Yous is a fairly common complaint in the forum.
It appears that MS has a very specific view of how it wants people to use Office. Unfortunately the "new and improved" model they designed for businesses so so different from the previous model that no-one has figured out how to use it. Obviously, MS has failed
to educate the world on how it expects them to work (hey, don't shoot the messenger...).
Here is what I've been able to mine from various sources and piece together (the puzzle is still incomplete)
How does a company install and control licenses - Business
Using Click to Run virtualization, the process of getting new users running has substantially changed. Because CTR installations are so fast, you no longer have to pre-install the software for users.
A business IT Admin controls use of corporate Office 365 licenses through the
Office 365 Administration Center online (aka
"Office 365 Administration Portal")
Overview:
- In the Office 365 Administration Center the designated Office Administrator sets up the new USER ID
- Setup the associated email account(s)
- Setup Office licenses allowed to the userid
- the new User logs in to their new computer
- in Internet Explorer the user goes to the “Office 365 Portal” site to get their allowed Office 365 installation
- using the Click to Run installation process, Office 365 is installed and running on a new computer is a matter of minutes.
The following links will provide you with more detailed information of where to look and what to do. You may require some additional support from an “expert” .
Free MS training for Office 365 Administration Center / Portal
http://office365support.ca/does-microsoft-have-free-training-for-the-new-office-365/
Excellent resource to get you started administering your business Office 365 licenses.
The first video, Exploring the Office 365 Administration Center
http://labs.officeignite.com/Guides/Exploring%20the%20Office%20365%20Administration%20Center.htm
(9:32), describes how to create new userids, and to assign Office licenses to them. It also very quickly breezes by how to install Office.
The second vidow, Office 365 Overview for IT Administrators http://labs.officeignite.com/Guides/Office%20365%20Overview%20for%20IT%20Administrators.htm
(14:00), quickly walks you through setting up new company and users.
On basic setup page, step 3 “Set up User Access” provides links to instructions on how to set up new users.
In Service Settings, Downloads, you can control what Office apps the user can download.
Creating Users for the NEW Office 365
http://office365support.ca/creating-cloud-users-for-the-new-office-365/
This page provides more detailed instructions for setting up the new userids and granting them Office 365 licenses
Configuring Desktops for the NEW Office 365
http://office365support.ca/configuring-desktops-for-the-new-office-365/
The following post will document how to setup a Windows 8 desktop for a cloud user for Office 365. I have already installed Windows 8 and created the local account for my test
user. I have logged into the Office 365 portal and had the user change his password. The password for Office 365 and the password for the desktop are the same.
Office 365 for enterprises: A tour for administrators
http://office.microsoft.com/en-us/videos/office-365-for-enterprises-a-tour-for-administrators-HA102654955.aspx
Office 365 for enterprises brings together the online services your business needs. To see how to set up and manage these services, watch these four short videos.
Where did My MSI go - Deployment Video
http://www.microsoft.com/resources/technet/en-us/office/media/video/video.html?cid=otc&from=mscomoffice&VideoID=670e3969-0509-4d3a-a8a6-ffbe526d3e6f&src=v5:endslate:related^play:related\_0&from=shareembed-syndication
10 minute comparison of MSI and CTR
Touches on corporate provisioning in”User Based License Model Activation”. Users activate/deactivate, but IT still has control to deprovision the license (starting at about minute 8:15).
Then in this video / article :
http://blogs.technet.com/b/office\_resource\_kit/archive/2013/03/20/the-new-office-garage-series-identity-activation-data-access.aspx
They again say the companies can still allow userid activation while maintaining control of the licenses through Active Directory
<snip>
Jeremy: So we showed the installation experience for a domain-joined computer where single sign on is enabled and one that is not domain-joined, but installs via the Office 365 portal. In the direct from portal case when
you kick off the installation, you will see a file that looks something like this:
Setup.X86.en-us_O365ProPlusRetail_24*****-45a2-4eeb-b06f-b14****189c8_TX_PR_.exe
In a future episode we'll talk about all of the configurations needed to suppress completely sign-in, first run experiences and user prompts. IT admins have had to deal with these in past releases of Office, but now there are
ways to automatically sign users in to Office 365 installs picking up their domain credentials. I also showed the effects of deleting the user account from the Azure AD store and how it put Yoni's Office into Reduced Functionality Mode (RFM) - even if Yoni
installs Office on his personal devices using his organization's Office software assets, once Yoni leaves the org the IT department can deprovision his personal installs. That keeps software asset management cleaner and IT is in control.
Yoni: Don't forget we also had Mark Russinovich on the show and he explained the security model for online services with Azure AD - in your car. It sounds like they are taking the defense in depth approach to harden the
service. And you made him slum it in your car, Jeremy.
</snip>
Overview of ID, Authentication and Authorization in Office 2013
<snip http://blogs.technet.com/b/office\_resource\_kit/archive/2013/04/16/new-poster-and-content-roadmaps-about-office-identity-authentication-authorization-and-security.aspx
>
This page has links to 3 posters. The first poster “Identity and Authentication in the Cloud: Office 2013 and Office 365” describes at a high level how to control new user setup in a corporate / small business environment.
</snip>
<snip http://technet.microsoft.com/en-us/library/jj683102.aspx
>
This page also has a link to the same poster online (http://www.microsoft.com/en-us/download/details.aspx?id=38193 has PDF and Visio versions
of the chart). As well, it goes into more detail with information like the following:
… Because Office is a tool that is used by the same individual in two different roles, the new Office offers two identities with which users can log on to Office 2013:
- A Microsoft account, which most people use for personal business
- An organization ID that is assigned by Microsoft, which most people use when doing work for an organization, such as a business, charity, or school.
The credentials that are used to sign in are recognized as either personal or organizational. That sign-in identity becomes the user's “home realm” and determines which documents the user has access to on SharePoint, SkyDrive,
or Office 365 Services for a specific session. Each unique sign in identity is saved in a most-recently used list so that it is easy to switch between identities without leaving the Office experience.
….
a personal SkyDrive can be mounted to an organization identity so that personal documents can be accessed at work or school without ever switching identities. Also, when a user authenticates by using an identity, this authentication
is valid for all Office applications, not just the application he or she signed in to.
….
Two logon types are supported when users sign in to Office 2013, a Microsoft account or an organization ID that is assigned by Microsoft.
Microsoft account (the user’s individual account). This account, formerly known as Windows Live ID, is the credential that users use to authenticate with the Microsoft network and is frequently used for personal or non-business work, such as volunteer work.
To create a Microsoft account, a user provides a user name and password, certain demographic information, and “account proofs,” such as an alternative email address or phone number. For more information about the new Microsoft account, see
What is a Microsoft account?. http://go.microsoft.com/fwlink/p/?LinkId=268357
An organization ID that is assigned by Microsoft / Office 365 account ID that is assigned by Microsoft. This account is created for business use. An Office 365 account can be one of three types: a pure Office 365 ID, an Active Directory ID, or an Active
Directory Federation Services ID. These are described below:
·
Office 365 ID. This ID is created when an admin sets up an Office 365 domain and takes the form <user>@<org>.onmicrosoft.com, for example:
sally@contoso.onmicrosoft.com
·
Organization ID that is assigned by Microsoft that is validated against a user's Active Directory ID. An organization ID that is assigned by Microsoft and validated against Active Directory as follows:
1.
First, a person who has an [on-premise domain]<user> account attempts to access organization resources.
2.
Next, the resource requests authentication from the user.
3.
Then, the user types in their organization user name and password.
4.
Finally, that user name and password are validated against the organization AD database, the user is authenticated, and is given access to the requested resource.
·
An organization ID that is assigned by Microsoft that is validated against a user’s Active Directory Federation Services ID. An organization ID that is assigned by Microsoft and validated against Active Directory Federation Services (ADFS)
as follows:
1.
First, one person who has an org.onmicrosoft.com attempts to access
partner organization resources.
2.
Then, the resource requests authentication from the user.
3.
Next, the user types in their organization user name and password.
4.
Then, that user name and password are validated against the organization AD database.
5.
Finally, that same user name and password are passed to the partner’s federated AD database, the user is authenticated, and is given access to the requested resource.
For on-premises resources, Office 2013 uses the domain\alias user name for authentication. For federated resources, Office 2013 uses the alias@org.onmicrosoft.com user name for authentication.
</snip>
Office 365 Administration / Office 365 Administration Center / Office 365 Portal
http://technet.microsoft.com/en-us/library/jj819272.aspx
This page summarized methods of administering Office 365
User Account Management
http://technet.microsoft.com/en-us/library/jj819300.aspx
Sign-in for Small Business subscriptions
Users receive Windows Azure Active Directory cloud credentials—separate from other desktop or corporate credentials—for signing into Office 365 and other Microsoft cloud services.
Sign-in options for Enterprise, Midsize Business, Kiosk, Academic, and Government subscriptions
Office 365 for Enterprise, Midsize Business, Kiosk, Academic, and Government subscriptions has two systems that can be used for user identities:
- Organizational account (cloud identity) Users receive Windows Azure Active Directory cloud credentials—separate from other desktop or corporate credentials—for signing into Office 365 and other Microsoft cloud services. This
is the default identity, and is recommended for small and midsize businesses in order to minimize deployment complexity. Passwords for organizational accounts use the Windows Azure Active Directory
password policy.
- Federated account (federated identity) For all subscriptions other than Office 365 Small Business and Office 365 Small Business Premium, in organizations with on-premises Active Directory that use single sign-on (SSO), users
can sign into Office 365 services by using their Active Directory credentials. The corporate Active Directory stores and controls the password policy. For information about SSO, see
Single sign-on roadmap.
The type of identity affects the user experience and user account management options, as well as hardware and software requirements and other deployment considerations.
Custom domains and identity options
When you create a new user, the user’s sign-in name and email address are assigned to the default domain as set in the Office 365 admin center. By default, the Office 365 subscription uses the <company name>.**onmicrosoft.com**
domain that was created with the Office 365 account. You can add one or more custom domains to Office 365 rather than retaining the
onmicrosoft.com domain, and can assign users to sign in with any of the validated domains. Each user’s assigned domain is the email address that will appear on sent and received email messages.
You can host up to 600 registered Internet domains in Office 365, each represented by a different namespace.
For organizations using single sign-on, all users on a domain must use the same identity system: either cloud identity or federated identity. For example, you could have one group of users that only needs a cloud identity because they don’t access on-premises
systems, and another group of users who use Office 365 and on-premises systems. You would use add two domains to Office 365, such as
contractors.contoso.com and
staff.contoso.com, and only set up SSO for one of them. An entire domain can be converted from cloud identity to federated identity, or from federated identity to cloud identity.
For more information about domains in Office 365, see the Domains service description.
Creating user accounts
Office 365 provides five ways to create user accounts, some of which are not available for Office 365 Small Business and Office 365 Small Business Premium: Add single User, Bulk upload using *.CSV files, Active Directory Synchronization,
Azure Active Directory Module for powershell, Exchange Simple Migration
Password management
The policies and procedures for password management depend on the identity system.
Cloud identity password management:
When using cloud identities, passwords are automatically generated when the account is created.
License management
A subscription to Office 365 is made up of a number of licenses to a set of services. An administrator assigns a license to each user for each service that user needs access to. For more information about managing licenses, see Assign
or remove a license in Office 365 Enterprise, http://go.microsoft.com/fwlink/p/?LinkID=270069 or
Assign or remove a license in Office 365 Small Business.
http://go.microsoft.com/fwlink/p/?LinkID=270070
Office 365 for Business FAQ
http://office.microsoft.com/en-us/business/microsoft-office-365-for-business-faq-FX103030232.aspx
Some general questions are answered