New Post has been published on o365info.com
New Post has been published on http://o365info.com/directory-synchronization-links-resources/
Directory synchronization - Links and Resources
The following post includes many useful links to: articles, videos and tools that relate to the Directory synchronization server\service in an Office 365 environment.
The Directory synchronization was crated for enabling a synchronization of the on-Premises Active Directory to the Windows Azure Active Directory.
Directory synchronization in Office 365 environment
For medium and large organizations, the task of managing two separated users directory can consider as complicated and non-efficient.
The Directory synchronization enables us to mimic a “one directory environment” by replicating the on-Premises Active Directory objects such as users, group contact, etc. to the cloud.
The outcome is that the user and group management is implemented via the on-Premises Active Directory and, all of the updates are replicated to the cloud (Windows Azure Active Directory).
The installation of the Directory synchronization server (Windows Azure Active Directory Sync tool ) is quite simple, but it’s very important that we understand how this “thing” work and what the logic of the Directory synchronization is.
In a scenario in which we did not implement the required preparations such as: adding the organization public domain name to the on-Premises Active Directory and, set the required UPN (User Principal Name) for the on-Premises Active Directory users, the results could be a wrong synchronization process and the process of “fixing the problem” could be quite complicated and no so simple.
My point is that like each of the reset of the Office 365 service and component, we will need to allocate the required resources for learning about the Directory synchronization server\service, plan headed for the Directory synchronization installation, implement the pre requirements, learn of to monitor the synchronization process, deal with a troubleshooting scenarios of synchronization problems and so on.
To be able to save your precious time, I have collected many relevant sources of information that relate to Directory synchronization.
Legend for Link and Resources table
Articles Links table Video link table PowerShell Scripts link table Tools Link table
To be able to optimize the navigation in the article, you can use the collapse and expand option.
Expand All Headers Collapse All Headers
Directory synchronization (DirSync) | Plan
Hybrid Migration | Get familiar with Directory synchronization
Articles Links table Migration to Office 365 | General information Planning Directory Synchronization Prepare for directory synchronization The Directory Sync tool can now be installed on a Domain Controller! Directory synchronization roadmap
Directory synchronization (DirSync) | Pre deployment tasks
Articles Links table Directory synchronization (DirSync) | Deploy | Pre deployment tasks Add User Principal Name Suffixes User names of users in your organizational account such as Office 365, Windows Azure, or Windows Intune don’t match the on-premises UPNs
Directory synchronization (DirSync) | Deploy
Articles Links table Directory synchronization (DirSync) | Deploy | Download and install Manage Windows Azure AD using Windows PowerShell Install or upgrade the Directory Sync tool Download and Install DirSync – Microsoft Download Center Installing and configuring Active Directory Synchronization
Articles Links table Directory synchronization (DirSync) | Deploy | Soft Match How to use SMTP matching to match on-premises user accounts to Office 365 user accounts for directory synchronization Soft Match with new domain
Video Links Table Ignite Webcast – Understanding DirSync Info In our latest Ignite Webcast, we will give you an overview of what dirsync is, what the requirements are, and the different options that are available for dirsync. We’ll also cover coexistence and some key deployment considerations. We are excited to have our host and Office 365 Architect, Daniel Kenyon-Smith, back for this session. Office 365 Identity Management options Info Office 365 offers a whole range of different identity management options that allow you to use Office 365 as YOU wish. In this session you will learn everything there is to know about User Accounts, Provisioning, Single Sign On and experience how Windows Azure AD can become your next best friend! Office 365 Identity Management Info As you move to the cloud with Microsoft Office 365, your directory moves there as well. Your organization’s directory lists all the people who you can collaborate with using Office 365 and it enables users to log in and authenticate themselves. This session introduces you to Office 365 Identity Management with a focus on how user accounts are synchronized with other repositories. It is aimed at those who work with Office 365 and need to understand the scope of Identity Management and the capabilities available to an Office 365 IT Administrator
Directory synchronization (DirSync) | Management
Articles Links table Best Practices for Deploying and Managing the Windows Azure Active Directory Sync Tool Get directory synchronization working Directory synchronization roadmap List of attributes that are synced by the Windows Azure Active Directory Sync tool FAQ – Directory Synchronization tool Office 365 DirSync Content Map Windows Azure AD Community Information Center
Articles Links table Directory synchronization (DirSync) | Deploy | Post deployment tasks How to force directory synchronization with Azure Dirsync? Prepare to provision users through directory synchronization to Office 365 Synchronizing your directory with Office 365 is easy
Articles Links table Directory synchronization (DirSync) | Management | Filtering Configure filtering for directory synchronization User soft-delete and Dirsync filtering enabled Installing and Configure DirSync with OU level filtering for Office365
Articles Links table Directory synchronization (DirSync) | Management | Password Synchronization DirSync/Windows Azure AD Password Sync Frequently Asked Questions Implement Password Synchronization New Azure Active Directory Sync tool with Password Sync is now available
Video Links Table Directory synchronization (DirSync) | Deploy | Video Links Configuring DirSync with Password Sync Info DirSync can synchronize a customers on-premises Active Directory to Windows Azure Active Directory where it can be used by Office 365. This video will show how to configure the synchronization and how to enable users to log into Office 365 using the same username and password as they use to log onto the corporate Active Directory. Office 365 Administration for Small Business: (03) Office 365 Single Sign-On, DirSync and ADFS Info
What is DirSync and ADFS? Watch this section to understand what these elements are and how to create them.
[00:49] – Lync Online Overview
[20:27] – System Requirements
[22:20] – DNS & Network Settings
[24:42] – Lync Online Configurations
[32:50] – Setup Domain Federation, Public IM, Dial In Conerencing
Configuring DirSync and Single Sign On with ADFS – Part 1 Info In this 300 level session, you will learn the various options for managing identities, authorization, and authentication with Office 365 and Windows Azure Active Directory. We’ll review the considerations involved in understanding a customer environment and the implications for choosing what authentication method to use. We will demonstrate how to assess and prepare the on-premises Active Directory for synchronization with Windows Azure Active Directory, and will show how to configure Active Directory Federation Services (ADFS) and the Directory Synchronization (DirSync) appliance. Finally, we will discuss directory synchronization best practices and how to troubleshoot common synchronization problems, equipping you to see an Office 365 directory synchronization project through to completion. Configuring DirSync and Single Sign On with ADFS – Part 2 Info In this 300 level session, you will learn the various options for managing identities, authorization, and authentication with Office 365 and Windows Azure Active Directory. We’ll review the considerations involved in understanding a customer environment and the implications for choosing what authentication method to use. We will demonstrate how to assess and prepare the on-premises Active Directory for synchronization with Windows Azure Active Directory, and will show how to configure Active Directory Federation Services (ADFS) and the Directory Synchronization (DirSync) appliance. Finally, we will discuss directory synchronization best practices and how to troubleshoot common synchronization problems, equipping you to see an Office 365 directory synchronization project through to completion.
Video Links Table Directory synchronization (DirSync) | Deploy | Virtual Academy | Video Links 01 | Install and Configure Active Directory Synchronization Info In this module you will learn how to install and configure Active Directory Synchronization. This is a self paced interactive learning experience. When module is completed make sure you return to this page to continue with the next module. 02 | Prepare for Active Directory Federation Services Info This module provides and insight on how to prepare your environment for Active Directory Federation Services. This is a self paced interactive learning experience. When module is completed make sure you return to this page to continue with the next module. 03 | Install and Configure Active Directory Federation Services Info In this module you will see how to installing and configuring Active Directory Federation Services. This is a self paced interactive learning experience. When module is completed make sure you return to this page to continue with the next module. 04 | Verifying Federated Domains Info This module covers adding and verifying Federated Domains. This is a self paced interactive learning experience.
Directory synchronization (DirSync) | Troubleshooting
Articles Links table Office 365 Service Accounts–How do I stop DIRSYNC from breaking every 90 days How to troubleshoot Windows Azure Active Directory Sync Tool installation and Configuration Wizard error messages in Office 365 Troubleshoot directory synchronization You can’t sync the SystemMailbox or DiscoveryMailboxSearch accounts by using the Windows Azure Active Directory Sync tool Filter support in the Microsoft Online Services Directory Synchronization Tool Troubleshoot directory synchronization Get directory synchronization working How to use SMTP matching to match on-premises user accounts to Office 365 user accounts for directory synchronization Changes aren’t synced to Windows Azure AD after you change the UPN of an on-premises user account to use a different SSO-enabled domain suffix Help…DirSync error – unable to change UPN on target account How to troubleshoot deleted user accounts in Office 365 Windows Azure Active Directory Sync Tool stops syncing or returns messages that sync hasn’t run in more than a day You can’t manage or remove objects that were synced from the on-premises Active Directory Domain Services to Windows Azure On-Premises Active directory
Tools Links table IdFix DirSync Error Remediation Tool InfoIdFix is used to perform discovery and remediation of identity objects and their attributes in an on-premises Active Directory environment in preparation for migration to Office 365. IdFix is intended for the Active Directory administrators responsible for DirSync with the Office 365 service ADModify.NET InfoADModify.NET is a tool primarily utilized by Exchange and Active Directory administrators to facilitate bulk user attribute modifications.
PowerShell Scripts Links table Directory synchronization (DirSync) | Troubleshooting | PowerShell Scripts Microsoft Office 365: DirSync – Count Total Synchronized Objects Info ‘DirSync – Count Total Synchronized Objects’ shows total counts of users, groups, contacts, and grand total objects by extracting the FIM SourceAD Connector Space data to an XML file named SourceAD.xml.When an object makes its way past the Office 365 DirSync filters, they become DirSync “Busted Users” Report Info This script generates a CSV list of users who are failing to export to Azure AD. It requires the FimSyncPowerShellModule and must be executed by an account in the FIMSyncAdmins group on the DirSync server.Below is a sample of the output:More information can be found here: DirSync Report Info This script gathers DirSync information from various locations and reports to the screen. Known Issues (Nov 5 2013):1) All commands, including SQL queries run as the local user. This may cause issues on locked-down SQL deployments.2) For remote SQL installations, the SQL PowerS Fix Empty DisplayName Attribute for On-premises Mail-Enabled Groups Info This script verifies displayName property for mail-enabled groups. This script allows you to export mail-enabled groups that have empty display name or questionable characters. After you correct the displayName of these groups, you can use this script to import them to the AD. Office 365 – Search Users with ProxyAddresses Matching a String Info There may come a time when you are required to query for all users in your Office 365 tenant whose proxyAddresses attribute matches a specific string, such as a domain suffix. This script sample will help get you started with this type of query. Sync Primary Email Address and UPN PowerShell Info A PowerShell script that I’m using in most of my Office 365 projects where I often need to change UPN to includ a public routable domain. The easiest way of doing this is to copy the primary email address to the UserPrincipalName attribute.
PowerShell Scripts Links table Directory synchronization (DirSync) | PowerShell Scripts Change user UPN Info Change the user UPN (User Principal Name) Change UPN Info This script can be used for changing the UPN for bulk users based on a CSV File. I used this while migrating users mailboxes from On-Premise to Office365 where its mandatory to have UPN and Email to be the same. Change On Premise Active Directory UserPrincipalName (UPN) Info Under some scenarios IT administrators may need to wholesale change the UPN suffix for all or a large group of users within an Active Directory. This script can be used to replace one provided string in the UPN suffix if found with another provided string How Can I Assign a New UPN to All My Users? Info Hey, CH. The UPN (or User Principal Name) provides an alternate way of logging on to a domain. Typically you log onto a domain by pressing Ctrl-Alt-Delete, typing in your user name, domain name, and password, and then pressing ENTER. With a UPN, you don’t enter separate user and names, instead you enter a user name similar to this:
Now it’s Your Turn!
We really want to know what you think about the article