• Unlocking Live@edu accounts and other password reset options

    If you have the opportunity to take a vacation to some exotic location this holiday season…Congratulations! You deserve it.

    But keep in mind that your Live@edu users may be planning to do the same.

    Whether it’s a trip to the mountains, the beach, somewhere close or somewhere far away, an interesting thing happens when people relax, unwind, and unplug. People forget their passwords.

    Research studies show that it is impossible for human beings to remember account passwords after “being offline” for more than three consecutive days. Kidding…I have no data to support this claim. Smile 

    Here are two tips that may make it easier when you (and all of your Live@edu users) return from those extended breaks.

    • Outlook Live administrators can reset user passwords AND unlock or unblock Live@edu accounts using the Exchange Control Panel (ECP) or Windows PowerShell.
    • Encourage your Live@edu users to enter an alternate email address and/or mobile phone number at https://account.live.com to enable user-initiated password reset options.

     

    Unlocking Live@edu Accounts

    After multiple unsuccessful login attempts, a Live@edu user may find oneself “locked out” or blocked from signing in to Outlook Live and Windows Live SkyDrive.

    IMPORTANT: In order to unlock or unblock a Live@edu account, an Outlook Live administrator (Organization Management or Helpdesk role group) must reset the password AND require password change on next logon for the affected account.

    IMPORTANT: Instruct users to update the Live@edu account password in all mobile devices and email clients after a password reset. 

    IMPORTANT: If using Password Change Notification Service (PCNS) with ILM 2007 or FIM 2010 and OLSync, please see below for additional steps to keep on-premises passwords sync’d with Live@edu passwords when unlocking or unblocking Live@edu accounts.

     

    Resetting user passwords and unlocking Live@edu accounts in ECP

     

    Login as an Outlook Live administrator to the Exchange Control Panel (ECP) at https://outlook.com/ecp

    Go to Users & Groups > Mailboxes and select the locked account

    With the account still selected, click Reset password…

    ecp-mailboxes-reset-password

    Enter Password, Confirm password and select the check box to Require password change on next logon

    ecp-mailboxes-reset-password-require-password-change-to-unlock

    For additional information on resetting user passwords and unlocking Live@edu accounts using the Exchange Control Panel (ECP), please see Reset a User's Password.

     

    Resetting user passwords and unlocking Live@edu accounts in PowerShell

    Connect to Exchange Online or Outlook Live using Windows PowerShell

    Install and Configure Windows PowerShell
    Connect Windows PowerShell to the Service

    Run the following command, but replace user1@consoso.edu with the Windows Live ID of the “locked out” user and replace Pa$$word1 with the desired temporary password.

    Unlocking an account with Windows PowerShell requires the parameters –Password and –ResetPasswordOnNextLogon $true.

    Set-Mailbox user1@contoso.edu -Password (ConvertTo-SecureString -String 'Pa$$word1' -AsPlainText -Force) -ResetPasswordOnNextLogon $true

    For additional information on resetting user passwords and unlocking Live@edu accounts using Windows PowerShell, please see Reset a Live@edu User's Password with Windows PowerShell.

     

    Resetting user passwords and unlocking Live@edu accounts when using OLSync with PCNS

    The Password Change Notification Service (PCNS) is a one-way synchronization of passwords from on-premises AD to Live@edu. In order for PCNS to keep passwords synced, all password changes must originate in on-premises AD.

    If users are permitted to change passwords in Windows Live, then passwords will get out of sync. It’s recommended to disable a user’s ability to change one’s password in Windows Live or to redirect a user’s Live@edu-side password change request back to an Internet-facing on-premises password change portal. This can be configured per domain in the Service Management Portal (https://eduadmin.live.com), e.g. SMP > Domains > contoso.edu > Password Reset Settings > Edit these settings > “Redirect domain members to the following Web site in order to reset their passwords”.

    In Outlook Live, the -ResetPasswordOnNextLogon $true parameter is required to “unblock” a locked out account. This flag prompts the user to change the password in Windows Live and it ignores the domain’s Password Reset Settings. This creates a scenario where a user’s on-premises password is not the same as the Windows Live password.

    What can be done? An admin should first unblock the Live@edu account via ECP or PowerShell, then set the password again in on-premises Active Directory Users and Computers (ADUC) or via some other on-premises password reset process. The ADUC “user must change password at the next logon” setting only applies to an on-premises logon to AD. A user will be prompted to change the password the next time one logs in to AD, and the password will be synced by PCNS.

    When working with remote users, it’s best to provide the temporary password to a user and direct them to an on-premises self-service password reset portal to change the password. This self-service password change portal (not included with the service) would set the password in on-premises AD, then PCNS would push the password to Live@edu.

     

    User-Initiated Password Reset Options

    If a Live@edu user adds an alternate email address and/or mobile phone number at https://account.live.com, then there are additional password reset options available to the user.

    IMPORTANT: Instruct users to update the Live@edu account password in all mobile devices and email clients after a password reset.

    IMPORTANT: If using Password Change Notification Service (PCNS) with ILM 2007 or FIM 2010 and OLSync, Live@edu users should use the school’s password reset procedures.

     

    Adding alternate email address and/or mobile phone number for resetting your password

     

    Go to https://account.live.com and sign in

    Under Account Security > Security Info, click the Manage link (right side)

    windows-live-account-security

    On the Manage Security Info page, enter Mobile phone number and/or Alternate email address

    windows-live-security-info-phone-email-question

    Click Save

     

    Resetting a forgotten password using alternate email address and/or mobile phone number

    If a user is unable to login to https://outlook.com and receives the message “You’ve tried to sign in too many times with an incorrect email address or password,” then you might recommend resetting the password by clicking the “Can’t access your account?” link on the Outlook Live Sign In page.

    unlock-unblock-ive-edu-accounts-ecp-powershell-captcha windows-live-sign-in-access-account

    A user will need to enter a valid Windows Live ID and the Characters from the CAPTCHA

    windows-live-reset-your-password-captcha

    When a user selects I forgot my password, he or she will be presented with additional password reset options, e.g. Email me reset link or Send a code to my mobile phone

    windows-live-reset-your-password

     

    Email me a reset link Send a code to my mobile phone
    windows-live-reset-your-password-email-reset-link windows-live-reset-your-password-send-code-mobile-phone

     

    ______________________________

    Thanks for joining us today!

    Zion Brewer

    ______________________________

  • Office 365, now with added HIPAA BAA

    Just a quick post to highlight the fact that Office 365 now offers customers requiring a HIPAA BAA the option of executing one with us.  This is an unique proposition from us as a major provider of cloud services, and one that we are delighted to be able to offer.

    Check it out! http://blogs.technet.com/b/microsoft_in_education/archive/2011/12/16/office-365-becomes-first-and-only-major-cloud-service-to-meet-the-rigors-of-u-s-standards-for-data-protection-and-security.aspx

    Jonny

  • Using Live@edu with a Windows Phone

    Windows Phone rocks!HTC 7 Mozart with green start angled

    Wouldn’t it be cool if you could sign into your Windows Phone using your Live@edu Windows Live ID? If you've already got a phone, or you’re lucky enough to be getting one over the Christmas period, there are some simple steps you need to take to make sure you get the best experience.

    It’s simple!

    Because Live@edu is supercharged with the power of Outlook Live, which is different to Hotmail, it means that we need to make a minor change in the server name in order to be able to connect successfully:

    1. On your phone, go to Start, flick left to the App list, and then tap Settings Settings.
    2. Tap Airplane mode, and tap to turn the status to On. Press Back to go to Settings.
    3. Tap Email+accounts and then tap Windows Live.
      Note If you receive an error on this step, tap Close to dismiss the error and then tap Windows Live again.
    4. On the Windows Live Settings screen, tap Server, and use the keyboard to change m.hotmail.com to read m.outlook.com.
    5. Tap Done . The phone will sync and the server should get changed to pod*****.outlook.com. Press Back to go to Settings.
    6. Tap Airplane mode, and tap to turn the status to Off.
    7. Visit http://help.outlook.com for additional guidance and support.

     That’s it – you’re done! You can read more about this on the Microsoft Support site.

    Happy holidays! Party smile

  • Live@edu Deployment and Marketing Kits

    ‘Twas the night before Christmas…image

    Can you believe it’s nearly Christmas already? It’s been a whole year since I started writing for this blog and what an exciting year we’ve had!

    As many of you break up for the holidays you’ll probably be looking forward to mince pies, roast turkey and the ubiquitous afternoon nap that follows on the big day – but why not get yourself another little present for when you return to the office by way of one of our fantastic little deployment and marketing kits?

    If you’re about to deploy Live@edu, or just have, these kits are a great way to help promote the service across your institution as they contain all sorts of great little resources:

    • A USB memory stick, containing:
      • Live@edu Co-branding Guide
      • Live@edu Deployment Checklist
      • Live@edu Top 10 for Deployment
      • Live@edu Cost Saving Calculator
      • Building Live@edu Into School Portal
      • Live@edu Single Sign On Kit
      • … and more!
    • Posters
      • Window Clings
      • Pencil Tubes
      • Bookmarks
      • Notepads
      • Pens
      • Monitor Hangers
      • Table Tents

    Why wait?

    We’re happy to send a kit to you, but if you need more copies of the resources that are included, or don’t want to wait for the post, you can access all of the resources in the kits online and print them yourself. Check out our SkyDrive where you can find not only the resources in the kit, but a whole load of other useful things, including recordings of our webcasts.

    Drop us a line!

    If you are in the United Kingdom all you need to do to get your hands on one of these kits is to drop us an email telling us about your institution – let us know how big you are, what your plans are for deployment and how we can contact you and we’ll be in touch with details about the kits. Unfortunately we’re unable to extend the physical kit offer outside of the UK, but the printable resources in the SkyDrive are available for all.

    Get in touch NOW!

  • Exchange 2010 Service Pack 2 is now available!!

     

    The long wait is over just for the holiday season. You can download the service pack here:

    http://www.microsoft.com/download/en/details.aspx?id=28190

     

    · General information: http://blogs.technet.com/b/exchange/archive/2011/05/17/announcing-exchange-2010-service-pack-2.aspx

    · Support for hosting: http://blogs.technet.com/b/exchange/archive/2011/08/30/exchange-server-2010-sp2-and-support-for-hosting-exchange.aspx