Forum Discussion
Does Azure AD (AD Connect) "Password Write Back" require me to open an Port on my on-premise firewal
- Aug 04, 2020
Hi shawn_fielding ,
The file experience does not have a direct correlation to that of working directly within a Document Library granted but it is getting better all of the time and the conversational element and the co authoring all under one roof can make for a valuable proposition.
However if one is looking for true records management then Teams may not be the destination and it is OK to say no sometimes and maybe just look directly to SharePoint Online or elsewhere. And with Teams being Teams you would know doubt be able to surface any effort spent elsewhere within Teams.
I would like to point out as one example however as shown below:
You can add in additional metadata columns and have them visible in Teams. I could also directly within Excel in this example, update the metadata text column, so I pretty much did not leave Teams, other than going into the respective Office Application and I would now have that bit of metadata to sort, filter and search on.
You can also just go directly into SharePoint and use it in all of its glory by clicking on Open in SharePoint, although depending on the experience of your users this may open up a whole can of worms or not.
As for Lifecycle, retention and deletion etc. You can look to things like Group Lifecycle Policies. Or use Security and Compliance features such as Retention/Disposition Policies. You could also set labels.
You can as you have said reference another document library that could be configured as desired and have it appear as a folder in situ alongside other Channel content.
Thanks
Henry
I think this is what you are looking for:
https://docs.microsoft.com/en-us/azure/active-directory/active-directory-passwords-writeback
- AUser ZUserOct 14, 2017Copper Contributor
Thanks Cody, that answered my question the artical contains the following text
Doesn’t require any inbound firewall rules - Password writeback uses an Azure Service Bus relay as an underlying communication channel, meaning that you do not have to open any inbound ports on your firewall for this feature to work.
Thanks again
- NanthaKumarJan 16, 2024Copper Contributor
AUser ZUser do I need to open any outbound traffic for this function to work? I have a situation here, by default we block outbound internet for all servers, and we only open specific destinations. After setting up the password writeback in AD, we get an unknown error. To test, we open the onprem AD and Sync servers to the internet and we can reset the password from Azure. The question now is what is the destination that we need to allow for this service to work? We tested again by adding this URL to the allowed list, https://account.activedirectory.windowsazure.com/ but we keep getting "This password does not meet the length, complexity, age or history requirements of your corporate password policy." However the policy is correct, and we opened the server to the internet again we could use the same password and were able to change it successfully.