Anyone have first hand experience with migrating Office 365 Exchange Online authentication from ADFS to DirSync with password sync?<\/p>\n
I’ve all but decided to go for it and not host ADFS servers internally anymore, but I would really like some validation out there either way.<\/p>\n
It seems like a no brainer if you don’t consider the password sync a security risk. We are really trying to eliminate the dependency of our infrastructure on availability of Email.<\/p>\n
So, let me have it. Do we like DirSync over ADFS?<\/p>","upvoteCount":4,"answerCount":12,"datePublished":"2013-09-06T15:48:28.000Z","author":{"@type":"Person","name":"keithstorrs0472","url":"https://community.spiceworks.com/u/keithstorrs0472"},"acceptedAnswer":{"@type":"Answer","text":"
Yes,<\/p>\n
I have done this for a client recently.<\/p>\n
All mailboxes “lived” in O365 (no on-premise mailboxes).<\/p>\n
You run a Powershell script to convert the O365 to standard rather than Federated. This resets all the users passwords so in this period people can’t authenticate.<\/p>\n
Uninstall ADFS.<\/p>\n
Uninstall any version of DirSync and install and configure the latest version. All users passwords will be re-synched.<\/p>","upvoteCount":1,"datePublished":"2013-09-06T15:56:36.000Z","url":"https://community.spiceworks.com/t/office-365-exchange-online-adfs-to-dirsync-review/237800/2","author":{"@type":"Person","name":"Huw3481","url":"https://community.spiceworks.com/u/Huw3481"}},"suggestedAnswer":[{"@type":"Answer","text":"
Anyone have first hand experience with migrating Office 365 Exchange Online authentication from ADFS to DirSync with password sync?<\/p>\n
I’ve all but decided to go for it and not host ADFS servers internally anymore, but I would really like some validation out there either way.<\/p>\n
It seems like a no brainer if you don’t consider the password sync a security risk. We are really trying to eliminate the dependency of our infrastructure on availability of Email.<\/p>\n
So, let me have it. Do we like DirSync over ADFS?<\/p>","upvoteCount":4,"datePublished":"2013-09-06T15:48:28.000Z","url":"https://community.spiceworks.com/t/office-365-exchange-online-adfs-to-dirsync-review/237800/1","author":{"@type":"Person","name":"keithstorrs0472","url":"https://community.spiceworks.com/u/keithstorrs0472"}},{"@type":"Answer","text":"
Yup, as Huw points out, NTG does this.<\/p>","upvoteCount":1,"datePublished":"2013-09-06T16:22:48.000Z","url":"https://community.spiceworks.com/t/office-365-exchange-online-adfs-to-dirsync-review/237800/3","author":{"@type":"Person","name":"scottalanmiller","url":"https://community.spiceworks.com/u/scottalanmiller"}},{"@type":"Answer","text":"
Speaking of DIrSync, will this work if you are all on the same Office365 domain, but you have separate AD domains that make up all of the users? We have Office365 for all employess globally but the US and europe have their own domains. Currently there is no synch of passwords with Office365 which is a headache sometimes.<\/p>","upvoteCount":0,"datePublished":"2013-09-07T13:57:07.000Z","url":"https://community.spiceworks.com/t/office-365-exchange-online-adfs-to-dirsync-review/237800/4","author":{"@type":"Person","name":"alex3031","url":"https://community.spiceworks.com/u/alex3031"}},{"@type":"Answer","text":"
Are we talking separate AD forests?<\/p>","upvoteCount":0,"datePublished":"2013-09-07T18:44:59.000Z","url":"https://community.spiceworks.com/t/office-365-exchange-online-adfs-to-dirsync-review/237800/5","author":{"@type":"Person","name":"Huw3481","url":"https://community.spiceworks.com/u/Huw3481"}},{"@type":"Answer","text":"
Completely separate domains, not even a trust relationship between them, only a couple of their IT people have admin accounts in our domain, we don’t have a single account on theirs.<\/p>","upvoteCount":0,"datePublished":"2013-09-07T21:51:33.000Z","url":"https://community.spiceworks.com/t/office-365-exchange-online-adfs-to-dirsync-review/237800/6","author":{"@type":"Person","name":"alex3031","url":"https://community.spiceworks.com/u/alex3031"}},{"@type":"Answer","text":"
DirSync can’t help you then as it only supports a single AD forest.<\/p>","upvoteCount":0,"datePublished":"2013-09-09T05:17:35.000Z","url":"https://community.spiceworks.com/t/office-365-exchange-online-adfs-to-dirsync-review/237800/7","author":{"@type":"Person","name":"Huw3481","url":"https://community.spiceworks.com/u/Huw3481"}},{"@type":"Answer","text":"
Thanks<\/p>","upvoteCount":0,"datePublished":"2013-09-09T17:04:21.000Z","url":"https://community.spiceworks.com/t/office-365-exchange-online-adfs-to-dirsync-review/237800/8","author":{"@type":"Person","name":"alex3031","url":"https://community.spiceworks.com/u/alex3031"}},{"@type":"Answer","text":"
If I am reading your post correctly, it sounds as if you are trying to get real SSO across mupltiple AD’s? Office 365 to my knowledge doesn’t support this. It may be a mute point if you already have O365 running, but EarthLink’s 365 solves those issues with email while supporting the rest (lync & sharepoint). Ping me if you have questions.<\/p>","upvoteCount":0,"datePublished":"2013-09-09T19:03:42.000Z","url":"https://community.spiceworks.com/t/office-365-exchange-online-adfs-to-dirsync-review/237800/9","author":{"@type":"Person","name":"toddm9956","url":"https://community.spiceworks.com/u/toddm9956"}},{"@type":"Answer","text":"
Yea that’s what I was asking about, Office365 is already deployed was before I came on, would just like to simplify things, as you can imagine some people have a hard time with the multiple passwords thing.<\/p>","upvoteCount":0,"datePublished":"2013-09-09T20:15:30.000Z","url":"https://community.spiceworks.com/t/office-365-exchange-online-adfs-to-dirsync-review/237800/10","author":{"@type":"Person","name":"alex3031","url":"https://community.spiceworks.com/u/alex3031"}},{"@type":"Answer","text":"
Huw3481 and Scott Alan Miller, I’m trying to gauge how long I should tell my users to expect Email to be unavailable until the DirSync is run after the conversion. I’m wondering if you could enlighten me on how long the domain conversion process would take on 450 mailboxes? I’m not finding anything out there, so wondering if some real world experience could give me a clue.<\/p>","upvoteCount":0,"datePublished":"2013-09-10T11:15:28.000Z","url":"https://community.spiceworks.com/t/office-365-exchange-online-adfs-to-dirsync-review/237800/11","author":{"@type":"Person","name":"keithstorrs0472","url":"https://community.spiceworks.com/u/keithstorrs0472"}},{"@type":"Answer","text":"