Email from one O365 domain controlled by Ajax.com and using Sharepoint & One Drive on mydomain.com

%3CLINGO-SUB%20id%3D%22lingo-sub-879609%22%20slang%3D%22en-US%22%3EEmail%20from%20one%20O365%20domain%20controlled%20by%20Ajax.com%20and%20using%20Sharepoint%20%26amp%3B%20One%20Drive%20on%20mydomain.com%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-879609%22%20slang%3D%22en-US%22%3E%3CP%3EI%20have%20a%20user%20(John%20Smith)%20that%20is%20a%20financial%20adviser%20for%20Ajax%20Investments%20Ajax.xom.%26nbsp%3B%20%26nbsp%3BAjax%20has%20950%20independent%20financial%20advisers%20throughout%20the%20United%20States.%26nbsp%3B%20%26nbsp%3BAjax%20is%20responsible%20for%20providing%20each%26nbsp%3Bindependent%20financial%20advisers%20an%20email%20account%20that%20meets%20SEC%20rules%20which%20requires%20email%20Journaling%20so%20the%20minimum%20O365%20seat%20they%20provide%20to%20John%20Smith%20would%20be%20E3.%26nbsp%3B%20%26nbsp%3BAjax%20provides%20an%20email%20address%20of%20JohnSmith%40Ajax.xom%20to%20John%20Smith%20and%20it%20is%20a%20regular%20user%20account%20without%20access%20to%20administrator%20or%20domain%20administrator%20functions.%26nbsp%3B%20Ajax%20has%20Sharepoint%20and%20One%20Drive%20disabled%20for%20all%20users%20in%20the%20Ajax.com%20domain.%26nbsp%3B%20Ajax%20has%20MFA%20(Multi%20factor%20authentication)%20enabled%20for%26nbsp%3BJohnSmith%40Ajax.xom.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EAjax.xom%20told%20John%20Smith%20to%20purchase%20a%20new%20domain%20of%26nbsp%3Bmydomain.com%20and%20create%20a%20new%20Office%20365%20account%20using%26nbsp%3Bmydomain.com%20as%20the%20tenant%20domain%20for%20Sharepoint%20and%20One%20Drive.%26nbsp%3B%20John%20Smith%20does%20not%20intend%20to%20use%20his%20email%20address%20of%20johnsmith%40mydomain.com%20at%20all%20and%20is%20forbidden%20to%20use%20it%20for%20business%20by%20SEC%20rules%20since%20it%20is%20not%20being%20filtered%20for%20bad%20advice%2C%20keywords%2C%20and%20has%20no%26nbsp%3Bemail%20Journaling.%26nbsp%3B%20Ajax%20is%20requiring%26nbsp%3BMFA%20(Multi%20factor%20authentication)%20to%20be%20enabled%20for%20johnsmith%40mydomain.com.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJohn%20Smith%20is%20using%20OWA%26nbsp%3B%26nbsp%3Bwith%20his%20JohnSmith%40Ajax.xom%20account%20and%20want%20to%20attached%20a%20300%20MB%20file%20and%20OWA%20prompts%20him%20with%20the%20option%20to%20upload%20it%20to%20One%20Drive%20and%20send%20a%20link%20to%20the%20recipient.%26nbsp%3B%20How%20will%20this%20work%20given%20there%20are%20two%20different%20domains%20involved%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EJohn%20Smith%20is%20setting%20up%26nbsp%3BJohnSmith%40Ajax.xom%20on%20his%20smartphone%20for%20emailing%20clients%20along%20with%20Sharepoint%20and%20One%20Drive%26nbsp%3Bjohnsmith%40mydomain.com.%26nbsp%3B%20The%20email%20accoutnt%20JohnSmith%40Ajax.xom%20is%20using%20MFA.%26nbsp%3B%20%26nbsp%3BThe%20SharePoint%20account%20tied%20to%26nbsp%3Bjohnsmith%40mydomain.com%20and%20the%20One%20Drive%20account%20tied%20to%26nbsp%3Bjohnsmith%40mydomain.com%20are%20using%20MFA.%26nbsp%3B%26nbsp%3BHow%20will%20this%20work%20given%20there%20are%20two%20different%20domains%20involved%3F%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EIt%20seems%20to%20me%20that%20this%20setup%20is%20counter%20intuitive%20to%20how%20Office%20365%20is%20designed%20and%20supported.%26nbsp%3B%20We%20have%20a%20difficult%20time%20supporting%20users%20with%201%20domain%20in%20Office%20365%20email%2C%20SharePoint%2C%20and%20One%20Drive%20using%20MFA%20on%20a%20daily%20basis%20with%20all%20the%20things%20that%20arise.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EI%20appreciate%20input%20from%20the%20community%2C%20especially%20from%20anyone%20that%20has%20tried%20this%20recently.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-LABS%20id%3D%22lingo-labs-879609%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ECompliance%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EExchange%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOffice%20365%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3EOneDrive%20for%20Business%3C%2FLINGO-LABEL%3E%3CLINGO-LABEL%3ESharePoint%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E%3CLINGO-SUB%20id%3D%22lingo-sub-883300%22%20slang%3D%22en-US%22%3ERe%3A%20Email%20from%20one%20O365%20domain%20controlled%20by%20Ajax.com%20and%20using%20Sharepoint%20%26amp%3B%20One%20Drive%20on%20mydoma%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-883300%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F416456%22%20target%3D%22_blank%22%3E%40TJmustangTJ%3C%2FA%3EYour%20post%20is%20very%20long%20and%20very%20confusing.%20The%20most%20important%20thing%20is%20missing%3A%20What%20are%20you%20trying%20to%20achieve%3F%20I%20don't%20get%20why%20you%20create%20tenants%20for%20individual%20users.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-883443%22%20slang%3D%22en-US%22%3ERe%3A%20Email%20from%20one%20O365%20domain%20controlled%20by%20Ajax.com%20and%20using%20Sharepoint%20%26amp%3B%20One%20Drive%20on%20mydoma%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-883443%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20your%20response.%26nbsp%3B%20Unfortunately%20I%20do%20not%20think%20I%20can%20make%20my%20post%20shorter.%26nbsp%3B%20I%20have%20a%20user%20that%20is%20provided%20an%20email%20account%20(%3CSPAN%3EJohnSmith%40Ajax.xom)%3C%2FSPAN%3Ethat%20is%20hosted%20on%20Office%20365%20and%20the%20user%20does%20not%20have%20admin%20rights%20to%20anything.%26nbsp%3BThe%20user%20will%20be%20forced%20to%20use%20MFA%20on%20this%20email%20account.%26nbsp%3B%20One%20Drive%20and%20SharePoint%20is%20disabled%20on%20the%20Office%20365%20account%20associated%20with%26nbsp%3B%3CSPAN%3EJohnSmith%40Ajax.xom.%26nbsp%3B%20The%20user%20is%20going%20to%20create%20an%20individual%20Office%20365%20account%20with%20a%20tenant%20mydomain.com%3C%2FSPAN%3E.%26nbsp%3B%20The%20user%20will%20assign%20himself%20an%20email%20account%20of%26nbsp%3B%3CSPAN%3Ejohnsmith%40mydomain.com%20and%20use%20OnDrive%20and%20SharePoint%20under%26nbsp%3Bmydomain.com%20with%20MFA.%26nbsp%3B%20How%20will%20all%20this%20work%20on%20the%20same%20PC%20with%20Outlook%20and%20the%20same%20smart%20phone%3F%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F65328%22%20target%3D%22_blank%22%3E%40Daniel%20Niccoli%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-885180%22%20slang%3D%22en-US%22%3ERe%3A%20Email%20from%20one%20O365%20domain%20controlled%20by%20Ajax.com%20and%20using%20Sharepoint%20%26amp%3B%20One%20Drive%20on%20mydoma%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-885180%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F416456%22%20target%3D%22_blank%22%3E%40TJmustangTJ%3C%2FA%3E%26nbsp%3BIf%20you%20do%20not%20connect%20the%20computer%20to%20Azure%20AD%2C%20then%20you%20can%20just%20sign%20in%20to%20each%20app%20with%20the%20required%20account.%20If%20you%20access%20web%20services%2C%20you%20need%20a%20different%20browser%20or%20browser%20profile%20for%20each%20tenant.%3C%2FP%3E%3CP%3E%26nbsp%3B%3C%2FP%3E%3CP%3EHowever%2C%20there%20is%20no%20cross-service%20access%20(Outlook%2Fajax.com%20accessing%20files%20on%20OneDrive%2Fmydomain.com).%26nbsp%3BOffice%20365%20is%20not%20really%20meant%20to%20be%20used%20by%20a%20single%20person%20with%20multiple%20tenants.%26nbsp%3BIf%20you%20need%20that%2C%20then%20you're%20having%20a%20management%20problem%20rather%20than%20a%20technical%20problem%20and%20the%20user%20should%20have%20all%20services%20accessible%20under%20one%20tenant.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-886140%22%20slang%3D%22en-US%22%3ERe%3A%20Email%20from%20one%20O365%20domain%20controlled%20by%20Ajax.com%20and%20using%20Sharepoint%20%26amp%3B%20One%20Drive%20on%20mydoma%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-886140%22%20slang%3D%22en-US%22%3E%3CP%3EThanks%20for%20the%20response.%26nbsp%3B%20I%20agree%20with%20the%20statement%20%22%3CSPAN%3EOffice%20365%20is%20not%20really%20meant%20to%20be%20used%20by%20a%20single%20person%20with%20multiple%20tenants.%22%26nbsp%3B%20One%20major%20problem%20I%20foresee%20is%20John%20Smith%20is%20a%20financial%20adviser%26nbsp%3Bunder%20Ajax%20and%20must%20use%26nbsp%3BJohnSmith%40Ajax.xom%20when%20communicating%20with%20clients%20because%20of%20SEC%20rules.%26nbsp%3B%20%26nbsp%3BWhat%20will%20happen%20when%20John%20Smith%20is%20composing%20an%20email%20in%20OWA%20using%20the%26nbsp%3BJohnSmith%40Ajax.xom%20account%20and%20he%20needs%20to%20attach%20a%20large%20file.%26nbsp%3B%20OWA%20will%20offer%20to%20upload%20the%20file%20to%20One%20Drive%20and%20send%20a%20link.%26nbsp%3B%20Ajax%20has%20One%20Drive%20associated%20with%20JohnSmith%40Ajax.xom%20disabled%20and%20instructed%26nbsp%3BJohn%20Smith%20to%20create%20One%20Drive%20tied%20to%26nbsp%3Bjohnsmith%40mydomain.com.%26nbsp%3B%20I%20do%20not%20think%20John%20Smith%20will%20ever%20be%20able%20to%20seamlessly%20use%20One%20Drive%20from%26nbsp%3Bjohnsmith%40mydomain.com%20with%20OWA%20email%20under%26nbsp%3BJohnSmith%40Ajax.xom.%26nbsp%3B%20I%20have%20had%20lengthy%26nbsp%3Bdiscussions%20with%20Ajax%20expressing%20my%20concerns%20and%20that%20they%20are%20attempting%20to%20use%20Office%20365%20in%20a%20way%20it%20was%20never%20designed%20to%20be%20used.%3C%2FSPAN%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F65328%22%20target%3D%22_blank%22%3E%40Daniel%20Niccoli%3C%2FA%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E
Highlighted
New Contributor

I have a user (John Smith) that is a financial adviser for Ajax Investments Ajax.xom.   Ajax has 950 independent financial advisers throughout the United States.   Ajax is responsible for providing each independent financial advisers an email account that meets SEC rules which requires email Journaling so the minimum O365 seat they provide to John Smith would be E3.   Ajax provides an email address of JohnSmith@Ajax.xom to John Smith and it is a regular user account without access to administrator or domain administrator functions.  Ajax has Sharepoint and One Drive disabled for all users in the Ajax.com domain.  Ajax has MFA (Multi factor authentication) enabled for JohnSmith@Ajax.xom.

 

Ajax.xom told John Smith to purchase a new domain of mydomain.com and create a new Office 365 account using mydomain.com as the tenant domain for Sharepoint and One Drive.  John Smith does not intend to use his email address of johnsmith@mydomain.com at all and is forbidden to use it for business by SEC rules since it is not being filtered for bad advice, keywords, and has no email Journaling.  Ajax is requiring MFA (Multi factor authentication) to be enabled for johnsmith@mydomain.com.

 

John Smith is using OWA  with his JohnSmith@Ajax.xom account and want to attached a 300 MB file and OWA prompts him with the option to upload it to One Drive and send a link to the recipient.  How will this work given there are two different domains involved?

 

John Smith is setting up JohnSmith@Ajax.xom on his smartphone for emailing clients along with Sharepoint and One Drive johnsmith@mydomain.com.  The email accoutnt JohnSmith@Ajax.xom is using MFA.   The SharePoint account tied to johnsmith@mydomain.com and the One Drive account tied to johnsmith@mydomain.com are using MFA.  How will this work given there are two different domains involved?

 

It seems to me that this setup is counter intuitive to how Office 365 is designed and supported.  We have a difficult time supporting users with 1 domain in Office 365 email, SharePoint, and One Drive using MFA on a daily basis with all the things that arise.

 

I appreciate input from the community, especially from anyone that has tried this recently.

4 Replies
Highlighted

@TJmustangTJYour post is very long and very confusing. The most important thing is missing: What are you trying to achieve? I don't get why you create tenants for individual users.

Highlighted

Thanks for your response.  Unfortunately I do not think I can make my post shorter.  I have a user that is provided an email account (JohnSmith@Ajax.xom)that is hosted on Office 365 and the user does not have admin rights to anything. The user will be forced to use MFA on this email account.  One Drive and SharePoint is disabled on the Office 365 account associated with JohnSmith@Ajax.xom.  The user is going to create an individual Office 365 account with a tenant mydomain.com.  The user will assign himself an email account of johnsmith@mydomain.com and use OnDrive and SharePoint under mydomain.com with MFA.  How will all this work on the same PC with Outlook and the same smart phone?@Daniel Niccoli 

Highlighted

@TJmustangTJ If you do not connect the computer to Azure AD, then you can just sign in to each app with the required account. If you access web services, you need a different browser or browser profile for each tenant.

 

However, there is no cross-service access (Outlook/ajax.com accessing files on OneDrive/mydomain.com). Office 365 is not really meant to be used by a single person with multiple tenants. If you need that, then you're having a management problem rather than a technical problem and the user should have all services accessible under one tenant.

Highlighted

Thanks for the response.  I agree with the statement "Office 365 is not really meant to be used by a single person with multiple tenants."  One major problem I foresee is John Smith is a financial adviser under Ajax and must use JohnSmith@Ajax.xom when communicating with clients because of SEC rules.   What will happen when John Smith is composing an email in OWA using the JohnSmith@Ajax.xom account and he needs to attach a large file.  OWA will offer to upload the file to One Drive and send a link.  Ajax has One Drive associated with JohnSmith@Ajax.xom disabled and instructed John Smith to create One Drive tied to johnsmith@mydomain.com.  I do not think John Smith will ever be able to seamlessly use One Drive from johnsmith@mydomain.com with OWA email under JohnSmith@Ajax.xom.  I have had lengthy discussions with Ajax expressing my concerns and that they are attempting to use Office 365 in a way it was never designed to be used.@Daniel Niccoli