azure active directory
6 TopicsGolden Path for Education - Part 1a
What is Golden Path Golden Path was developed to simplify and enhance the security of deploying a Microsoft 365 tenant solution in education. It consists of three stages: Stage 1: Deployment Guides are available online at Golden Path. This stage includes: Baseline - Stage 1a Standard - Stage 1b Advanced - Stage 1c Stage 2: A Discovery/Assessment AI tool is used to expose the tenant's configuration and analyze it against the tenant's license configurations, tenant and service settings, Microsoft's general education recommendations, and customer requirements. Stage 3: Drift Configuration management helps understand changes made against the established configuration in the tenant. These changes can be reversed or modified before any breaches or irregularities create problems. Goals and Objectives for Golden Path Goals Develop prescriptive deployment guides that provide a centralized resource with education-specific scenarios to assist organizations in defining, managing, and organizing their tenant and appropriate applications. Reduce the overall complexity of tenant and service deployment. Establish baseline recommended pathways to facilitate a common and agreed-upon configuration based on subject-matter experts. Utilize AI technology to uncover and compare recommended settings against user requirements based on documented configurations. Implement phased configurations to aid customers and partners in understanding what they may not know or should consider during discovery to meet customer expectations. Highlight unused features and products to ensure customers fully leverage the potential and benefits of their purchased product licenses. Identify opportunities for partner participation in achieving customer goals and expectations based on customer requirements and Golden Path findings. Create an easy pathway for customer change management to enhance control, security, compliance, and privacy of tenants. Develop custom assessments to evaluate product entry for items such as Copilot, Defender, Purview, Intune, Zero-Trust, and Microsoft Entra ID. Objectives Deliver information for features available (used/unused) to users based on license model. Prescriptive recommendations based on education scenarios. - Present upgrade license opportunities from A1 to A3 to A5. Security analysis exposing gaps and issues proactively to allow modifications before it's too late. Promote partner access to customers that have defined gaps based on assessments and are requesting partner assistance. Better discovery and assessment analysis with new tools. Designed to be more self-serving customer and partner access management. Speed up user adoption for educators and IT Admins alike. Baseline Stage 1a Baseline is stage 1a in the overall development of the Golden Path for Education. It is based on a majority of licenses within the tenant at the Microsoft 365 A1 for Education level. It also is a set of recommendations for ALL Microsoft Education tenants. Navigation Golden Path has three folders in the navigations. Golden Path Baseline References Golden Path folder consist of the Golden Path overall review. It goes over the entire program and the how and why it is built. Currently there are two pages, Golden Path overview and Baseline Overview. Golden Path overview menu Golden Path overview Stages (Deployment Guides, Discovery/Assessments, Drift Management) Modules (Setup, Identity, Applications, Security, and Devices) Phases (Baseline(A1), Standard(A3), Advanced(A5)) Baseline Overview Steps for each phase (Setup, Identity, Applications, Security, Devices) Licenses that are included General information links List of links for all applications and products included with A1 license List of links for all features included with A1 license Baseline menu Setup Tenant setup is key to establishing a secure and valid tenant. Setup goes through domain assignment, administration, and service management. Overview - Review all the steps that are part of the setup phase section Step 1 - Create your Office 365 tenant account Step 2 - Configure Security Center admin settings Step 3 - Secure and configure your network Step 4 - Sync your on-premises active directory Step 5 - Provision users Step 6 - Sync SIS with School Data Sync (SDS) Step 7 - License Users Identity Establishing an identity via Microsoft Entra ID and establishing authentication methods, Single Sign-On, and user procurement methodologies. Overview - Review all steps that are a part of the identity phase Step 1 - Understand identity definitions Step 2 - Configure Microsoft Entra ID basics Step 3 - Consider education identity steps Step 4 - Consider identity applications Step 5 - Set up access to operation services Step 6 - Set up identity lifecycle Step 7 - Configure security in identity Step 8 - Manage access controls Applications Applications like Microsoft Teams, SharePoint, OneDrive, Exchange Online are the core to a Microsoft tenant. Getting these applications setup are essential to allowing users in education to access services and apps like Learning Accelerators. Overview - Review all steps that are a part of the application phase Exchange Online o Step 1 - Design an Exchange Online environment o Step 2 - Set up Exchange Online o Step 3 - Configure compliance and security in Exchange Online o Step 4 - Configure address books, shared mailboxes, and clients Microsoft Teams o Overview - What is Microsoft Teams for Education o Step 1 - Configure Microsoft Teams for Education o Step 2 - Configure Microsoft Teams policies and settings for education organization OneDrive/SharePoint - Overview o Step 1 - Plan your OneDrive and SharePoint Deployment o Step 2 - Share within OneDrive and SharePoint o Step 3 - Configure security and access controls in OneDrive and SharePoint o Step 4 - Compliance considerations with OneDrive and SharePoint Security and Compliance Security via each phase is essential to maintaining order and blocking access for bad actors. Along with security compliance/privacy considerations that are established to adhere to a multitude of local and government requirements worldwide. Overview Step 1 - Security Considerations Devices Managed and unmanaged devices are another key to helping secure the network and potential cyber-security considerations that enter the network via these devices. Overview Step 1 - Review device management structure Step 2 - Plan device management Step 3 - Configure settings and applications Step 4 - Deploy and manage devices Windows 11 features and tips References menu Mulit-tenant solutions - Architectural recommendations base on multi or large tenant solutions. Accessibility Deploy Office 365 applications Pooled storage management How do you use Golden Path? Golden Path uses deployment guidelines content that contain education scenario specifics. Golden Path has a linked path for each modules based on the phase (Baseline,Standard,Advanced). Users can follow the deployment content to establish or redefine the tenant configuration in order to enable additional services and products. What’s Next Go to https://aka.ms/gp4edu to access the first part of Golden Path. Part 1b (Standard -A3 content) NEXT Part 1c (Advanced – A5 content) Part 2 - We will create a mechanism to discover the tenant configuration settings and allow customers and partners the ability to qualify what is set to standard recommendation. Using AI to deliver user requirements against the configuration will allow additional paths to enable services and features that allow the user/customer to achieve their objectives. Part 3 – Deliver drift management solution for management of unrealized or understood changes that need to be approved or modified.335Views3likes1CommentIntune, MDT, WDS, Autopilot, Config Mgr
I am new to the community, hopefully asking in the correct general area. I am a one man IT shop at a small high school. We are a MS based school (365 A1; AD one-way sync to Azure; using WSUS/GP, and PDQ to deploy most everything. Though we are a BYOD school, I have several hundred school devices, Workstations, desktops, laptops, and tablets. These service both staff and students in labs, etc. Every summer I purchase/refresh a lab or two as well as staff machines. In the past, I have used FOG to image these PC's. I am looking for the Golden-Image scenario - model/drivers non-specific. Now with Windows 10, there seems to be many more options. I have been reading up on: Intune, MDT, ADK, WDS, Autopilot, and Configuration Manager. I am wondering if there is anyone out there in similar shoes (one man, low budget, etc.) , that use these Microsoft systems to manage their devices and could share what they use?2.5KViews0likes0Comments365 A3 for Faculty - cannot upgrade to Windows 10 edu (ent)
We recently purchased Microsoft 365 A3 for Faculty, we were assured that for educations users there was an upgrade path from home to Windows 10 Edu (comes with the 365 A3 for Faculty) . We have not been able to upgrade. Things we have tried: MDM, setting up MDM in intune, doesn't work with a rest on the home ed, or with a glpk on pro connecting user via azure (add work or school account) installing 10 pro and signing in with the domain account assigned the licence many command line product key tricks changing our domain and users to ***.onmicrosoft.com installing education and Enterprise editions installing the office apps setting up the education store to auto switch Contacting 365 support, activation support, support through our partner. Nothing we (or our partner) have done gets us closer (we have been working on this since Nov 30th). Any suggestions are greatly appreciated. Brad6.8KViews0likes1CommentRestrict Office 365 group creation to faculty licenses only
I am global admin. I need to restrict Office 365 Group creation to users with faculty licenses only. Students are creating groups and should be going through their instructors to do so. We have Azure AD Basic and cannot afford Premium licenses. Is there a way to set O365 Group creation by members of a Security group through scripting?1.6KViews0likes2CommentsAzure AD Group Based Licensing in Education. Will this apply to Staff, Students and Alumni?
Please note that I have previously posted this as a ‘reply’ to the announcement of the feature https://techcommunity.microsoft.com/t5/Azure-Active-Directory/Azure-AD-group-based-license-management-for-Office-365-and-more/m-p/57595#M304 - I apologize if this is some sort of cross posting breach. Greetings all, My question is specifically in regards to end user licensing in the Education Sector, which is needed to use Azure AD Group Based Licensing. Going by Source 1, all users who inherit a license via the group based licensing model will need an Azure AD Basic license (not Azure AD Free). Going by Source 2, this will change once the functionality reaches GA. Once this happens, "it will be included in Office 365 Enterprise E3 and similar products." As Education licensing differs from the standard Enterprise E3, will this functionality be included at no cost for Student and Alumni licensing? As you can imagine, a large University will have hundreds of thousands of Alumni and tens of thousands of Students. Having Education E3 include the Azure AD Basic licensing / eligibility for Azure AD Group based licensing for $0 will help for Staff, but if Azure AD Basic licensing is not included for Alumni and Students, the Education sector will not be able to afford to use this awesome functionality. Can someone please provide clarity, and preferably a link to a valid Microsoft site, on how Azure AD Group Based Licensing and Azure AD Basic will apply to Staff, Students and Alumni. Source 1 - Link - https://docs.microsoft.com/en-us/azure/active-directory/active-directory-licensing-whatis-azure-port... Features – During public preview, a paid or trial subscription for Azure AD basic or premium editions is required in the tenant to use group-based license management. Also, every user who inherits any licenses from groups must have the paid Azure AD edition license assigned to them. Source 2 - Link - https://blogs.technet.microsoft.com/enterprisemobility/2017/02/22/announcing-the-public-preview-of-a... It contains the following statement: "While group-based license management is in public preview you will need an active subscription for Azure AD Basic (or above) in your tenant to assign licenses to groups. If you don’t have one, just sign up for an Enterprise Mobility + Security trial. Later, when this functionality becomes generally available it will be included in Office 365 Enterprise E3 and similar products."3.3KViews4likes3CommentsWindows 10 Pro Education: Unwanted downgrade to Pro
Hi everyone, a strange thing we've been encountering for a week now: We upgraded our Windows 10 Pro installations on our Surface 4 Pro devices per the setting in the Microsoft Store for Business (a benefit). This has worked since a week ago, when almost all of the "Hybrid Azure AD joined" (local AD and online AAD fused to single identity) devices were automatically downgraded to Windows 10 Pro, losing all of the GPOs that had been working fine before. All devices still show up as joined in the AAD portal. Doe anyone have any idea where to look for a solution? Thanks a lot! Neven2KViews0likes2Comments