Friday, 20 April 2018

Utilising App ID to find apps in the Intune Portal faster


Just a quick one this Friday afternoon from me. Ever been in the Intune portal and getting frustrated at finding the correct App from the returned results? Well just use the App ID instead.

Find the app in the actual app store.


Take note of the App ID


Use the App ID to search within Intune



Et voila! You'll find that not so well known app much faster.


Have fun,

@OliverMoazzezi

Branding Azure Information Protection OME with your Company Logo

Microsoft recently release Office 365 Message Encryption v2, overhauled on Azure Information Protection rather than Azure Rights Management.

The solution, like it's predecessor, allows you to encrypt messages and have them encapsulated in the browser when being sent to recipients. The likely scenario for this is external recipients, and you can enforce encryption on specific domains, to specific people, or allow users to specify when to encrypt a message by, as an example, putting the word 'encrypt' into the subject line.

Exchange Online through the browser using Outlook on the Web/Outlook Web App and an updated version of Outlook 2016 allows recipients to decrypt these messages on the fly, as such does the Outlook.com web browser experience. (note Outlook version support requires 2016 as is being rolled out).





However the majority of users on other services will recieve the following.



The user will then have to authenticate with their username and password if they're on a supported platform such as gmail (where Microsoft is using gmail as an authentication provider), or the user will have to opt for a One Time Code (OTP). This is basically the same experience as Office 365 Message Encryption v1 offered. All well and good so far.

I was keen to see if you could still brand the OME experience, and I am pleased to say you can.


First, fire up a session to Exchange Online in PowerShell, then let's view the OME configuration using Get-OMEConfiguration



Next, let's upload a logo and see if OME continues to honour it even through we're utilising AIP.

Set-OMEConfiguration -Identity "OME Configuration" -Image (Get-Content c:\yourimage.png -encoding byte)


Finally let's check the image has been uploaded with Get-OMEConfiguration

You can see the image is uploaded to blob storage in Azure - but specifically mentions OMEv2 branding with the url e4eomev2branding.blob.core.windows.net


So to users that cannot auto decrypt OME encrypted emails, is the OME experience now branded? It is!


On another note, it's nice to point out you can also add disclaimer and additional text using these commands.

Set-OMEConfiguration -Identity "OME Configuration" -DisclaimerText "Your Text Here"

Set-OMEConfiguration -Identity "OME configuration" -PortalText "Your Text Here"


And don't forget, with AIP integrated you can use 'encrypt' via the 'Protect' button to auto encrypt emails rather than creating an OMEv2 Transport Rule for encryption self service or recipient or domain enforcement processes




Have fun!


@OliverMoazzezi






Tuesday, 20 March 2018

Help! My imported Visio stencils are blue!

Just a quick one. But I know this annoys everyone that it happens to!


You download some visio stencils to 'My shapes' go to use them, and then they are blue. Very frustrating.


To resolve the issue, go to Design | Themes and specify the 'no theme' setting. And voila.


This post will no doubt be archived by the internet search engines soon so it will hopefully make everyones life a lot easier.



Take care,

@OliverMoazzezi

Monday, 12 March 2018

Changing phones when using the Microsoft Authenticator app for Azure MFA in Office 365

Hi all,

I've had a busy beginning start of 2018 moving customers to Office 365 and have had a few blog posts and blog post ideas queueing up on me for a while now. So, here's the first post for March.

How does one change their Azure MFA settings once you an administrator has forced you to enroll and you're now a year in and you're changing your mobile phone?

Good question! It's not discussed on any kb article or Microsoft blog post. So if you need to change your device or even your 2nd factor type, for example from text or phone to the App, then follow this process.

1. Login to Office 365 and go to 'My Account'


2. Go to 'Security and Privacy'


3. Select 'Update your phone numbers used for account security'. Now it will ask you to go through multi factor authentication at this stage. So if you have lost your device then contact IT support to help resolve your issue (their solution will be that they will make you re-enroll).


4. Select 'Configure' and setup the Microsoft Authenticator app on your new phone by either using the QR code or the manual url.



5. You can of course change your 2nd factor type by changing your preferred option. Note that you will only be able to select what your IT Administration team has made available to you.




And that's it. If you don't want the cumbersome process of going all the way through to the 'My Accounts' page you can also use this link: https://aka.ms/MFASetup


Take care,


@OliverMoazzezi







Monday, 4 December 2017

Microsoft Teams gets Usage Reports

Just a quick update from me as we start this week. Microsoft has added two usage reports for Microsoft Teams. User Activity and Device Usage reporting.

Log into the Admin Portal and select Reports | Usage | Microsoft Teams


We can expect to see more in the coming days and weeks as the transition from Skype for Business to Microsoft Teams continues.


Have fun

Oliver Moazzezi
@OliverMoazzezi














Thursday, 23 November 2017

An error occurred while attempting to provision Exchange to the Partner STS 'Client found response content type of 'text/html; charset=utf-8', but expected 'text/xml'

This week I had a very interesting Exchange Hybrid Wizard error present itself that I haven't seen before, or at least seen the root cause before. The purpose of this post is to actually have some data on it searchable on the internet so if you are facing this issue you know what to expect and do.

The error is: "An error occurred while attempting to provision Exchange to the Partner STS.  Detailed Information "An error occurred accessing Windows Live. Detailed information: "Client found response content type of 'text/html; charset=utf-8', but expected 'text/xml'"

This error never presents itself in the HCW, infact once you have added your TXT records to your required domains, the HCW will just hang at 'adding Federated Domain...' and sit on this screen forever:


You'll wait and wait and wait, and nothing will ever happen. This is when you hopefully dig into the HCW log and get dig through it to find the cause. Now I have had this happen before, and we know we have to look to the HCW log to see what's going on. However the issue wasn't what I was expecting.

In my case the error was caused because the web service that allows the HCW to provision the domains onto the Microsoft Federation Gateway had failed, and was returning a 500 error. This is why the HCW log was complaining it was expecting an html xml response but instead was getting an html response with text.

So if you recieve this error what can you do to check that it's Microsoft's issue and not yours?

It's a good idea if you're getting any "An error occurred while attempting to provision Exchange to the Partner STS" to check https://domains.live.com/service/managedelegation2.asmx


When working it will give you the following


In my instance, with the HCW stalled it was due to Microsoft actually having a service health issue.

It's good to point out that if you're getting other "An error occurred while attempting to provision Exchange to the Partner STS" errors to still check the web service. You may find you have a proxy or firewall in the way causing issues between the HCW and the functioning web service. Compare https://domains.live.com/service/managedelegation2.asmx from another network that you know won't have proxy or firewall issues or even check it on your phone via 4G.

On another note I have reached out to the Exchange Product Group as I think Office 365 Service Health should be reporting on STS services as they will have potential impacts with enabling Exchange Hybrid and federation capabilities.

Take care,


Oliver Moazzezi
@OliverMoazzezi




Friday, 10 November 2017

Managing gifs in Microsoft Teams


Microsoft Teams is turning out to be a great product. It's unifying a lot of Office 365 services in the solution stack to make the app a pretty much once stop place for getting work done, communicating and enabling productivity. However you may find you get a gif explosion in Microsoft Teams as users find, love and consume the service.

Well whilst we are still awaiting the Skype for Business and Microsoft Teams unified Admin Center that was announced and shown at Ignite we do have some administative functionality over Microsoft Teams.

Let's take a look how we can disable Giphy, or apply content rating to the gifs that are available to users to minimise inappropriate use.


  1. Login to Office 365 and browse to the Admin centre. Looking at your respective Admin Centers you won't yet find Microsoft Teams there
Inline image OWAPstImg64754

2. Instead, go to Settings | Services and Add-ins. Here you will find Microsoft Teams!
Inline image OWAPstImg133817


3.  Selecting it will show various administrative functions we can currently do - however expand 'Messaging' to see where Giphy is. You will see it can be enabled and disabled and also content ratings applied

Inline image OWAPstImg653915

4.  The current content rating filter allows Moderate (the default setting), Strict and Show all content.
Inline image OWAPstImg916347

5.  So what is the experience if you want to disable gifs? Disable the function and save.
Inline image OWAPstImg475043

6. Within a short amount of time, users cannot insert gifs or see Giphy anymore. Old gif insertions continue to function
Inline image OWAPstImg716493

I look forward to seeing the combined Skype for Business and Teams Admin Center that's due out at the end of the year - possibly in public preview rather than GA - it should be good! Here's a preview from TechCommunity
Inline image OWAPstImg292571

Take care,



Oliver Moazzezi
@OliverMoazzezi