Single Sign-On s Officeom 365 na Kineziološkom fakultetu Sveučilišta u Zagrebu

Similar documents
RSA SecurID Access Configuration for Microsoft Office 365 STS (Secure Token Service)

Enabling and Managing Office 365

ENABLING AND MANAGING OFFICE 365

Course Outline. Enabling and Managing Office 365 Course 20347A: 5 days Instructor Led

[MS20347]: Enabling and Managing Office 365

Tech Dive: Microsoft Azure Identity Management and Office 365

20347: Enabling and Managing Office hours

Microsoft Official Curriculum Enabling and Managing Office 365 (5 Days - English) Programme détaillé

Office 365 and Azure Active Directory Identities In-depth

Enabling and Managing Office 365 (NI152) 40 Hours MOC 20347A

Enabling and Managing Office 365

Office : Enabling and Managing Office 365. Upcoming Dates. Course Description. Course Outline

Enabling and Managing Office 365

Education and Support for SharePoint, Office 365 and Azure

Course Content of Office 365:

MCSA Office 365 Bootcamp

ENABLING AND MANAGING OFFICE 365

Office 365 Administration and Troubleshooting

Microsoft Enabling and Managing Office 365

Course 10997A: Office 365 Administration and Troubleshooting

Enabling and Managing Office 365

10997: Office 365 Administration and Troubleshooting

Vendor: Microsoft. Exam Code: Exam Name: Managing Office 365 Identities and Requirements. Version: Demo

20347: Enabling and Managing Office 365

Microsoftova productivity vizija

Microsoft Managing Office 365 Identities and Requirements. Download Full version :

Case Study Hrvatska pošta: Korisničko iskustvo iz snova. Tomislav Turk Samostalni sistem inženjer, Combis d.o.o. Zagreb,

RSA SecurID Access SAML Configuration for Microsoft Office 365

Office 365 Administration and Troubleshooting

DATACENTER MANAGEMENT Goodbye ADFS, Hello Modern Authentication! Osman Akagunduz

DigitalPersona. SSO for Office 365. On Premise DigitalPersona SSO for Office 365. Solution Deployment Guide

How to Map OnPrem Active Directory users to existing Office365 Users

Office 365 Administration and Troubleshooting

AAD Connect setup guide

Extranet Identity Management and Authentication for SharePoint On Premise, Office 365 and Beyond

SafeNet Authentication Client

Windows Server 2012, VDI Licenciranje najprodavanijeg servera, što je novo, VDI licenciranje. Office 2013 / Office 365

Course Outline 20742B

10997A: Office 365 Administration and Troubleshooting

MOC20347 Enabling and Managing Office 365

Exam Code: Exam Code: Exam Name:Managing Office 365 Identities and Requirements.

Assess Remediate Enable Migrate

/

Course 20533B: Implementing Microsoft Azure Infrastructure Solutions

IT Tools MICROSOFT OFFICE SPECIALIST A: Enabling and Managing Office 365. Κωδικός Σεμιναρίου / Code. Που Απευθύνεται / Audience IT Professionals

Use Microsoft EMS. to Protect your Mobile Data and Mobile Apps. Chris Nackers Nackers Consulting

Course Outline: Course : Core Solutions Microsoft SharePoint Server 2013

Configure a one-way hybrid environment with SharePoint Server 2013 and Office 365

Cloud Access Manager How to Configure Microsoft Office 365

Delivering training since 1996

O365 Solutions. Three Phase Approach. Page 1 34

Geant2 - JRA1. Upravljanje mjerenjem i performansama mreža (perfsonar, baza multi-domain nadzorne usluge) Danijel Matek (Srce)

MB Microsoft Dynamics CRM 2016 Online Deployment.

2016 Braindump2go Valid Microsoft Exam Preparation Materials:

WELCOME! Using Microsoft Office 365 for a Robust Mail and Conferencing System

Planning and Administering SharePoint 2016

Enabling and Managing Office 365

Q&As Managing Office 365 Identities and Requirements

ConfigMgr 2012 R2 & Intune

KillTest *KIJGT 3WCNKV[ $GVVGT 5GTXKEG Q&A NZZV ]]] QORRZKYZ IUS =K ULLKX LXKK [VJGZK YKX\OIK LUX UTK _KGX

Enabling and Managing Office 365

Office 365 management done right

Office 365 for IT Pros

Single Sign-On Showdown

Advanced Technologies of SharePoint 2016 ( )

Hybrid Cloud najbolje od oba svijeta

Contents. Introduction To CloudSync. 2. System Requirements...2. Installing CloudSync 2. Getting Started 4

Microsoft Azure Course Content

M20742-Identity with Windows Server 2016

UPUTSTVO ZA KORIŠĆENJE NOVOG SPINTER WEBMAIL-a

Universal Windows Applications

Cloud Secure. Microsoft Office 365. Configuration Guide. Product Release Document Revisions Published Date

Advanced Technologies of SharePoint 2016

Advanced Technologies of SharePoint 2016

20742: Identity with Windows Server 2016

METHODOLOGY This program will be conducted with interactive lectures, PowerPoint presentations, discussions and practical exercises.

Identity with Windows Server 2016

COURSE OUTLINE MOC : PLANNING AND ADMINISTERING SHAREPOINT 2016

Hybrid Identity de paraplu in de cloud

Unaprjeñenje sigurnosti u mrežama pružatelja


Cloud Operations Using Microsoft Azure. Nikhil Shampur

Extranets in SharePoint and SSO for Claims Apps. January 18, 2017

Enabling and Managing Office 365 (20347)

Use EMS to protect your mobile data and mobile app

About. This is Abdelrahman Muhammad, a Unified Communication Expert at Orange Business services (OBS)

Step-by-step Guide to Office 365 Hybrid Deployment

MCSA: Windows Server MCSA 2016 Windows 2016 Server 2016 MCSA 2016 MCSA : Installation, Storage, and Compute with Windows Server 2016

Course : Planning and Administering SharePoint 2016

Track MS-100: Microsoft 365 Identity and Services

Office 365 Deployment Guide

microsoft.

SafeNet Authentication Client

by Jim. Number: Passing Score: 800 Time Limit: 120 min File Version: 1.0. Microsoft.Actualtests By-Jay-Corrected

Administering Office 365 for Small Businesses

VIEVU Solution AD Sync and ADFS Guide

Developer s Guide to Azure RemoteApp Hybrid Collection Deployment

Load Balancing Microsoft AD FS. Deployment Guide v Copyright Loadbalancer.org

Microsoft Dynamics CRM Online Deployment (MB2-706)

Exam Questions

Transcription:

Single Sign-On s Officeom 365 na Kineziološkom fakultetu Sveučilišta u Zagrebu Stipe Gorenjak, Kineziološki fakultet Sveučilišta u Zagrebu e-mail: stipe.gorenjak@kif.hr

Sponzori

Ugasite mobitele. Hvala.

Sadržaj 1. dio: Uvod Zašto Office 365? Zašto integracija AD-a i Single Sign-On? Mogućnosti integracije Demo 1 (SSO @ O365 @ KIF) Priprema lokalne infrastrukture

Uvod Zatečeno stanje na KIF-u Serverska infrastruktura Usluge Što se željelo postići Omogućiti veću produktivnost Bolje iskoristiti informatičke stručnjake Kako do cilja Rekonstrukcijom serverske infrastrukture Korištenjem potencijala Cloud usluga

Zašto Office 365? Sigurnost dizajniran kako bi zadovoljio sigurnosne zahtjeve Enterprise okružja Pouzdanost geo redundantni datacentri (99.9% SLA) Dostupnost nudi konzistentno korisničko iskustvo bez obzira na koji način i s kojeg uređaja korisnik pristupa Produktivnost Exchange Online (50 GB inbox) SharePoint Online (na primjeru KIF-a, 3,7 TB) ONEDRIVE for Business (1 TB po korisniku ) Lync Online (konekcija prema Skype-u i ostalim Lync Online korisnicima) Office Web Apps YAMMER (leading enterprise social network for businesses)

Zašto integracija AD-a i Single Sign-On? Upravljanje s jednog mjesta Jednaki korisnički računi lokalno i u O365 Jednake korisničke lozinke i politike lozinki Jednostavniji pristup Office 365 uslugama Autentikacija se vrši samo u lokalnom AD-u

Mogućnosti iplementacije Office365

Mogućnosti implementacije Office365 Admin Portal Authentication platform Office 365 Provisioning platform Directory Store

Mogućnosti implementacije Office365 AD DS Admin Portal Authentication platform Office 365 DirSync Provisioning platform Directory Store

Implementacija Office365 na Kineziološkom fakultetu Svučilišta u Zagrebu AD DS AD FS Admin Portal Authentication platform Office 365 DirSync Provisioning platform Directory Store

Demo 1 - SSO @ O365 @ KIF

Priprema lokalne infrastrukture

Sadržaj 2. dio: Priprema AD-a za integraciju SSL Certifikati za AD FS Podešavanje AD FS servera Podešavanje Federation Trust-a Podešavanje Directory sinkronizacije Demo 2 (DirSync Filtering)

Priprema AD-a za integraciju UPN suffix (kif.hr; student.kif.hr; alumni.kif.hr) Proxy adrese Nepodržani znakovi (Space () @ =? /) Dodati UPN-ove na O365 Prilagoditi dizajn OU-a

SSL certifikati za AD FS Trusted Public Certifikati (TERENA) Potrebni za ADFS server i WEB APLICATION PROXY (WAP)server

Podešavanje AD FS servera AD FS Federation Server Configuration Wizard kreiranje novog federacijskog servisa Federation Server Farm (preporuka čak i ukoliko se podešava samo jedan server)

ADFS Server 3.0 Farma servera koja služi za hosting Federation servisa Preporučeno je koristiti najmanje dva Federation servera u load balancing-u WEB APLICATION PROXY (WAP) Proxy serveri služe za preusmjeravanje korisničkih zahtjeva za autentikacijom koji dolaze izvan lokalne mreže Trebaju se nalaziti u DMZ-u

Primjer logičke infrastrukture potrebne za SSO sa O365

Podešavanje Federation Trust-a Windows Azure AD module for Windows PS

Podešavanje Federation Trust-a Set the credential variable Global administrator $cred=get-credential Connect to Microsoft Online Services Connect-MsolService Credential $cred Set the MSOL ADFS Context server, to the ADFS server Set-MsolADFSContext Computer adfs_servername.domain_name.com

Podešavanje Federation Trust-a Convert the domain to a federated domain Convert-MsolDomainToFederated DomainName domain_name.com Successful Federation Successfully updated domain_name.com domain. Verify federation Get-MsolFederationProperty DomainName domain_name.com

Podešavanje Directory sinkronizacije DirSync.exe (Instalacija) uncheck Synchronize directories now Pokreni UI %Program Files%\Windows Azure Active Directory Sync\SYNCBUS\Synchronization Service\UIShell\miisclient.exe U Identity Manageru odabrati OU za sinkronizaciju

Demo 2 - DirSync Filtering

Sadržaj 3. dio: Forsiranje sinkronizacije AD-a Provjera uspješnosti sinkronizacije ADFS vs. DirSync w/ Password Zaključak

Forsiranje sinkronizacije AD-a Pokrenuti PowerShell s učitanim cmdlet-ima %Program Files%\Windows Azure Active Directory Sync \DirSyncConfigShell.psc1 U powershell-u pokrenuti Start-OnlineCoexistenceSync

ADFS vs. DirSync w/ Password

Zaključak Značajno bolje korisničko iskustvo za interne korisnike Veći zahtjevi za internim resursima Serverskim Administrativnim

Pitanja i odgovori.