Provision tenants
- Configure the tenant name, tenant region, initial global administrator; manage tenant subscriptions; manage the licensing model; configure tenant for new features and updates
Add and configure custom domains
- Specify domain name; confirm ownership; specify domain purpose; set default domain; move ownership of DNS to Office 365; update and verify domain settings
Plan a pilot
- Designate pilot users; identify workloads that don’t require migration; run the Office 365 Health, Readiness, and Connectivity Checks; run IdFix; create a test plan or use case; set up email accounts for pilot users
Configure DNS records for services
- Create DNS records for Exchange Online, Skype for Business Online, and SharePoint Online; update and verify DNS records for Office 365 settings
Enable client connectivity to Office 365
- Configure proxy to allow the client access to Office 365 URLs; configure firewalls for outbound port access to Office 365; recommend bandwidth and internet connectivity for clients; deploy desktop set up for previous versions of Office clients
Administer Microsoft Azure Rights Management Service (RMS)
- Activate rights management; set up Office integration with rights management; assign roles for Rights Management; enable recovery of protected documents; set up templates for rights management protected email
Manage administrator roles in Office 365
- Implement a permission model; create or revoke the assignment of administrative roles or the administrative model; assign Global administrator, Billing administrator, Exchange administrator, Password administrator, Skype for Business administrator, Service administrator, SharePoint administrator, User management administrator, Compliance admin, Dynamics 365 service administrator, Power BI administrator, and delegated administrator roles, implement scoped admin roles
Configure password management
- Set expiration policy, password complexity, and password resets in Admin center
Manage user and security groups
- Perform a bulk import (CSV) and soft delete using the Admin center; configure multi-factor authentication
Manage cloud identities with Windows PowerShell
- Configure passwords to never expire; perform a bulk update of user properties; perform bulk user creation using Azure Active Directory cmdlets; perform bulk user license management; hard delete users
Prepare on-premises Active Directory for Azure AD Connect
- Plan for non-routable domain names; clean up existing objects; plan for filtering Active Directory; plan support for multiple forests
Set up Azure AD Connect tool
- Implement soft match filtering; identify synchronized attributes, password sync, pass-through authentication, and installation requirements; implement multi-forest Azure AD Connect scenarios
Manage Active Directory users and groups with Azure AD Connect in place
- Create, modify, and soft delete users and groups with Azure AD Connect; perform scheduled synchronization; perform forced synchronization
Plan requirements for Active Directory Federation Services (AD FS)
- Plan namespaces, certificates, AD FS internal topologies, AD FS dependencies, WAP topologies, network requirements, and multi-factor authentication; plan access filtering using claims rules
Install and manage AD FS servers
- Create AD FS service account; configure farm or stand-alone settings; add additional servers; convert from standard to federated domain; manage certificate lifecycle
Install and manage WAP servers
- Set up perimeter network name resolution; install required Windows roles and features; set up certificates; configure WAP settings; set custom proxy forms login page; switch between federated authentication and password sync; implement password sync temporary fall back
Analyze reports
- Analyze service reports, mail protection reports, Office 365 audit log reports, portal email hygiene reports, Azure AD reports, and SharePoint usage reports
Monitor service health
- Set up RSS feeds; set up service health dashboard with an awareness of planned maintenance, service updates, and historical data; configure Office 365 Management Pack for System Center Operations Manager, Microsoft Graph reporting APIs, and Windows PowerShell cmdlets
Isolate service interruption
- Create a service request; identify connectivity issues using the Microsoft Remote Connectivity Analyzer (RCA), Microsoft Lync Connectivity Analyzer Tool, or Microsoft Connectivity Analyzer tool; resolve exchange issues with the hybrid free/busy troubleshooter; diagnose and fix Microsoft Outlook issues with Microsoft Support and Recovery Assistant for Office 365