoint since 2001

Page 3: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an
Page 4: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an
Page 5: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Hub for TeamworkCo-AuthorConnect Across

the OrganizationIntranets &

Content Management

Email & Calendar

TeamsOffice AppsYammerSharePointOutlook

Office 365 GroupsSingle team membership

across apps and services

Microsoft GraphSuite-wide intelligence

connecting people and content

Security and ComplianceCentralized policy management

Page 6: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

SharePoint

SharePoint Online AD

- Documents - OneNote

Additional workloads

Workload scenarios

LocalDirectory

(if applicable)

Exchange

- Conversations - Calendar

Exchange Online AD

- Identity- Resource URLs- Owners- Members

Azure Active Directory

Page 7: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Office 365 Groups

Outer Loop Inner Loop FilesSites

Content

SharePoint

Email

Page 8: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Apps

One identity Federated resources Loose coupling

Azure AD is the master for

group identity & membership

Office 365 services extend with

their data

Service notify each other of

changes to a group

Attributes

FlowUser creates new group

for teamwork

Group experience

populated in app of

choice

Group identity created in

Azure Active Directory

Page 9: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

of employees believe IT is ineffective at providing collaboration,

data analysis, and mobility capabilities.60%

80%

Establish IT leadership eBook, Microsoft 2017

Page 10: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

OPEN

CONTROLLED

Processes in place

Reporting & monitoring

Change management

Page 11: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an
Page 13: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Benefits

Guidance

Documentation: Office 365 Groups Naming Policy

Page 14: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

What if our user attributes are quite long? Will it impact group creation?

Yes, group alias is restricted to 64 chars and group name to 256 chars. So longer user attributes used as

prefixes/suffixes could block group creation in your organization

Can we use extension attributes and custom attributes?

Extension attributes and custom attributes are currently not supported

Can we have different naming policies for each group workload?

No, this will be a tenant wide policy and will apply to all group workloads

Can we create rule based policy where we can apply prefixes only for users in a

specific department?

We currently do not support rule based policy application. We suggest that you leverage user attributes for

these scenarios

Is this a premium feature?

Yes, Group naming policy requires Azure AD Premium P1 license for unique users that are members of Office

365 groups in tenants.

Page 16: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an
Page 17: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

CmdletsAdd-AzureADMSLifecyclePolicyGroup

Get-AzureADMSGroupLifecyclePolicy

Get-AzureADMSLifecyclePolicyGroup

New-AzureADMSGroupLifecyclePolicy

Remove-AzureADMSGroupLifecyclePolicy

Remove-AzureADMSLifecyclePolicyGroup

Reset-AzureADMSLifeCycleGroup

Set-AzureADMSGroupLifecyclePolicy

Release Notes

Connect to Azure AD: Open AAD powershell with admin permissions and do

> Connect-AzureAD // Provide tenant admin credentials.

View current settings:

Get-AzureADMSGroupLifecyclePolicy

Setup new policy:

> New-AzureADMSGroupLifecyclePolicy -GroupLifetimeInDays 31 -ManagedGroupTypes All -AlternateNotificationEmails [email protected]

Update of current policy

> Set-AzureADMSGroupLifecyclePolicy -Id "9988f760-990b-47f7-9d87-549b929b605f" -GroupLifetimeInDays 32 -AlternateNotificationEmails [email protected]

Reset of Group Expiration Date (updating the RenewedDateTime property on a group to the current DateTime)

> Reset-AzureADMSLifeCycleGroup -GroupId <String>

Page 18: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Group Owner

• Renew expired groups

• Restore expired groups that

were soft deleted

Page 19: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Pilot with select groups

Define a goal on which groups you want to expire

Get groups older than X days

> $date = Get-Date.AddDays(-X); > Get-UnifiedGroup -Filter {WhenCreatedUTC -le $date} -ResultSizeUnlimited

Get Ownerless groups

> Get-UnifiedGroup -ResultSize Unlimited -filter {ManagedBy -eq $null}

Page 20: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Build a strategy for Orphaned groupsCreate a different email notification template to revert back to the IT admin from the group members, for

self-nomination of the person who reverts back and set them as group owners

Survey Pilot Users

To check if the owners noticed the expiry notification and to check the renewal rate

Page 21: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Roll out in phases

If your ultimate motive is to expire groups older than 6 months, start with 12 months - check the renewal rate, and

then proceed with 9 months and then finally 6 months

Onboard the Helpdesk team

Appraise the Helpdesk team of the prospective of getting more tickets during the soft deletion period of 30 days

for the groups that were not renewed and expired

If you have specific support teams for each workload such as Microsoft Teams, Sharepoint site, etc. you would

need to onboard all of them since the groups created across workloads will expire with the group expiration policy

Page 22: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Can I set an option to expire groups that are inactive?

This is not currently supported. The expiration policy is applied based on group creation date.

Can we change the expiry notification intervals?

The expiry notification intervals are fixed to 30 days, 15 days and 1 day prior to expiry and cannot be changed.

Can we apply expiration policy to specific group workloads?

The expiration policy applies to all groups workloads and it cannot be set for specific group workloads.

What happens to expiring groups if I have setup an Advanced retention policy in

Security and Compliance Portal?

When a group expires and gets soft deleted, the group’s conversations in mail box and files in the group site are

retained in the retention container for the specific number of days defined in the retention policy. Refer link for more

details.

Is this a premium feature?

Yes, Group expiration policy requires Azure AD Premium P1 license for unique users that are members of Office 365

groups in tenants.

Page 24: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Admin (EAC)

• Soft Delete groups

• View Soft Deleted groups and

when it was soft deleted

• Restore soft deleted groups

Admin Tool

• Azure AD powershell – Supported

• Exchange Admin Center – Supported

• Exchange powershell - Supported

• Office Admin Center – Not yet

supported

Page 25: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Admin (AAD powershell)

• Soft Delete groups

• View Soft Deleted groups and when it

was soft deleted

• Hard Delete groups

• Restore soft deleted groups

Note!

• Remove-MsolGroup purges the

group permanently

• Always use Remove-

AzureADMSGroup to delete an O365

group

• Restore might take some time

1. Get all the Groups

> Get-AzureADGroup

2. Soft Delete a specific group

> Remove-AzureADGroup -ObjectId b7d81c81-9b77-40c5-b50a-b1017e8d6c27

3. Show all Soft Deleted Groups

> Get-AzureADMSDeletedGroup

4. Restore a specific soft deleted group

> Restore-AzureADMSDeletedDirectoryObject -Id b7d81c81-9b77-40c5-b50a-b1017e8d6c27

5. Hard Delete a Group

> Remove-AzureADMSDeletedDirectoryObject – Id <objectId of the soft deleted object.>

Page 26: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Can I change the soft deletion period of 30 days?

Can I restore a soft deleted group, if another group with the same name exists?

Can I soft delete a group if the group mailbox is on legal hold?

Can I soft delete a group if I have setup an Advanced retention policy in the Security

and Compliance Center?

link

Page 27: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an
Page 31: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Groups Activity across workloadsAdmin can view group activity across Group mailbox Conversations, Group site/files activity, Yammer group activity

Page 32: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Audit Logs in the

Azure AD Admin

Portal

Audit Log Search in

Security and

Compliance Center

Page 33: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Group Activities that are logged and can be audited

Added group

Updated group

Deleted group

Added member to group

Removed member from group

Page 34: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Options

Page 35: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Policy enforcement for groups in Microsoft Enabled

Enable self-service Yes

Collect classification Yes

User awareness Yes

Usage guideline Yes

Set public vs. private based on classification Yes (Custom)

Guest access/external based on classification (HBI) No (future)

Guest membership disallowed with classification (HBI) Yes (Custom)

Page 36: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

• Guest inviter role - Setup a

policy so that users with this

role can only invite guest

• This can be set using user AD

properties such - Title, Job

Description

Reach

• Admins can create an

allow/deny list of

external partner

domains that are

allowed to be added as

guests.

• Guest approved by IT admin

can be approved and added

to groups..• Add guests through B2B

portal and turn off sharing

for tenant

Page 37: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an
Page 38: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Rolling Out

In Development

Page 39: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an
Page 40: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

goals

pilot

Office ProPlus

successful

▪ Upgrade

Page 41: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an
Page 42: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

AAD connect for hybrid

Distribution List, Public Folders Migration

Public Folder Migration | Upgrade DL’s to Groups | Configure Office 365 Groups with on-premises Exchange

Page 43: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Why you should upgrade your DL to groups in Outlook aka.ms/whyupgradedls

Upgrade with one click via Exchange admin center or via PowerShell scripts

Page 44: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Proper Setup of Yammer Network

Yammer identity management

Enable Group creation through Yammer

(Big) Advantage!

Page 45: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Link an existing private group to a Microsoft Team

Use main Planner Site for Group plannings

Page 46: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an
Page 47: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Access group data using the Microsoft Graph API:https://graph.microsoft.com/v1.0/groups

• Group creation

• Membership updates;

• Sender restrictions, thread operations

Keep users updated with notificationshttps://dev.outlook.com/Connectors https://dev.office.com/teams https://dev.office.com/sharepoint

Conversations

DocumentsCalendar

Tasks

Photo

Notes

Page 48: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

Capability Free Premium

P1

Create, read, update, delete X

Group activities report X

Soft-delete & restore X

Hidden membership X

Dynamic group membership X

Self-Service group management X

Group creation permissions X

Groups naming convention X

Groups expiration X

Usage guidelines X

Default classification X

Documentation: What is Azure Active Directory? | Azure Active Directory pricing

Page 49: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an

50

Q&A

Page 50: Presentation title goes here - Microsoft Azuremsservicesday.azurewebsites.net/Content... · Yammer identity management Enable Group creation through Yammer (Big) Advantage! Link an