office 365
83 TopicsMicrosoft Ignite 2018 - The Recap
Microsoft Ignite 2018 ended a few weeks ago, and what a great event it was. It was great to see so many of our customers, partners and friends there – thank you for coming to our sessions, thank you for coming to the booth, thank you for hanging out with us whenever the opportunity arose and thank you for giving us great feedback on what we’re doing. We’re still recovering but we heard you and are focused on doing a better job because of it. All of the sessions were recorded this year, and so here’s a handy reference to all the sessions in the Exchange and Outlook track, and some others we think you’ll find interesting, so you can refer back here whenever you want to find one. You will need an account in Tech Community to access them, but that’s something you should have anyway. So here’s a long list of sessions, in no particular order but grouped by technology as much as possible. Exchange Welcome to Exchange 2019! Panel discussion: Microsoft Exchange/Calendar/OWA Hybrid Exchange – Making it easier and faster to move to the cloud Scott Schnoll's Exchange and Office 365 Tips & Tricks Securing Exchange Online from Modern Threats So long and thanks for all the (email) phish Email Search in a Flash! Accelerating Exchange 2019 with SSDs Turbo charge your Exchange on-premises and Hybrid environment – Notes from the field How to add MFA to your Exchange On-Prem/Online mailboxes in 20 minutes or less Preparing to Move (or remove) Those Public Folders to the Cloud Why do we need to keep an Exchange Server on-premises when we move to the cloud? Making the best of the cloud: How Exchange Online is different from Exchange on-premises Azure Information Protection and Exchange Online - better together Securing your Office 365 environment from advanced phishing campaigns with Office 365 Advanced Threat Protection Outlook Deep dive into what’s new and coming soon to Outlook for Windows and Mac Outlook mobile in the Enterprise Deploying Outlook mobile securely in the enterprise What's Amazing and New in Calendaring in Outlook! Outlook on the web - What's new and why you should care! The Best (Outlook driven) Day of Your Life Success through people with LinkedIn and Microsoft 365 What's New in groups in Outlook Panel discussion: Microsoft Outlook (Windows, Mac, and Mobile) Let the intelligence built into Outlook help you to make time for what really matters Simple room booking in Outlook using new built-in Intelligence The Power of People in Outlook Security made real with Outlook mobile in-app experiences Outlook on the web: Don’t block your users, restrict them with conditional access/limited access! Adaptive Cards in Teams, Windows, Outlook and your own applications Create engaging, powerful new business processes in Microsoft Outlook with Adaptive Cards Office 365 Notes from the field: how we moved a large global bank to Office 365 Office 365 – Marriages, Divorces and Adoptions Getting stuff done: Solving Office 365 problems with PowerShell How to be an author and write about Office 365 Real-world best practices for managing Office 365 groups Embrace Office 365 Groups: What's new and how to get started Office 365 Groups automation inside-out Delivering Office 365 as an evergreen service: What to do, and more importantly, what not to do Understanding how Microsoft Information Protection capabilities work together to protect sensitive information across devices, apps, and services Secure enterprise productivity with Office 365 threat protection services including EOP, ATP, and Threat Intelligence Strategies for building effective, optimal and future proof connectivity to Office 365 that will delight your users Implementing a modern network architecture to get the most out of Office 365 Addressing global data residency needs with Multi-Geo in Office 365 Podcasts/Broadcasts Ross Smith IV & Greg Taylor on theCUBE Scott Schnoll & Jeff Mealiffe on theCUBE Ross Smith IV on Channel 9 talking about Outlook mobile Greg Taylor on Channel 9 talking about Exchange Server 2019 Greg Taylor, Tony Redmond and Paul Robichaux – Office 365 Exposed talking about random stuff It’s possible we missed a session you think we should have included (there were 750 or more after all), if so, add it to the comments section so people can find it. Thanks! Happy watching! And see you next year for more of the same. Microsoft Ignite 2019 here we come! Greg Taylor Director of Product Marketing Exchange Server and Online11KViews1like3CommentsIn-Place eDiscovery and In-Place Hold in the New Exchange; Part II
In Part I of this post, we covered what’s new in In-Place eDiscovery in the new Exchange. In this post, let’s take a look at how the new Exchange retains data immutably. One of the first steps you must take when reasonable expectation of litigation exists or when served an eDiscovery request is to preserve messaging records so they can be produced when required. Before Exchange 2010, this was generally achieved using different methods, including archiving data to an external system, suspending automated deletion mechanism (such as Exchange’s Messaging Records Management), or in some cases - by instructing users to not delete records. Failure to preserve records required for litigation may expose your organization to legal and financial risk. In Exchange 2010 and Office 365, we introduced Litigation Hold to enable you to preserve messaging records. Litigation Hold is a mailbox property – placing a mailbox on litigation hold places all items in a mailbox on hold indefinitely (or until hold is removed), resulting in accumulation of a large volume of data – all of which may not be required to be preserved. In the new Exchange, you can use In-Place Hold to retain items immutably. In-Place Hold is integrated with In-Place eDiscovery, allowing you to perform both search and hold using the same interface and the same query parameters. You can use In-Place Hold in the following scenarios. Indefinite Hold: You can create an In-Place Hold without any query parameters and without a hold duration to hold all items in a mailbox indefinitely or until the hold is removed. This emulates the behavior of litigation hold. Query-Based Hold: Using In-Place Hold, you can create a search query and specify the source mailboxes and parameters such as keywords, senders and recipients, as well as start and end dates. You can also specify the type of items to search – email messages, calendar items such as meetings and appointments, tasks, notes, or Lync content archived in Exchange mailboxes. Time-Based Hold: Whereas Litigation Hold placed all mailbox contents on hold indefinitely or until you remove the hold, In-Place Hold allows you to specify a duration of time for which to hold items. The time is calculated based on the received date or the date the item was created in the mailbox (for items such as appointments, tasks and notes that are not sent/received). One of the more common feature requests in Exchange 2010 was to be able to specify a definite time period for which an item is retained. Whereas retention policies allow you to specify the email lifecycle and automatically delete items when the specified period is reached, they don’t guarantee retention for that period. In other words, you could specify items will be kept for a maximum of 7 years, but you couldn’t guarantee items won’t be deleted before that period by a user or a process. The commonly recommended workaround to meet this requirement was to use configure the Deleted Item Recovery period to the minimum period you want an item to be retained for. In this example, setting the deleted item retention period to 7 years means if a user deletes an item before 7 years, it is retained in the Recoverable Items folder for 7 years. However, the period for Deleted Item Retention is calculated from the date of deletion. If a user deletes an item after 6 years, it is retained for an additional 7 years in the Recoverable Items folder, resulting in a total retention period of 13 years. In others words, you can guarantee an item will be retained for a minimum of 7 years, but not the maximum retention period. In the new Exchange, when you create a time-based In-Place Hold, because the hold period is calculated from the item received/creation date, you can guarantee the item won’t be held beyond that period. You can combine a time-based In-Place Hold with a Retention Policy (that has a single default policy tag) to ensure items in the mailbox are deleted by the Managed Folder Assistant (MFA) after 7 years, and items deleted by a user or a process before that period are retained for at least the specified duration. You can also combine a query-based In-Place Hold with a time-based hold to preserved items matching query parameters for the specified period. You can also place a user on multiple holds - for example, when a mailbox may contain records pertaining to multiple cases or investigations. In-Place Hold & Permissions Like In-Place eDiscovery, In-Place Hold can be used by authorized users with delegated Discovery Management permission. However, there’s a slight twist. The Discovery Management role group is assigned the Mailbox Search and Litigation Hold management roles. The former allows an authorized user to create a mailbox search for In-Place eDiscovery and Hold. The latter actually allows you to place mailbox content on hold. If a user is only assigned the Litigation Hold role, for example by creating a custom role-based access control (RBAC) role group or via membership of a role group such as Organization Management that has the Litigation Hold role assigned, the user is able to use In-Place Hold - but only to place all mailbox content on hold. The user can’t specify query parameters. In other words, the user can’t create a query-based In-Place Hold. Creating an In-Place Hold Let’s go back to the query Robin created in Part I of this post. When creating the In-Place Hold, on the Mailboxes page Robin must select Specify mailboxes to search and select the mailboxes or distribution groups. If she selects Search all mailboxes, the option to place content on hold will not be available. You must specify mailboxes or distribution groups to place on hold. If you select Search all mailboxes, the option to place content on hold will not be available. Figure 1: To create an In-Place Hold, you must select Specify mailboxes to search Note: If you select a distribution group, the hold applies to mailbox users that are members of the group when the hold is created. On the Search query page, Robin can use the same query she used for the In-Place eDiscovery. Figure 2: Messages matching query parameters are preserved She can also select the message types to place on hold. Figure 3: You can specify the message types to hold or hold all message types Placing archived Lync content on hold If the new Lync is enabled to archive Instant Messaging and meeting content into the new Exchange, Lync content is archived in the user’s mailbox and automatically placed on hold. You need to configure OAuth authentication between Lync and Exchange to enable this. Additionally, the mailbox must be located on a Mailbox server in the new Exchange. On the In-Place Hold settings page, Robin selects the option to Place content matching the search query in selected mailboxes on hold. She can then select Hold indefinitely to hold content indefinitely (or until the In-Place Hold is removed or a mailbox is removed from the search). To hold items for a specific period, she can select Specify number of days to hold items relative to their received date and specify the number of days. Figure 4: You can specify a hold duration or hold items indefinitely It’s important to reiterate here that for the time-based hold, the duration is calculated from the date a message is received/created. How In-Place Hold Works Let’s take a look at what happens under the hood. When a user deletes a message, it goes to the Deleted Items folder. When the Deleted Items folder is emptied or messages are deleted from it, or the user uses Shift-Delete to delete a message, it is moved to the Recoverable Items\Deletes folder. Contents of this folder are exposed when the user uses Recover Deleted Items in Outlook or Outlook Web App. If the user doesn’t do anything, messages from the Deletes folder are purged when the Deleted Items Retention period configured for the mailbox database or the user expires. If the user deletes a message from this view, few things can happen: If Single Item Recovery is enabled for the mailbox, the item is moved to the Recoverable Items\Purges folder and retained until the deleted item retention period expires. This provides the administrator the capability to recover items without having to recover from backups. If the mailbox is placed on Litigation Hold, the items is moved to the Recoverable Items\Purges folder and retained until the hold is removed. If the mailbox is placed on an In-Place Hold, the item is moved to the Recoverable Items\DiscoveryHolds folder. Figure 5: Deleted items and original copies of modified items are preserved in the Recoverable Items folder of each mailbox When the MFA , a mailbox assistant that processes mailboxes and expires content, processes the mailbox, it checks if messages meet the query parameters of any In-Place Holds the user is placed on. This evaluation is done for up to 5 queries, beyond which all items are retained – emulating the same behavior as litigation hold. If the number of holds is brought below 5, the MFA again reverts to the query-based In-Place Hold behavior. When the In-Place Hold is removed, messages placed on hold are removed if they no longer match query parameters of any other In-Place Hold that the user may have been placed on. In-Place Hold and Immutability When talking about preservation, the concept of immutability invariably comes up. Immutability means messages placed on hold must be preserved without alteration. Not only should we prevent them from deletion (even if the user placed on hold thinks they’ve successfully purged the message), but the messages should also be prevented from tampering or alteration. Immutability is not a product feature but a combination of feature and the hold processes your organization implements. In-Place Hold also helps you preserve content from intentional tampering or modification. This is achieved by performing a copy-on-write (COW) – when the user or any process attempts to modify a message, before the modified message is saved a copy of the original message is made and saved in the Recoverable Items\Versions folder. Items captured in the Versions folder are also indexed and returned in an In-Place eDiscovery search. When the hold is removed, the copies made in the Versions folder are also removed by the Managed Folder Assistant. Together, In-Place Hold and In-Place eDiscovery provide an easy-to-use mechanism for authorized legal, human resources or other non-technical personnel to easily search and immutably preserve messaging records. Bharat Suneja and Julian Zbogar-Smith35KViews0likes0CommentsMail flow insights (wave 2) will soon be available in O365 Security & Compliance Center
As you might have previously read, we released the first wave of mail flow insights last year (here is the original announcement). Admins can use the mail flow dashboard in the Office 365 Security & Compliance Center to discover trends, insights, and take actions to fix issues related to mail flow in their Office 365 organization. We're excited to announce that second wave of mail flow insights will soon be available in the Office 365 Security & Compliance Center. The new insights will be rolled out to customers who have opted in to Targeted Release, and will start to show up in the admin's mail flow dashboard at the beginning of April 2019. We'll continue to create and refine mail flow insights to help improve productivity for admins, and we'll announce them as they become available. You can see the details in this doc, but a quick summary is listed below. Where to find mail flow insights? If you are a global admin or an Exchange administrator, you can go to the Office 365 Security & Compliance Center at https://protection.office.com. Expand Mail flow in the left hand nav, select Dashboard, you will see all insights on the right panel. As the doc we linked to earlier details, we're creating six new insights, reports and widgets available. Here are just a few examples of what you'll find in the mail flow insights dashboard. Mail Flow Map This report provides a visual map showing how mail flows through your Office 365 organization. You can use this information to learn patterns, identify anomalies, and fix issues as they arise. Domain mail flow status The Top domain mail flow status report gives you the current mail flow status for your organization's domains. This insight helps you identify and troubleshoot domains that are experiencing mail flow impacting issues (such as not receiving external email), domain expirations or domains with incorrect MX records. SMTP Auth client status This report allows you to detect potentially compromised accounts due to the use of legacy (less secure) protocols. Clicking the widget will allow admins to see details of accounts that are still using the SMTP Basic Auth protocol, and will allow them to investigate potentially compromised accounts. We really do encourage you to take advantage of mail flow insights in the Office 365 Security & Compliance Center and we hope you appreciate these additions. We will continue to improve the current insights as well as add new insights, and we're looking forward for your feedback! Note that you can click the Feedback button at the bottom of the page to give feedback directly from the Security & Compliance Center: Carolyn Liu18KViews0likes5CommentsFAQs on Office 365 Retention, Disposal and Archiving
With the introduction of Unified Retention & Retention Labels in the Security and Compliance, many customers have questions on the differences between Unified Retention, Retention Labels and MRM retention, configurable parameters and other common scenarios. Retention or Unified Retention Retention or Unified Retention is available in Office 365 Security and Compliance portal. Unified retention policy in Office 365 can help you achieve all these goals. Managing content commonly requires two actions: Retaining content so that it can't be permanently deleted before the end of the retention period. Deleting content permanently at the end of the retention period. With a retention policy, you can: Decide proactively whether to retain content, delete content, or both - retain and then delete the content. Apply a single policy to the entire organization or just specific locations or users. Apply a policy to all content or just content meeting certain conditions, such as content containing specific keywords or specific types of sensitive information. SCC Retention provides true retention, you can use a single SCC retention policy to perform both deletion and retention and at the same time a single policy can be applied across different workloads. For more details, refer Overview of Retention Policies Retention Labels Retention Labels is available in Office 365 Security and Compliance portal. Retention labels in Office 365 can help you take the right actions on the right content. With retention labels, you can classify data across your organization for governance, and enforce retention rules based on that classification. With retention labels, you can: Enable people in your organization to apply a retention label manually to content in Outlook on the web, Outlook 2010 and later, OneDrive, SharePoint, and Office 365 groups. Users often know best what type of content they're working with, so they can classify it and have the appropriate policy applied. Apply retention labels to content automatically if it matches specific conditions, such as when the content contains: Specific types of sensitive information. Specific keywords that match a query you create. The ability to apply retention labels to content automatically is important because: You don't need to train your users on all of your classifications. You don't need to rely on users to classify all content correctly. Users no longer need to know about data governance policies - they can instead focus on their work. Apply a default retention label to a document library in SharePoint and Office 365 group sites, so that all documents in that library get the default retention label. Implement records management across Office 365, including both email and documents. You can use a retention label to classify content as a record. When this happens, the label can't be changed or removed, and the content can't be edited or deleted. Retention setting in Labels and Unified Retention is same. A single retention labels policy to perform both deletion and retention and at the same time a single policy can be applied across different workloads. There are different ways to monitor the usage of Retention Labels using Data Governance Dashboard, Label Activity Explorer (Available with E5 only), Content Search, Audit log For more details, refer Overview of Retention Labels Messaging Records Management (MRM) Messaging Records Management aka Retention Policy is available in Exchange on-premises as well as in Exchange online and available in Exchange Admin Center (EAC). You can use retention policies to enforce basic message retention for an entire mailbox or for specific default folders. Although there are several strategies for deploying MRM, here are some of the most common: Remove all messages after a specified period. Move messages to archive mailboxes after a specified period. Remove messages based on folder location. Allow users to classify messages. Retain messages for eDiscovery purposes. When you implement MRM policies that remove messages from mailboxes after a specified period it also retains them in the Recoverable Items folder for In-Place eDiscovery purposes, even if the messages were deleted by the user or another process. In Exchange Server and Exchange Online, MRM is accomplished through the use of retention tags and retention policies. Assigning retention policy tags (RPTs) to default folders, such as the Inbox and Deleted Items. Applying default policy tags (DPTs) to mailboxes to manage the retention of all untagged items. Allowing the user to assign personal tags to custom folders and individual items. Messaging Record Management policy itself doesn’t perform any retention. You need to use a time-based In-Place Hold or Litigation Hold to preserves messages that were deleted for long period of time than the Single Item Recovery period. In this post, we will be referring Messaging Records Management (MRM) as EAC based Retention. For more details, refer Messaging records Management Next, we will answer some of the frequently asked questions around Retention Policies in the SCC and EAC. Deletion and Retention options for Retention. What do they really do? While creating Unified Retention policy or Retention Labels, the settings below, may not be as clear for some customers. Let’s take a deeper look: Option: “Yes, I want to retain” This option means retain content in user’s mailbox (mail folders and Recoverable Items folder) wherever they are located for specified x days/months/years. You also get an option to retain them forever. This setting also applies to content in folders in archive mailbox and its Recoverable items folders. Content deleted from user’s mail folders will be moved to Recoverable items folder and content which is already existing in Recoverable items folder (when policy is applied), will be retained for x days/months/years. In short retention will make sure that the content will not be purged completely from the mailbox for specified number of days/months/years What happens to content when the retention period for emails is expired? It depends on what’ option is selected next; “Do you want us to delete it after this time?” If “Yes” is selected, MFA does the job of cleaning the expired contents from user’s mail folders and from the Recoverable items folders. This also includes expired content in archive mailbox and its recoverable items folders. If “No” is selected, Managed Folder Assistant (MFA) will not clean the expired content (move to recoverable items folder) which exists in user’s mailbox folders. But the expired content in Recoverable items folder older than Single Item recovery period (14 days) will be cleaned, provided there is no other hold applied to this mailbox to retain the content longer. To identify other holds on the mailbox, refer How to identify the type of hold placed on an Exchange Online mailbox. Option: “No just delete content that’s older than” This option indicates delete content in user’s mailbox (users’ mail folders and Recoverable Items folder) which is older than configured x days/months/years, wherever it is located. This also includes content in folders in the archive mailbox and its Recoverable items folder. With this option selected, expired content from user's mail folders and Recoverable items will be deleted permanently (provided that there is no other hold configured to retain content for longer period.) For more details refer Deleting content that's older than a specific age Let’s discuss some of the common scenarios. Retain and Delete content in the entire mailbox. If you are planning to use Unified Retention and your requirement is that the mailbox should not hold any content older than 1 year. You can create a SCC Retention as shown below so that any data which is older than 1 year would be deleted from the user's mail folders and Recoverable items folders. This option makes sure than there is no content in the mailbox older than 1 year, both in users mail folder and Recoverable items folder, this also includes content in archive mailbox. The expired content is not immediately purged from the mailbox instead it is retained for some more days, it could be because other holds and because of DelayHoldApplied on the mailbox. Retain the deleted content for a longer period. If you are planning to use SCC Retention and your requirement is that the content from user's mail folders older than 1 years needs to be deleted and the deleted content need to be retained for 7 years for eDiscovery or recovery. One of the ways to achieved this is by creating two SCC Retention policies One policy to delete email older than 1 year: Another policy to retain data for 7 years: How is the retention period specified calculated? The retention period calculation for different types of items varies and is documented in below article. For more details How retention age is calculated Above article applies both the EAC based retention and SCC Retention Principles of retention. A mailbox can have multiple Unified Retention or Retention Labels policies applied either implicitly or explicitly. At times in order to meet your compliance requirement, a given mailbox can be subjected to multiple policies, in such cases it’s important to understand which action take precedence, which is explained nicely using “Principles of retention” For more detail on “Principles of retention” refer Overview of retention policies Should I use the EAC based retention or SCC Retention? It really depends on your retention requirements. With introduction of auto-expanding archive feature, it is important that you move your old emails from primary mailbox to archive mailbox this includes emails from the user’s folders and Recoverable Items folder of primary mailbox, so that Primary mailbox doesn’t exceed the mailbox quota limits. For auto-expanding archiving feature refer Auto-expanding archiving feature Automate moving emails to the archive. What if you want to automate moving emails older than 2 years from primary to archive, the only option to do this currently is using Default Policy tag or Personal tag in MRM 2.0 as these are the only retention tags which support move to archive action. SCC Retention or even Retention Labels doesn’t provide us the same option of moving emails to archive mailbox. So, in this case EAC based retention is the only option (currently). This is probably the only advantage of using EAC based retention. Does it mean that I can apply EAC based retention and SCC Retention to the same mailbox? Yes, You can. It's important note that a given mailbox can have only one EAC based retention with multiple tags and at the same mailbox can have multiple SCC Retention policies and Retention labels policies. I would recommend using EAC based retention to meet your archiving (mailbox) needs and SCC retention for your retention needs. But what about emails in the Recoverable Items folder in Primary mailbox? As Recoverable items has its own quota, in order to prevent it from being full, you can opt to archive emails from your primary mailbox’s recoverable items to archive mailbox’s recoverable items. There is a special tag called “Recoverable Items tag” in EAC based retention which only support the move to archive action can move emails from Recoverable items folder of Primary mailbox to Recoverable items folder of Archive mailbox. So, if you are planning to use EAC based retention for archiving purpose and SCC retention to meet your retention needs, your sample policies should look as below. With above EAC based retention policy in place, emails (as well as other items) older than 180 days in users mail folders will be moved to archive mailbox, at the same time deleted content in Recoverable items of Primary mailbox will be moved to Recoverable items of archive mailbox after 14 days. Also, when you are planning to use SCC retention along with EAC based retention policy it is important to understand how precedence works in EAC based retention like; Default Policy tag (DPT) with move to Archive action always overwrites the Retention Policy tag (RPT) or the Personal tag (PT), when the age limit for retention of DPT is lower than of RPT or PT. Explicitly assign tag wins over an implicit tag It’s important to plan your policies & test the policies on test mailboxes to understand the behavior. Organizations share a common goal of having consistent approach to categorize, classify important content from its creation, retention and disposal. In achieving this goal it's critical that administrators and Information Management teams carefully plan and test their data governance strategy. Hope this post helps. Big Thanks to Linda Harrell (Supportability PM - Information Protection) & Bhalchandra Atre (Supportability PM - Exchange) for reviewing this post. Vikas Soundade52KViews3likes15Comments