{"id":144,"date":"2013-02-27T20:29:29","date_gmt":"2013-02-27T19:29:29","guid":{"rendered":"http:\/\/powerkjell.com\/?p=144"},"modified":"2013-02-27T20:29:29","modified_gmt":"2013-02-27T19:29:29","slug":"setting-up-office-365","status":"publish","type":"post","link":"https:\/\/powerkjell.com\/?p=144","title":{"rendered":"Setting up Office 365"},"content":{"rendered":"<p>This is a quick guide how to set up Office 365 according to Microsoft best practice. This is what the setup looks like:<\/p>\n<p><a href=\"http:\/\/powerkjell.com\/wp-content\/uploads\/2013\/02\/Office-365.jpg\"><img decoding=\"async\" loading=\"lazy\" class=\"alignnone size-full wp-image-145\" title=\"Office 365\" src=\"http:\/\/powerkjell.com\/wp-content\/uploads\/2013\/02\/Office-365.jpg\" alt=\"\" width=\"1173\" height=\"488\" srcset=\"https:\/\/powerkjell.com\/wp-content\/uploads\/2013\/02\/Office-365.jpg 1173w, https:\/\/powerkjell.com\/wp-content\/uploads\/2013\/02\/Office-365-300x124.jpg 300w, https:\/\/powerkjell.com\/wp-content\/uploads\/2013\/02\/Office-365-1024x426.jpg 1024w, https:\/\/powerkjell.com\/wp-content\/uploads\/2013\/02\/Office-365-500x208.jpg 500w\" sizes=\"(max-width: 1173px) 100vw, 1173px\" \/><\/a><\/p>\n<p>This is what you need:<\/p>\n<ul>\n<li>Windows Server 2008 R2 for DirSync.<\/li>\n<li>Windows Server 2008 R2 for ADFS federation. This can be a domain controller.<\/li>\n<li>Windows Server 2008 R2 for ADFS federation proxy in DMZ. This can be an IIS.<\/li>\n<li>Account to log into these machines. This account needs to be local admin to be able to install DirSync and ADFS.<\/li>\n<li>Account that is member of Enterprise Admins. This account is needed to configure DirSync. A service account, <strong>MSOL_AD_SYNC<\/strong>, is created in Users container.<\/li>\n<li>Active Directory service account for ADFS, e.g. <strong>ADFS2SVC<\/strong>.<\/li>\n<li>SSL certificate for ADFS, e.g. <strong>fs.powerkjell.com<\/strong>. This certificate needs to be added to IIS of both ADFS and ADFS proxy servers.<\/li>\n<li>External DNS record for <strong>fs.powerkjell.com <\/strong>to point at ADFS proxy. In internal DNS it should point at internal ADFS.<\/li>\n<\/ul>\n<p>Information about setting up DirSync: <a href=\"http:\/\/technet.microsoft.com\/en-us\/library\/hh967642.aspx\">http:\/\/technet.microsoft.com\/en-us\/library\/hh967642.aspx<\/a><\/p>\n<ul>\n<li>Remember to check your environment using <a title=\"Microsoft Deployment Readiness Tool\" href=\"http:\/\/go.microsoft.com\/fwlink\/p\/?linkid=235650\" target=\"_blank\">Microsoft Deployment Readiness Tool<\/a> and to activate DirSync using <a href=\"https:\/\/portal.microsoftonline.com\">https:\/\/portal.microsoftonline.com<\/a>. This may take up to 24 hours to apply. Read more about preparations here: <a href=\"http:\/\/technet.microsoft.com\/en-us\/library\/jj151831.aspx\">http:\/\/technet.microsoft.com\/en-us\/library\/jj151831.aspx<\/a><\/li>\n<li>Create a sync account in Office 365 and set the alternative e-mail address to a monitored address for\u00a0catching DirSync errors.<\/li>\n<li>Do not start DirSync immediately in case you need to configure DirSync: <a href=\"http:\/\/technet.microsoft.com\/en-us\/library\/hh967629.aspx\">http:\/\/technet.microsoft.com\/en-us\/library\/hh967629.aspx<\/a><\/li>\n<li>Make sure you understand mapped attributes: <a href=\"http:\/\/support.microsoft.com\/kb\/2256198\/en-us\">http:\/\/support.microsoft.com\/kb\/2256198\/en-us<\/a><\/li>\n<\/ul>\n<p>Read more about SSO with ADFS: <a href=\"http:\/\/technet.microsoft.com\/en-us\/library\/hh967628.aspx\">http:\/\/technet.microsoft.com\/en-us\/library\/hh967628.aspx<\/a><\/p>\n<ul>\n<li>Make sure you have the service account created.<\/li>\n<li>Make sure you have the SSL certificate available.<\/li>\n<li>You may need an account with higher priviledges when configuring ADFS on first server, since it creates a\u00a0container in Active Directory.<\/li>\n<li>Make sure DNS records are correct. ADFS proxy needs to finns ADFS on <strong>fs.powerkjell.com<\/strong>.<\/li>\n<li>Run the Powershell commands to create a trust to Office 365 from ADFS (not ADFS proxy).<\/li>\n<\/ul>\n<p>According to the recommendations from Microsoft you need load balanced ADFS and ADFS proxy servers, which means they should be at least\u00a0two on each side.<\/p>\n<p>Good luck!<\/p>\n","protected":false},"excerpt":{"rendered":"<p>This is a quick guide how to set up Office 365 according to Microsoft best practice. This is what the setup looks like: This is what you need: Windows Server 2008 R2 for DirSync. Windows Server 2008 R2 for ADFS &hellip; <a href=\"https:\/\/powerkjell.com\/?p=144\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[3],"tags":[9,6],"_links":{"self":[{"href":"https:\/\/powerkjell.com\/index.php?rest_route=\/wp\/v2\/posts\/144"}],"collection":[{"href":"https:\/\/powerkjell.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/powerkjell.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/powerkjell.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/powerkjell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=144"}],"version-history":[{"count":4,"href":"https:\/\/powerkjell.com\/index.php?rest_route=\/wp\/v2\/posts\/144\/revisions"}],"predecessor-version":[{"id":149,"href":"https:\/\/powerkjell.com\/index.php?rest_route=\/wp\/v2\/posts\/144\/revisions\/149"}],"wp:attachment":[{"href":"https:\/\/powerkjell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=144"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/powerkjell.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=144"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/powerkjell.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=144"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}