Nhsmail Office 365 Hybrid Service Configuration Guide
Total Page:16
File Type:pdf, Size:1020Kb
NHSmail Office 365 Hybrid Service Configuration Guide May 2019 Version 1 Copyright © 2019 NHS Digital NHSmail Office 365 Hybrid Service Configuration Guide Contents 1 Introduction 5 1.1 Target audience 5 1.2 Service background 5 2 Scope 5 2.1 Licences and applications 5 2.2 Service support 6 3 Onboarding 7 3.1 Joining the service 7 3.2 Leaver / joiner process 8 3.3 Licensing procurement 9 3.4 Transferring existing licences 9 3.5 Data migration from an existing O365 tenant 9 3.6 Microsoft FastTrack services 10 3.7 Ending NHSmail O365 Hybrid services 10 3.8 Technical pre-requisites 11 4 Application service information 12 4.1 Supported application summary 12 4.2 Azure Active Directory 13 4.3 SharePoint Online 15 4.4 OneDrive for Business 20 4.5 Microsoft Teams 21 4.6 Yammer enterprise 24 4.7 StaffHub 26 4.8 PowerBI 27 4.9 Delve 28 4.10 Planner 29 4.11 Office Online 29 4.12 Microsoft Forms 30 4.13 Sway 30 4.14 Office 365 Groups 31 4.15 Microsoft PowerApps 32 4.16 Microsoft Flow 32 4.17 Microsoft Stream 33 Copyright © 2019 NHS Digital 2 NHSmail Office 365 Hybrid Service Configuration Guide 4.18 Microsoft Project Online 34 4.19 Microsoft Visio Online 34 4.20 Mobile applications 35 5 Azure B2B Guest Access 36 5.1 Domain Name Whitelisting 36 5.2 Guest User Invites 37 5.3 Azure Federated Group Import 38 5.4 Lifecycle Management 38 5.5 External sharing breakdown by application 40 6 Tenant Policy 41 6.1 Vanity domains 41 6.2 Office 365 release cycle policy 41 6.3 Third party applications 41 6.4 Tenant branding 41 6.5 Office 365 desktop applications 42 7 Compliance 43 7.1 Data Residency 43 7.2 Data retention and recovery 43 7.3 Label Policy 52 7.4 Data Loss Prevention 52 7.5 eDiscovery 55 7.6 General Data Protection Regulation (GDPR) 55 8 Reporting 56 8.1 Licence reports 56 8.2 Storage reports 56 8.3 Azure B2B reports 56 8.4 Other reports 56 8.5 Service health 56 9 Local organisation responsibilities 57 9.1 Local software and hardware 57 9.2 Local network and infrastructure 57 9.3 Adoption and training 57 9.4 Licence procurement 57 10 Un-supported services 58 Copyright © 2019 NHS Digital 3 NHSmail Office 365 Hybrid Service Configuration Guide 11 Clinical Safety and Acceptable Use Policy 59 11.1 Clinical safety 59 11.2 Acceptable Use Policy 59 11.3 More information 59 12 NHSmail helpdesk 60 Copyright © 2019 NHS Digital 4 NHSmail Office 365 Hybrid Service Configuration Guide 1 Introduction 1.1 Target audience This document provides an outline for IT Managers and Local Administrators (LAs) of the NHSmail Office 365 Hybrid Service configuration for NHSmail. Service configuration guides for other services will be available at the point of release. 1.2 Service background The NHSmail service is the national secure collaboration service for health and care in England and Scotland and is currently used by over 1.5 million users and continues to grow. To enable greater access to collaboration applications, the NHSmail service is now integrated with Microsoft Azure Active Directory (Azure AD) and Microsoft Office 365 (O365). Azure AD is a cloud-based directory that enables secure, cloud-based identity management for the NHSmail service. O365 is a subscription-based cloud productivity suite that includes services such as OneDrive for Business, SharePoint Online and Yammer. The NHSmail service has been integrated with a dedicated Office 365 tenant for users across England. NHS organisations will be able to access the O365 services in a ‘bring your own licence’ model. Users provisioned with licences will access the NHSmail Office 365 Hybrid Service using their existing NHSmail username and password. The NHSmail Portal has been developed to enable organisations to subscribe and manage their Office 365 licences. This includes, but is not limited to, the ability to assign licences, enable applications and create SharePoint sites. Organisations consuming Office 365 services via the NHSmail Office 365 Hybrid Service will need to use NHSmail as their primary email service. This document outlines the key functional and configuration details for each of the new services for NHS organisation administrators and IT managers. Note: The NHSmail Office 365 Hybrid Service is currently not available for users in Scotland. 2 Scope 2.1 Licences and applications Office 365 licences must be procured by NHS organisations directly from Microsoft or their Licence Reseller and will not be available to procure nationally through the NHSmail service. Organisations are not required to procure Azure AD licences to consume the O365 service. The following enterprise and standalone licence types are supported on the NHSmail Office 365 Hybrid Service: Office 365 Enterprise F1 Office 365 Enterprise E1 Office 365 Enterprise E3 Office 365 Enterprise E5 Copyright © 2019 NHS Digital 5 NHSmail Office 365 Hybrid Service Configuration Guide Microsoft PowerApps Plan 1 Microsoft PowerApps Plan 2 Microsoft Flow Plan 1 Microsoft Flow Plan 2 Microsoft Stream Plan 1 Microsoft Stream Plan 2 Microsoft Visio Plan 1 Microsoft Visio Plan 2 Power BI (Free) Power BI Pro Power BI Premium Microsoft Project Online Essential Microsoft Project Online Professional Microsoft Project Online Premium Details of the applications supported within these licence types can be found in the Application Service Information section of this document. Organisations will be required to raise a service request with the NHSmail helpdesk to onboard their licences to the NHSmail Office 365 Hybrid Service. Further information is available on onboarding within this document. The commercial relationship for provision of O365 services is between the NHS organisations and Microsoft via their licence agreement. The NHSmail service is providing access and integration management of the NHSmail O365 tenant. The NHSmail service is not responsible for the Microsoft cloud infrastructure and Office 365 application service levels. 2.2 Service support Helpdesk support for the NHSmail O365 Hybrid Service will be provided by the existing NHSmail helpdesk. Local organisations are expected to provide initial triage and troubleshooting support to their end users as per the existing NHSmail service. LAs will be able to raise tickets with the NHSmail helpdesk for faults relating to configuration within the NHSmail Office 365 tenant. Faults relating to Microsoft infrastructure and product issues will be raised directly with Microsoft. Organisations wishing to use their Microsoft Premier Support should raise cases directly with Microsoft via the standard Premier Support channels. Where these cases require support from the NHSmail service, a ticket should be raised with the NHSmail helpdesk by the local organisation. The NHSmail service does not support submission of Microsoft Premier Support cases centrally on behalf of NHS organisations. Further information is available in this document on local organisation responsibilities. Copyright © 2019 NHS Digital 6 NHSmail Office 365 Hybrid Service Configuration Guide 3 Onboarding 3.1 Joining the service To join the NHSmail Office 365 Hybrid Service, users must have an existing NHSmail account and be using NHSmail as their primary email service. The process for joining the NHSmail Office 365 Hybrid Service can be broken down into four stages. 1. Procure Office 365 licences 2. Submit licences to NHSmail via the NHSmail helpdesk 3. Allocate licences to users within the NHSmail Portal 4. Enable users as guest inviters (optional) Step 1: Procure O365 licences Local organisations should procure Office 365 licences directly from Microsoft or their Licence Reseller who will issue the organisation with an email confirmation of their purchase. Licensing is not available centrally via the NHSmail service. More information is available in this document on licensing procurement. Step 2: Submit licences to NHSmail Once your organisation has procured O365 licences you will receive an email from your Licence Reseller confirming the purchase. At this point your organisation’s LA should raise a service request with the NHSmail helpdesk where details of your subscription can be shared and the process for tenant allocation started. Details required in this request can be found in the Onboarding Guide for Local Administrators. Once an onboarding service request has been raised, the NHSmail team will allocate your licences to the O365 tenant and make them visible in the self-service NHSmail Portal. Once this process is complete, licences will be available to manage and allocate by LAs through the NHSmail Portal. Your licences will be securely held and managed in the central NHSmail O365 tenant until their expiry. Note: Licences and their submission will be managed and serviced on a per organisation basis and cannot be split across multiple organisations. Step 3: Allocate licences to users by creating user policies Once step 2 is completed, the organisation LAs will be able to log into the NHSmail Portal and navigate to the administration area for enabling services. Detailed guidance on how to create licence profiles and enable O365 services for users is available in the Hybrid Local Administrator guide. Step 4: Enable users as guest inviters (optional) Organisation LAs will be able to decide whether they would like to enable their NHSmail users as guest inviters so that they can collaborate with users from external organisations. They can configure NHSmail users as eligible guest inviters via the NHSmail Portal. Detailed guidance on this is available in the Hybrid Local Administrator guide. Copyright © 2019 NHS Digital 7 NHSmail Office 365 Hybrid Service Configuration Guide 3.2 Leaver / joiner process The NHSmail service has a defined process for account leavers / joiners. NHSmail accounts marked as ‘leavers’, that have an NHSmail O365 Hybrid licence assigned, require some additional steps to remove the O365 licence and define retention actions for organisation-owned content stored in the account’s OneDrive.