O365Engage17 - How to avoid the 5 stages of grief when moving to office 365
1. 1
Slide
1
How to Avoid the 5 Stages of
Grief When Moving to Office 365
Michael Van Horenbeeck
@vanhybrid
www.vanhybrid.com / www.vhct.be
2. 2
Slide
2
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Who am I?
• Independant Consultant
(VH Consulting & Training)
• Office Servers & Services
MVP (Exchange)
• Microsoft Certified Solutions
Master – Messaging
• Co-Author of Office 365 for IT
Professionals
3. 3
Slide
3
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Scenario: Large
Multinational Corp.
• +/- 100,000 users
• Various AD Forests
• Multiple geographical locations
• Exchange On-Premises, Lotus Notes, Office
365 and perhaps some Gmail
4. 4
Slide
4
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
The playing field...
5. 5
Slide
5
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Customer requirements (asks):
• Setup a (single) global
solution to improve
collaboration between all
subsidiaries (organizations)
• Keep the time to implement
as low as possible; impact on
the end-user should be
minimized at all times
• Use “low hanging fruit” to
show benefits early on…
• “Secure by design”;
everything you implement
should adhere to company
security policies
• Keep in mind regulations
(such as GDPR)
6. 6
Slide
6
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Where do I begin?!
7. 7
Slide
7
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
My BAE
• Make sure network connectivity / infrastructure is up to par!
• Network is often underestimated:
• Available IP Addresses (port exhaustion)
• Use of Proxy Servers (and performance)
• Firewalls and their (in)ability to deal with domain-based ACLs
• Alternative: how to stay up to date with changing IP addresses?
• Single or multiple tenants?
• Multi-tenants = complex and doesn’t meet requirements (same issues
as before, only moved the cloud)
8. 8
Slide
8
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
A solid foundation…
• Identities are the cornerstone of your deployment; but also the
front door to your data and enables easy collaboration
• Azure AD can serve multiple purposes > your first quick win!
• Multiple forests > How to deal with them?
• AAD Connect (stay away from MIM...)
• On-prem synchronization tool? (GalSync)
9. 9
Slide
9
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Synchronization
Directories
Company A Company B Company C Company D
Think about your sourceAnchor attribute!
(objectGUID vs. msDs-ConsistencyGuid (or other)
10. 10
Slide
10
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Benefits of a single (global) Azure AD tenant
• Enables easy and quick collaboration across connected
organizations
• Quickly start collaborating with new partners and acquisitions
through e.g. Azure B2B (or External Sharing features)
• New mergers/acquisitions can easily hook into existing tenant (expand
Azure AD Connect with additional on-prem forest)
11. 11
Slide
11
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Authentication?
• Lots of organizations (try to) default to AD FS. Is it really
necessary?
• What’s the constraint against e.g. Password Hash Sync, or PTA/SSO?
• AD FS and multi-forest works great, IF:
• All organizations have a unique UPN (namespace); else cross-forest
UPN suffix routing is disabled!
• Separate UPNs also allow for separate AD FS instances
12. 12
Slide
12
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Auth; User A in Company A
Company B
Company A
sync
@companyA.com
CompanyB.com
CompanyA.com
13. 13
Slide
13
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Auth; User B in Company B
Company B
Company A
sync
@companyB.com
CompanyB.com
CompanyA.com
14. 14
Slide
14
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Auth; User B in Company B
Company B
Company A
sync
UserB@Holding.com
Holding.com
Holding.com
15. 15
Slide
15
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
AD FS caveats
• 1) Watch/go to Brian Desmond’s session (Identity in the Cloud)!
• Also discusses AD FS & SQL
• 2) Use AD FS 2016 whenever possible
• Gives you more control in complex scenarios (e.g. AD FS without IDP,
but as a “pass-through” to another AD FS/IdP)
• 3) Think of HA
• Hybrid setup with e.g. Azure / AWS might be beneficial
• 4) Beware of limitations with other workloads!
• Modern Auth with SfB on-prem and cloud (hybrid) = not possible today!
16. 16
Slide
16
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Migration Strategies?
• Exchange on-premises: hybrid or not?
• Long-term?
• Just for migration purposes?
• What version of Exchange to use?
• Lotus Notes: built-in tools or 3rd-party tools?
• Email-only? Or also applications and data?
• Other cloud-solutions
• Use a third-party tool (hosted or on-premises?)
17. 17
Slide
17
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Exchange: Edge or no Edge?
• Edge is not required; but can help to overcome certain security
requirements (i.e. incoming connections must be terminated in
DMZ).
• Sizing Edge for (large) hybrids is hard > no real guidance
available.
• Size just like you would size regular transport servers (account for
Transport Dumpster!)
• Start small and scale up as needed
• Use of a third-party routing agent can be useful. But be prudent!
18. 18
Slide
18
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Exchange Hybrid
• Scaling up migration throughput?
• Adding servers is not always a solution.
• Look at alternatives
• (Temporary) additional bandwidth
• Tweak Exchange MRS settings (ExportBuffer)
• Multiple Concurrent Migration Endpoints = better
• Requires potentially multiple external IPs
• Requires additional SNs on the certificate
19. 19
Slide
19
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
What if?
• Autodiscover or Outlook Anywhere aren’t published externally?
• Although you can bypass some limitations, make these work!
• My firewall can’t do domain-based IP lookups?
• I don’t want to move everyone at once? (segregation within a
domain)
• ...
20. 20
Slide
20
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Sharing a namespace?
• One of the toughest problems to solve
today
• Internal Relay domains are prone to issues
(e.g. Mail loops), and cumbersome to
setup/maintain across various orgs.
• 3rd-party solutions can help with this (e.g.
Mimecast)
• Address rewriting for inbound/outbound
messages
• Might break functionality (e.g. Outbound DKIM
signing)
@compA.holding.com
@holding.com
@compC.holding.com
21. 21
Slide
21
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Non-technical challenges
• Building a service organization across boundaries within the
holding.
• Define the “standard”-service and how to deal with new functionalities
• Define the MVP (minimal viable product), for functionality, security etc.
• Define possible deviations
• How to deal with support?
• If spread across multiple geo locations > enable/organize FTS-support (=quick
win)
• Other challenges that (might) will arise:
• Political, tooling, ...
22. 22
Slide
22
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Shared administration across boundaries?
• Often there are legal implications (admins from other regions
managing objects elsewhere).
• 3rd-party tools can help (e.g. Delegate 365)
• Often does not take away the need for a “Code of Conduct”
• Shared tooling can improve comms (and reduce overhead)
• An extra cost to factor into the budget!
23. 23
Slide
23
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Common struggles
• How to deal with the fast pace of “The Cloud”?
• How to organize the IT department for setup/support etc.?
• How to move to the cloud in a reasonable time frame?
• Where will data be stored?
• Technical limitations > bandwidth; latency etc…
• Legal implications > local regulations etc.
• What features will be made available?
• Technical/Functional > are they useful to the organization?
• Other > Can these features legally be used?
24. 24
Slide
24
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Looking ahead
• Today, there’s no good solution for multi-geo support. However,
MSFT announced new capabilities coming in the future:
• Skype Regionally Hosted meetings (2016/2017)
• OneDrive Geo Support (2017)
• Other workloads surely must follow some time in the future?!
25. 25
Slide
25
How to Prepare, Build, and Manage Real-Life, Complex, Hybrid Deployments | Michael Van Horenbeeck | Thursday, June 21st, 10:45AM
Follow us:
#O365ENGAGE17
Questions? | Thank You
Michael Van Horenbeeck
michael@vhct.be
We’d like to know what you think!
Please fill out the evaluation form you
received at the registration desk for this
session
Session recordings and materials:
Materials will be available on
Office365Engage.com soon