• Office 365 ProPlus benefit FAQ

    Great news! We just publically announced today at Educause that Office 365 ProPlus will be offered to students at no additional charge if all your faculty and staff are already licensed for Office 2013 Professional Plus via EES/OVSES agreement or via Office 365 ProPlus subscription.

    This is incredible news for students as they can now take advantage of all that Office 365 ProPlus has to offer.

    I put together a quick FAQ for what this means for your education institution:

    What is included with Office 365 ProPlus subscription license?

      • Office 365 ProPlus for PC (Office 2013 ProPlus base applications)
      • Office 365 ProPlus for Mac (Office 2011 for Mac base applications)
      • Office for iPad (see here for new update 3.27.14)
          

    How many machines/devices can I run this subscription on?

    Each subscription license allows you to run Office on up to five machines being Mac or PC. You can also run Office for iPad on up to 5 tablets.

    Is this a full version Office and available for offline use?

    Yes, this is full Office on the PC, Mac, tablet, mobile platform and all are available for offline use.

    What applications come with Office 365 ProPlus for PC?

    image

    Word 2013

    Excel 2013

    PowerPoint 2013

    OneNote 2013

    Access 2013

    Publisher 2013

    Outlook 2013

    Lync 2013

    InfoPath 2013

    What comes with Office 365 ProPlus for Mac?

    image

    Word 2011

    Excel 2011

    PowerPoint 2011

    Outlook 2011

    What comes with Office Mobile for iPhone? (update 3.27.14 – now free)

    image

    Word Mobile

    Excel Mobile

    PowerPoint Mobile

    OneNote and Lync Mobile available as separate download.

    See here for more options.


    What comes with Office Mobile for Android? (update 3.27.14 – now free)

    image

    Word Mobile

    Excel Mobile

    PowerPoint Mobile

    OneNote and Lync Mobile available as separate download

    See here for more options.

    What are the PC requirements for Office 365 ProPlus?

    • Windows Server 2008 R2
    • Windows 7
    • Windows Server 2012
    • Windows 8

    32-bit Office can be installed on 32-bit or 64-bit operating systems and 64-bit Office can only be installed on 64-bit operating systems.

    Computer and processor
    1 GHZ or faster x86 or 64-bit processor with SSE2 instruction set.

    Memory

    1 GB RAM (32-bit)

    2 GB RAM (64-bit) recommended for graphics features, Outlook Instant Search, and certain advanced functionality.

    Disk space
    3 gigabytes (GB)

    Monitor resolution
    1024 x 768


    What are the Mac requirements for Office 365 ProPlus?

    • A Mac computer with an Intel processor.
    • Mac OS X version 10.5.8 or later.
    • 1 GB of RAM recommended.
    • 2.5 GB of available hard disk space.
    • HFS+ hard disk format (also known as Mac OS Extended or HFS Plus).
    • DVD drive or connection to a local area network (if installing over a network).
    • 1280 x 768 or higher resolution monitor

    What are the iPhone requirements for Office Mobile for iPhone?

    iPhone 4

    iPhone 5

    iPhone 5s

    iPod Touch 5th generation

    All devices above must be running iOS 6.1 minimum

    What about Office on the iPad?

    Office for iPad is now available as of 3.27.14.  See new blog post for details here.

    What are the Android requirements for Office Mobile for Android?

    Android OS 4.0 or greater

    Android touch enabled smartphones only

    Do students have to sign into Office 365 to use any of these applications with Office 365 ProPlus?

    image

    Yes, a valid Office 365 ProPlus license tied to a valid Office 365 login for students is required to enable any of the four Office 365 ProPlus features.

    How long can a student leverage Office 365 ProPlus?

    The guidelines are they can leverage this until they graduate or are no longer attending your school. At that point, you must disable their Office 365 ProPlus license.

    How is this different from Office 2013 Professional Plus?

    The Office 2013 applications are exactly the same however there are some differences including patching, license sign in for usage, and Click-to-run (C2R) technology for rapid installs (2 minutes for quick usage).

    Can I run a local image of Office 365 ProPlus to install from and can I customize the install share?

    Yes, you can install Office 365 ProPlus for PC from a local share and still leverage C2R technology for a few minutes installation of Office and with the Office Deployment Tool you can also customize the Office installation. See here for more instructions

    Where can I get training on Office 365 ProPlus?

    There is some excellent end user training on Office 2013 here.

    There is some excellent end user training on Office for Mac 2011 here:

    Some end user help guides on Office Mobile for iPhone here and here.

    Some end user help guides on Office Mobile for Android here and here.

    Some end user Office for iPad training here:

    Is there a deployment guide for Office 365 ProPlus?

    Yes, there is an excellent IT Pro reference guide here and see my deployment blog post here.

    When can I obtain this license for my students?

    You can order it through your reseller. Please see these three part series on “How to get Student Advantage” - partI, partII, and partIII for guidance. Here is a new “Student Advantage Deployment Guide”.

  • Get a Room! Enable Room Finder with Room List Distribution Groups

    If your Exchange Online (Office 365) or Outlook Live (Live@edu) users are already using Room Mailboxes to schedule meetings in conference rooms, auditoriums, labs or other facilities, then why not enable Room Finder for your Microsoft Office Outlook 2010 clients by configuring Room List Distribution Groups?

    Room Finder simplifies the process of searching for an available room while setting up a meeting. Instead of adding all possible conference rooms to a meeting request and using the Scheduling Assistant to identify available rooms, meeting organizers can use Room Finder to show a room list, see suggested times, and choose an available room.

     

    Room Finder in Outlook 2010 
    without Room Lists
    Room Finder in Outlook 2010 
    with Room Lists
    room-finder-without-room-list-distribution-groups room-finder-with-room-list-distribution-groups-2

     

    How do I enable Room Finder?

    A messaging administrator can enable Room Finder for Outlook 2010 clients in a few easy steps: (1) Connect to Exchange Online or Outlook Live using Windows PowerShell; (2) Create Room List Distribution Groups; (3) Add existing Room Mailboxes to Room List Distribution Groups. 

    Outlook 2010 detects the Room List Distribution Groups automatically and populates the Room Finder with room lists, available rooms and suggested meeting times.

     

    Connect to Exchange Online or Outlook Live using Windows PowerShell

     

    Create Room List Distribution Groups

    New-DistributionGroup -Name "Name of Room List" –RoomList creates a new Room List Distribution Group using the cmdlet’s minimum required parameters for a Room List Distribution Group. If you don’t specify any additional parameters, then they will be set for you.

    You may want to take control of your recipient object’s attributes by using additional parameters, e.g. –Alias, –DisplayName, –PrimarySmtpAddress, etc. You can find a full list of available parameters at TechNet New-DistributionGroup: Exchange 2010 SP1 Help.

    New-DistributionGroup -Name Bldg_HUB -DisplayName "Student Union Building Conf Rooms" –PrimarySmtpAddress Bldg_HUB@contoso.edu –RoomList

     

    Add existing Room Mailboxes to Room List Distribution Groups

    Add-DistributionGroupMember –Identity "Name of Room List" –Member "Name of Room Mailbox" adds Room Mailboxes to Room List Distribution Groups. It requires that you specify the Room List Distribution Group using the –Identity parameter and the Room Mailbox to be added using the –Member parameter.

    Add-DistributionGroupMember –Identity Bldg_HUB -Member Room_HUB1001
    Add-DistributionGroupMember –Identity Bldg_HUB -Member Room_HUB1002

    You can use the DisplayName, Identity, PrimarySmtpAddress and various other values with the –Identity and –Member parameters. You might find it helpful to list them.

    The following command will list the Room List Distribution Groups.

    Get-DistributionGroup | Where {$_.RecipientTypeDetails -eq "RoomList"} | Format-Table DisplayName,Identity,PrimarySmtpAddress

    The following command will list the existing Room Mailboxes.

    Get-Mailbox | Where-Object {$_.RecipientTypeDetails -eq "RoomMailbox"} | Format-Table DisplayName,Identity,PrimarySmtpAddress

     

    ______________________________

    Thanks for joining us today!

    Zion Brewer

    ______________________________

  • OneDrive for Business FAQ

    image

    I get asked a lot of questions about OneDrive for Business from customers so I have put together a quick FAQ to help:

    How many OneDrives are there? I see one in Windows 8 and then I see one with Office 365 Education. I also see SkyDrive and SkyDrive Pro.  What are the differences?

    There are two OneDrive offerings available. One is our consumer OneDrive, formerly known as SkyDrive, which comes with 7GB of free storage and is catered towards personal storage use.  The other offering comes with Office 365 and is called OneDrive for Business, formerly known as SkyDrive Pro, which requires a valid Office 365 login to leverage. The default storage is now 1TB for OneDrive for Business.

    Here is a matrix with the differences:

    image

    Can I use the OneDrive consumer sync technology with OneDrive for Business?

    No, the OneDrive sync integration with Mac, Vista, Windows 7, 8 and 8.1 does not sync to OneDrive for Business.  There are different folder sync technologies required specifically for OneDrive for Business and currently we only have Windows 7, 8, and 8.1 folder sync clients. Mac client is slated for later this year.

    image

    Grab all the OneDrive and OneDrive for Business sync clients here.

    Can I use the OneDrive consumer mobile apps with OneDrive for Business?

    No, these are also separate mobile and tablet apps for OneDrive for Business.

    image

    To download those apps on for tablet, Android, iOS visit here.

    Can I have both OneDrive consumer and OneDrive for Business installed on the same computer? 

    Yes, you can have both sync clients installed and there is no collision between the two sync technologies.

    image

    both OneDrive sync technologies installed

    What are the ways I can get the OneDrive for Business sync client?

    There are two ways to obtain the OneDrive for Business sync client:

    1) It is automatically installed with the following Office 2013 installations:

      • Office Professional Plus 2013
      • Office 365 E3/A3 SKU which includes Office 365 ProPlus
      • Office 365 Midsize Business
      • Office 365 Small Business Premium
      • Student Advantage (Office 365 ProPlus for Students)

    2) If you do not have Office Professional Plus 2013 installed via one of the versions above, you can download a separate OneDrive for Business client with the download links above for Windows 8.1, Windows 8, Windows 7.

    See herefor more manual installation steps of OneDrive for Business if needed.    

    Can I setup OneDrive for Business Sync automatically for users?

    Unfortunately, there is no way to do this currently. The only current method is to have the end users click ‘Sync’ inside of OneDrive for Business.  See here for more directions.

    image

    Can I map a drive to OneDrive for Business?

    Currently, there are methods I have heard of however they have mixed results with this. See here and here for steps. There is also new unsupported code available to help with mapping a drive to OneDrive for Business via a login script. See here.   One example I have seen work from a command line is (replace tenant with your tenant name) and you must make sure the WebDAV service is running:

    Net use w: \\tenant-my.sharepoint.com@SSL\DavWWWRoot\Personal\user_domain_com/documents /PERSISTENT:yes

    Can I preprovision OneDrive for Business so my endusers don’t have to wait to use on first time use?

    Yes, there is a way to preprovision OneDrive for Business using the new CSOM API.  See sample code here and here.

    Can I redirect my local folders (\documents, \pictures, etc) via Group Policy to OneDrive for Business?

    Yes, there is a way to do this using environment variable mappings.  Please see steps here.      

    .

  • What firewall ports do I need open to connect to Office 365 for Education?

    This was a question for a large university in Arizona moving faculty, staff and students to Office 365.

    Here are the ports from the deployment guide (note: these are subject to change so refer here to the latest Port and IP list):

    image

     

    *SMTP Relay with Exchange Online requires TCP port 587 and requires TLS. See TechNet for details on how to configure SMTP Relay with Exchange Online. Note: you will need to provide the SMTP server which is specific to the mailbox used for relay. See the TechNet article Set Up Outlook 2007 for IMAP or POP Access to Your E-Mail Account.

    ** POP3 access with Exchange Online requires TCP port 995 ) and requires SSL. See TechNet for details on how to configure POP3 with Exchange Online.

     

    Can I lock it down to certain IP ranges, URLs/servers?

    Yes, here are the IP ranges and URLs/Servers:

    Office 365 portal

    image

     

    Microsoft online services sign in:

    image

     

    Exchange Online sign in and authentication:

    207.46.150.128/25
    157.55.59.128/25
    *.microsoftonline.com
    *.microsoftonline-p.com
    *.microsoftonline-p.net
    *.microsoftonlineimages.com
    *.microsoftonlinesupport.net

     

    Exchange Online servers: note: only need  IP ranges for your geographic region

    Americas

    65.54.62.0/25
    65.55.39.128/25
    65.55.78.128/25
    65.55.94.0/25
    65.55.113.64/26
    65.55.126.0/25
    65.55.174.0/25
    65.55.181.128/25
    70.37.151.128/25
    157.55.49.0/25
    157.55.49.128/25
    157.55.61.0/25
    157.55.61.128/25
    157.55.157.128/25
    157.56.24.0/25
    157.56.234.0/28
    157.56.234.16/29
    157.56.234.24/29
    157.56.234.32/28
    157.56.234.48/28
    157.56.234.64/28
    157.56.236.0/28
    157.56.236.16/28
    157.56.236.32/29
    157.56.236.40/29
    157.56.236.48/28
    157.56.236.64/28
    157.56.240.0/28
    157.56.240.16/28
    157.56.240.32/29
    157.56.240.40/29
    157.56.240.48/28
    157.56.240.64/28
    157.56.244.0/28
    157.56.244.16/29
    157.56.244.24/29
    157.56.244.32/28
    157.56.244.48/28
    157.56.244.64/28
    207.46.4.128/25
    207.46.198.0/25
    207.46.203.128/26

    Europe

    94.245.117.128/25
    157.55.9.128/25
    157.55.11.0/25
    157.55.47.0/25
    157.55.47.128/25
    157.55.224.128/25
    157.55.225.0/25
    213.199.174.0/25
    213.199.177.0/26

    Asia-Pacific

    111.221.23.128/25
    111.221.66.0/25
    111.221.69.128/25
    207.46.58.128/25

    Microsoft Federation Gateway – required for federated delegation and hybrid deployments

    207.46.150.128/25
    207.46.164.0/24
    *.microsoftonline-p.com
    *.live.com
    *.microsoftonline.com
    *.microsoftonlinesupport.net

    FOPE URLs and IP addresses

    • 12.129.20.0/24
    • 12.129.199.61
    • 12.129.219.155
    • 63.241.222.0/24
    • 65.55.88.0/24
    • 94.245.120.64/26
    • 206.16.57.70
    • 207.46.51.64/26
    • 207.46.163.0/24
    • 213.199.154.0/24
    • 213.199.180.128/26
    • 216.32.180.0/24
    • 216.32.181.0/24

    CIDR format

    • 12.129.20.0/24 = 12.129.20.1 - 12.129.20.254
    • 63.241.222.0/24 = 63.241.222.1 - 63.241.222.254
    • 65.55.88.0/24 = 65.55.88.1 - 65.55.88.254
    • 94.245.120.64/26 = 94.245.120.65 – 94.245.120.126
    • 207.46.51.64/26 = 207.46.51.65 - 207.46.51.126
    • 207.46.163.0/24 = 207.46.163.1 - 207.46.163.254
    • 213.199.154.0/24 = 213.199.154.1 - 213.199.154.254
    • 213.199.180.128/26 = 213.199.180.129 – 213.199.180.190
    • 216.32.180.0/24 = 216.32.180.1 - 216.32.180.254
    • 216.32.181.0/24 = 216.32.181.1 - 216.32.181.254

    Lync Online URLs and Servers

    IP Ranges

    • 111.221.17.128/27
    • 111.221.22.64/26
    • 111.221.23.0/25
    • 157.55.104.96/27
    • 157.55.229.128/27
    • 157.55.238.0/25
    • 157.55.40.128/25
    • 157.55.46.0/27
    • 157.55.46.64/26
    • 207.46.5.0/24
    • 207.46.57.0/25
    • 207.46.7.128/27
    • 65.54.54.128/25
    • 65.55.121.128/27
    • 65.55.127.0/24

    Lync Online URLs

    • *.online.lync.com
    • *.onmicrosoft.com
    • *.infra.lync.com
    • *.lync.com
  • New Azure Active Directory Sync tool with Password Sync is now available

    This release has been a capability which has generated a lot of interest with my customers going with Office 365 Education.  I have put together a quick FAQ to help with this.

     

    What is Azure Active Directory Dirsync with Password Sync?

    Formerly known as Dirsync, this tool has been updated to allow for the synchronization of local Active Directory passwords to Azure Active Directory. in addition to the syncing of users, groups and contacts.  This new feature will allow for Same Sign In with Microsoft cloud services such as Office 365 Education powered by Azure Active Directory since the username and the password from local AD will by synced up to Azure AD.  See here on TechNet for more details.

     

    Where can I get the new Dirsync with Password sync bits?

    You can grab the latest version of Dirsync here or it is available in the Office 365 portal under ‘users'  and then Dirsync.

     

    What version of Dirsync has Dirsync with Password sync?

    Dirsync with password sync is available in versions 1.0.6385.12 or newer version.

     

    How can I quickly tell if I have the right version downloaded?

    image

    The first way you can tell is by size. The file size is about 183+MB vs. the older version is 99MB.  The other way you can tell is by the icon. The application icon should be our new Windows logo with the four blue squares. The final way to confirm this is by hovering over the dirsync download and check the version the version with Dirsync with password sync or later is: 

    image

     

     

     

    note: I renamed the default ‘dirsync’ filename since I already had the older dirsync in the same directory.

     

    What do I need to do to replace my older dirsync?

    You do have to remove the existing installation of Dirsync prior to installing the new version with password sync.

    You don’t need to remove other components such as SIA or SQL express. I left everything else in place. Here is the setup I did on an existing Dirsync Server:

    1) Important: If using ADFS with federated ID, you must first convert your domain namespace to managed ID PRIOR to installing and running Dirsync with password sync. See steps below under “What if I am federated…”

    2) Remove existing Dirsync application from control panel.

    3) I took screenshots of the rest:

    clip_image001

    clip_image002

    clip_image003

    clip_image004

    clip_image005

    clip_image006

    clip_image007

    clip_image008

    clip_image009

    clip_image010

    clip_image011

    clip_image012

     

    What if I am federated and using ADFS and want to switch to Dirsync with Password Sync?

    You will need to convert your domain from federated to managed.  Using the

    convert-msoldomaintostandard –domainname foo.edu –skipuserconversion $false –passwordfile c:\password.txt 

    Azure AD cmdlet.   See here on TechNet for more details.  Note: the password file is for dumping all users temporary passwords into.

     

     

    How can I tell if it is configured correctly for Dirsync with Password Sync?

    You should see event ID 656 and 657 in your application event log to show that it is syncing the password hash to the cloud.

     

     image

     

    What are the advantages of Dirsync with Password Sync vs. ADFS?

    There are a couple of advantages of using Dirsync with Password Sync over using ADFS 2.1 with Dirsync:

     

    1) A single server is needed vs. redundant and scaled out ADFS servers.

    2) No dependency with on prem hardware/data center – if Dirsync with Password Sync server dies – just replace it. There is no impact accessing cloud services with an onprem outage because the identity is a managed identity in Azure AD vs. a federated identity using ADFS 2.1.

    3) No complex ADFS architectures – No ADFS Proxies, load balancers, certificate management are required. It keeps the deployment less complex with fewer moving parts.

     

     

    What are the disadvantages of Dirsync with Password Sync vs. ADFS?

    ADFS 2.1 with federated login provides true Single Sign On (SSO) with Office 365 where as Dirsync with Password Sync allows for Same Sign On which implies users will be prompted for credentials when accessing Office 365 even in domain joined scenarios.  ADFS 2.1 also allows for better access control based on IPs, etc.

     

    Where can I find more information on troubleshooting Dirsync with Password Sync?

    There is an excellent KB article here to help you.