ImaginAb - M365 General Configuration
Section titled “ImaginAb - M365 General Configuration”The purpose of this KB is to explain the general setup and configuration for ImaginAb’s M365 Subscription. We will step through the main columns in the admin portal and explain what is set up and configured.
Active Users
Section titled “Active Users”All active users are cloud-only accounts. There is no local active directory sync.
Global Admin Account
Section titled “Global Admin Account”The admin account to access the M365 subscription is centrexit@imaginab.com. Credentials can be found in pwstate.
Devices
Section titled “Devices”As of this writing, there are 35 devices managed by M365. There are no autopilot devices or autopilot profiles. The Intune configuration will be covered in greater detail in later sections.
Teams & Groups
Section titled “Teams & Groups”There are 23 active M365 groups/teams.
Security Groups - DUO Users - members of this group are bound to the DUO policy.
Nothing out of the ordinary here.
Resources
Section titled “Resources”Nothing in here.
Billing
Section titled “Billing”Products
Section titled “Products”Most active users are on M365 E3. There are about 10 Exchange Online E1 (email only) plans. There are also M365 Audio Conferencing, and Microsoft Defender for O365 P1 plans in the subscription. See Screenshot:
Licenses are on month to month renewal, and purchase channel is through reseller (as of this writing it is Synnex, but once onboarding is complete it will be through Pax8).
M365 E3 Licenses
Section titled “M365 E3 Licenses”All active users will get this license to access M365 office suite, email, sharepoint, onedrive, etc.
Exchange Online (Plan 1)
Section titled “Exchange Online (Plan 1)”These licenses are used for mailbox-only accounts.
M365 Apps for Business
Section titled “M365 Apps for Business”This license is used to access the M365 Office Apps. No email, endpoint manager, etc. Just apps. Currently, these licenses are used for the laboratory equipment.
M365 Audio Conferencing
Section titled “M365 Audio Conferencing”This license is used to provide audio conferencing features in Teams meetings. Audio Conferencing in Microsoft 365 and Office 365 enables users to call in to meetings from their phones. Audio Conferencing allows up to 1000 phone attendees.
Microsoft Defender for Office 365 (Plan 1)
Section titled “Microsoft Defender for Office 365 (Plan 1)”This license is used to provide advanced security features on top of E3 license features - Protects email and collaboration from zero-day malware, phish, and business email compromise.
Office 365 E1
Section titled “Office 365 E1”This license is used to provide web-based access to office365 apps to these users:
Windows 365 Business 2 vCPU, 8 GB, 128 GB (with Windows Hybrid Benefit)
Section titled “Windows 365 Business 2 vCPU, 8 GB, 128 GB (with Windows Hybrid Benefit)”This license is a Windows OS license - more info to come. Looks like they have a M365 Cloud PC for the following users:
Project Plan 3
Section titled “Project Plan 3”This license provide access to Microsoft Project.
Domains
Section titled “Domains”Primary domain is imaginab.com
M365 back-end domain is imaginab.onmicrosoft.com
DNS Records:
There is no third-party Email Gateway.
Security & Privacy
Section titled “Security & Privacy”Password Expiration Policy
Section titled “Password Expiration Policy”365 days before passwords expire.
Partner Relationship
Section titled “Partner Relationship”This is the current partner relationship as of onboarding 7/19/2022. Pax8 needs to be added as a reseller, and centrexIT as an indirect reseller/advisor. NR and Synnex365 needs to be removed. DFC and ingram micro possibly removed as well.
Microsoft Endpoint Manager Admin Center
Section titled “Microsoft Endpoint Manager Admin Center”Only Windows Devices. There are no Android, iOS, or macOS devices.
No compliance policies.
Configuration Profile
Section titled “Configuration Profile”Automatic Lock Screen for Inactive Device. This profile configures devices to lock after 15 minutes of inactivity. It is applied to all devices.
Condition Access Policy
Section titled “Condition Access Policy”Require Duo MFA - Policy is applied to the DUO Users security group, and requires DUO MFA on all Office365 apps.