SlideShare una empresa de Scribd logo
1 de 48
Melissa Miller La Salle University Philadelphia, PA [email_address]
[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object]
 
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object]
 
[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object]
Based off of Scenario 2a from SDK Guide
 
[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object]
 
[object Object],[object Object],[object Object],[object Object],[object Object]
https://inside.lasalle.edu/cas/login?Service=www.mywebsite.com User logs into Luminis Portal  User is presented with Link
Browser sent to CAS with Service ID  CAS Returns Ticket and Cookie http://www.mywebsite.com/? ticket=ST-12-g9uDQJB0gtoOJfiycsdz https://inside.lasalle.edu/cas/login? Service=www.mywebsite.com
Browser sent to CAS enabled  Web Service with ticket  http://www.mywebsite.com/ ?ticket=ST-12-g9uDQJB0gtoOJfiycsdz https://inside.lasalle.edu/cas/validate?service=http://www.mywebsite.com& ticket=ST-12-g9uDQJB0gtoOJfiycsdz Web Service Validates Ticket External CAS Enabled Web Service
Yes ,  username User is now Authenticated into External Web Service  External CAS Enabled Web Service
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
 
Alternative to GCF/CPIP No password exchanged with External System
[object Object],[object Object]
[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
Authenticated. Now What? Microsoft's Solution (Big Picture)
[object Object],[object Object]
[object Object]
The client is redirected by the URL to the Windows Live ID Login Service with a valid SLT. The Windows Live ID Login Service issues a ticket for requested mail service .
The Windows Live Mail Service redirects the student to their mailbox. The client browser is redirected again to the Windows Live Mail Service.  https://exchangelabs.com/owa/?wa=wsignin1.0
[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object],[object Object]
[object Object],[object Object]
[object Object],[object Object],[object Object],[object Object]

Más contenido relacionado

La actualidad más candente

Claims-Based Identity in SharePoint 2010
Claims-Based Identity in SharePoint 2010Claims-Based Identity in SharePoint 2010
Claims-Based Identity in SharePoint 2010Danny Jessee
 
Ce order rma_wireframes111913v7
Ce order rma_wireframes111913v7Ce order rma_wireframes111913v7
Ce order rma_wireframes111913v7Jon Winsor
 
Thawte EV SSL: A New Revolution for Trust
Thawte EV SSL: A New Revolution for TrustThawte EV SSL: A New Revolution for Trust
Thawte EV SSL: A New Revolution for TrustRapidSSLOnline.com
 
Authorization in asp
Authorization in aspAuthorization in asp
Authorization in aspOPENLANE
 
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the CloudSharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the CloudDanny Jessee
 
How To Get Your Own Contact Management System
How To Get Your Own Contact Management SystemHow To Get Your Own Contact Management System
How To Get Your Own Contact Management SystemVal Slastnikov
 
Placement Consultants Companies Agencies List Prepared By N C
Placement Consultants Companies Agencies List Prepared By  N CPlacement Consultants Companies Agencies List Prepared By  N C
Placement Consultants Companies Agencies List Prepared By N Cncct
 
Stateless Auth using OAUTH2 & JWT
Stateless Auth using OAUTH2 & JWTStateless Auth using OAUTH2 & JWT
Stateless Auth using OAUTH2 & JWTMobiliya
 
Open Id, O Auth And Webservices
Open Id, O Auth And WebservicesOpen Id, O Auth And Webservices
Open Id, O Auth And WebservicesMyles Eftos
 
Canarie Federated Non Web Signon
Canarie Federated Non Web SignonCanarie Federated Non Web Signon
Canarie Federated Non Web SignonChris Phillips
 
Deciphering 'Claims-based Identity'
Deciphering 'Claims-based Identity'Deciphering 'Claims-based Identity'
Deciphering 'Claims-based Identity'Oliver Pfaff
 
BlackBerry Workspaces: Authentication and Identity Connectors
BlackBerry Workspaces: Authentication and Identity ConnectorsBlackBerry Workspaces: Authentication and Identity Connectors
BlackBerry Workspaces: Authentication and Identity ConnectorsBlackBerry
 
Windows Server 2008 Active Directory ADFS Claims-base Idm for Windows Part 2
Windows Server 2008 Active Directory ADFS Claims-base Idm for Windows Part 2Windows Server 2008 Active Directory ADFS Claims-base Idm for Windows Part 2
Windows Server 2008 Active Directory ADFS Claims-base Idm for Windows Part 2Tũi Wichets
 

La actualidad más candente (16)

Claims-Based Identity in SharePoint 2010
Claims-Based Identity in SharePoint 2010Claims-Based Identity in SharePoint 2010
Claims-Based Identity in SharePoint 2010
 
Ce order rma_wireframes111913v7
Ce order rma_wireframes111913v7Ce order rma_wireframes111913v7
Ce order rma_wireframes111913v7
 
Thawte EV SSL: A New Revolution for Trust
Thawte EV SSL: A New Revolution for TrustThawte EV SSL: A New Revolution for Trust
Thawte EV SSL: A New Revolution for Trust
 
Authorization in asp
Authorization in aspAuthorization in asp
Authorization in asp
 
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the CloudSharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
 
How To Get Your Own Contact Management System
How To Get Your Own Contact Management SystemHow To Get Your Own Contact Management System
How To Get Your Own Contact Management System
 
TMCnet final
TMCnet finalTMCnet final
TMCnet final
 
Placement Consultants Companies Agencies List Prepared By N C
Placement Consultants Companies Agencies List Prepared By  N CPlacement Consultants Companies Agencies List Prepared By  N C
Placement Consultants Companies Agencies List Prepared By N C
 
Feide Connect
Feide ConnectFeide Connect
Feide Connect
 
Stateless Auth using OAUTH2 & JWT
Stateless Auth using OAUTH2 & JWTStateless Auth using OAUTH2 & JWT
Stateless Auth using OAUTH2 & JWT
 
Open Id, O Auth And Webservices
Open Id, O Auth And WebservicesOpen Id, O Auth And Webservices
Open Id, O Auth And Webservices
 
Canarie Federated Non Web Signon
Canarie Federated Non Web SignonCanarie Federated Non Web Signon
Canarie Federated Non Web Signon
 
Deciphering 'Claims-based Identity'
Deciphering 'Claims-based Identity'Deciphering 'Claims-based Identity'
Deciphering 'Claims-based Identity'
 
BlackBerry Workspaces: Authentication and Identity Connectors
BlackBerry Workspaces: Authentication and Identity ConnectorsBlackBerry Workspaces: Authentication and Identity Connectors
BlackBerry Workspaces: Authentication and Identity Connectors
 
Windows Server 2008 Active Directory ADFS Claims-base Idm for Windows Part 2
Windows Server 2008 Active Directory ADFS Claims-base Idm for Windows Part 2Windows Server 2008 Active Directory ADFS Claims-base Idm for Windows Part 2
Windows Server 2008 Active Directory ADFS Claims-base Idm for Windows Part 2
 
Tags
TagsTags
Tags
 

Similar a Luminis Iv To Exchange Labs

Why Cant I Access The Portal
Why Cant I Access The PortalWhy Cant I Access The Portal
Why Cant I Access The PortalDan Usher
 
Introduction to the Windows Live Platform
Introduction to the Windows Live PlatformIntroduction to the Windows Live Platform
Introduction to the Windows Live PlatformClint Edmonson
 
TugaIT 2017 Office 365 Multi-factor authentication with Microsoft Azure Activ...
TugaIT 2017 Office 365 Multi-factor authentication with Microsoft Azure Activ...TugaIT 2017 Office 365 Multi-factor authentication with Microsoft Azure Activ...
TugaIT 2017 Office 365 Multi-factor authentication with Microsoft Azure Activ...Nuno Árias Silva
 
The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)Jay Simcox
 
DD109 Claims Based AuthN in SharePoint 2010
DD109 Claims Based AuthN in SharePoint 2010DD109 Claims Based AuthN in SharePoint 2010
DD109 Claims Based AuthN in SharePoint 2010Spencer Harbar
 
SPSLisbon 2017 Office 365 Multi-factor Authentication with Microsoft Azure Ac...
SPSLisbon 2017 Office 365 Multi-factor Authentication with Microsoft Azure Ac...SPSLisbon 2017 Office 365 Multi-factor Authentication with Microsoft Azure Ac...
SPSLisbon 2017 Office 365 Multi-factor Authentication with Microsoft Azure Ac...Nuno Árias Silva
 
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the CloudSharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the CloudDanny Jessee
 
O auth2 with angular js
O auth2 with angular jsO auth2 with angular js
O auth2 with angular jsBixlabs
 
Impact of digital certificate in network security
Impact of digital certificate in network securityImpact of digital certificate in network security
Impact of digital certificate in network securityrhassan84
 
Impact of digital certificate in network security
Impact of digital certificate in network securityImpact of digital certificate in network security
Impact of digital certificate in network securityrhassan84
 
Managing Identity and Securing Your Mobile and Web Applications with Amazon C...
Managing Identity and Securing Your Mobile and Web Applications with Amazon C...Managing Identity and Securing Your Mobile and Web Applications with Amazon C...
Managing Identity and Securing Your Mobile and Web Applications with Amazon C...Amazon Web Services
 
Powerpoint Presentation
Powerpoint PresentationPowerpoint Presentation
Powerpoint Presentationwebhostingguy
 
Powerpoint Presentation
Powerpoint PresentationPowerpoint Presentation
Powerpoint Presentationwebhostingguy
 
#SPSToronto The SharePoint Framework and the Microsoft Graph on steroids with...
#SPSToronto The SharePoint Framework and the Microsoft Graph on steroids with...#SPSToronto The SharePoint Framework and the Microsoft Graph on steroids with...
#SPSToronto The SharePoint Framework and the Microsoft Graph on steroids with...Vincent Biret
 
#SPSottawa The SharePoint Framework and The Microsoft Graph on steroids with ...
#SPSottawa The SharePoint Framework and The Microsoft Graph on steroids with ...#SPSottawa The SharePoint Framework and The Microsoft Graph on steroids with ...
#SPSottawa The SharePoint Framework and The Microsoft Graph on steroids with ...Vincent Biret
 
Web 2.0 Tech Talk
Web 2.0 Tech TalkWeb 2.0 Tech Talk
Web 2.0 Tech Talkpooyad
 
Tejasya Hotel
Tejasya HotelTejasya Hotel
Tejasya Hotelkiranc0
 

Similar a Luminis Iv To Exchange Labs (20)

Luminis Iv Sso 2010
Luminis Iv Sso 2010Luminis Iv Sso 2010
Luminis Iv Sso 2010
 
Why Cant I Access The Portal
Why Cant I Access The PortalWhy Cant I Access The Portal
Why Cant I Access The Portal
 
Introduction to the Windows Live Platform
Introduction to the Windows Live PlatformIntroduction to the Windows Live Platform
Introduction to the Windows Live Platform
 
TugaIT 2017 Office 365 Multi-factor authentication with Microsoft Azure Activ...
TugaIT 2017 Office 365 Multi-factor authentication with Microsoft Azure Activ...TugaIT 2017 Office 365 Multi-factor authentication with Microsoft Azure Activ...
TugaIT 2017 Office 365 Multi-factor authentication with Microsoft Azure Activ...
 
The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)The Who, What, Why and How of Active Directory Federation Services (AD FS)
The Who, What, Why and How of Active Directory Federation Services (AD FS)
 
ad.ppt
ad.pptad.ppt
ad.ppt
 
Ad.Ppt
Ad.PptAd.Ppt
Ad.Ppt
 
DD109 Claims Based AuthN in SharePoint 2010
DD109 Claims Based AuthN in SharePoint 2010DD109 Claims Based AuthN in SharePoint 2010
DD109 Claims Based AuthN in SharePoint 2010
 
SPSLisbon 2017 Office 365 Multi-factor Authentication with Microsoft Azure Ac...
SPSLisbon 2017 Office 365 Multi-factor Authentication with Microsoft Azure Ac...SPSLisbon 2017 Office 365 Multi-factor Authentication with Microsoft Azure Ac...
SPSLisbon 2017 Office 365 Multi-factor Authentication with Microsoft Azure Ac...
 
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the CloudSharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
SharePoint 2010, Claims-Based Identity, Facebook, and the Cloud
 
O auth2 with angular js
O auth2 with angular jsO auth2 with angular js
O auth2 with angular js
 
Impact of digital certificate in network security
Impact of digital certificate in network securityImpact of digital certificate in network security
Impact of digital certificate in network security
 
Impact of digital certificate in network security
Impact of digital certificate in network securityImpact of digital certificate in network security
Impact of digital certificate in network security
 
Managing Identity and Securing Your Mobile and Web Applications with Amazon C...
Managing Identity and Securing Your Mobile and Web Applications with Amazon C...Managing Identity and Securing Your Mobile and Web Applications with Amazon C...
Managing Identity and Securing Your Mobile and Web Applications with Amazon C...
 
Powerpoint Presentation
Powerpoint PresentationPowerpoint Presentation
Powerpoint Presentation
 
Powerpoint Presentation
Powerpoint PresentationPowerpoint Presentation
Powerpoint Presentation
 
#SPSToronto The SharePoint Framework and the Microsoft Graph on steroids with...
#SPSToronto The SharePoint Framework and the Microsoft Graph on steroids with...#SPSToronto The SharePoint Framework and the Microsoft Graph on steroids with...
#SPSToronto The SharePoint Framework and the Microsoft Graph on steroids with...
 
#SPSottawa The SharePoint Framework and The Microsoft Graph on steroids with ...
#SPSottawa The SharePoint Framework and The Microsoft Graph on steroids with ...#SPSottawa The SharePoint Framework and The Microsoft Graph on steroids with ...
#SPSottawa The SharePoint Framework and The Microsoft Graph on steroids with ...
 
Web 2.0 Tech Talk
Web 2.0 Tech TalkWeb 2.0 Tech Talk
Web 2.0 Tech Talk
 
Tejasya Hotel
Tejasya HotelTejasya Hotel
Tejasya Hotel
 

Luminis Iv To Exchange Labs

  • 1. Melissa Miller La Salle University Philadelphia, PA [email_address]
  • 2.
  • 3.
  • 4.
  • 5.
  • 6.
  • 7.
  • 8.
  • 9.
  • 10.
  • 11.
  • 12.
  • 13.
  • 14.  
  • 15.
  • 16.
  • 17.  
  • 18.
  • 19.
  • 20.
  • 21. Based off of Scenario 2a from SDK Guide
  • 22.  
  • 23.
  • 24.
  • 25.
  • 26.  
  • 27.
  • 28. https://inside.lasalle.edu/cas/login?Service=www.mywebsite.com User logs into Luminis Portal User is presented with Link
  • 29. Browser sent to CAS with Service ID CAS Returns Ticket and Cookie http://www.mywebsite.com/? ticket=ST-12-g9uDQJB0gtoOJfiycsdz https://inside.lasalle.edu/cas/login? Service=www.mywebsite.com
  • 30. Browser sent to CAS enabled Web Service with ticket http://www.mywebsite.com/ ?ticket=ST-12-g9uDQJB0gtoOJfiycsdz https://inside.lasalle.edu/cas/validate?service=http://www.mywebsite.com& ticket=ST-12-g9uDQJB0gtoOJfiycsdz Web Service Validates Ticket External CAS Enabled Web Service
  • 31. Yes , username User is now Authenticated into External Web Service External CAS Enabled Web Service
  • 32.
  • 33.  
  • 34. Alternative to GCF/CPIP No password exchanged with External System
  • 35.
  • 36.
  • 37.
  • 38. Authenticated. Now What? Microsoft's Solution (Big Picture)
  • 39.
  • 40.
  • 41. The client is redirected by the URL to the Windows Live ID Login Service with a valid SLT. The Windows Live ID Login Service issues a ticket for requested mail service .
  • 42. The Windows Live Mail Service redirects the student to their mailbox. The client browser is redirected again to the Windows Live Mail Service. https://exchangelabs.com/owa/?wa=wsignin1.0
  • 43.
  • 44.
  • 45.
  • 46.
  • 47.
  • 48.

Notas del editor

  1. Good morning everyone. My name is Melissa Miller and I work at La Salle University as the Manager of Web Applications. I am here today to talk about our method of providing Single Sign On to the Microsoft Exchange Labs email system.
  2. In the Fall of 2007, Our IT department started to evaluate options for student email. Do we stay with Lotus Notes, migrate to a local Exchange server, or outsource? Students want larger mailboxes, larger attachments, an easy to use interface and a reliable system.
  3. Read slide
  4. So what about Faculty and Staff email? Well, there was no desire to leave them on the Lotus Notes system due to the overall dissatisfaction of the software. We decided to build a local Exchange server environment and migrate them to this new server. This migration process is still underway as we speak, moving people by department or building, keeping the action contained to ensure they get the best support possible in the process. What’s nice about this solution is that we already owned the Exchange server and Outlook client licenses so the cost really came down to hardware. We were also able to upgrade the hardware for our spam appliance and reduce licensing costs since the number of local mailboxes dropped from 15000 to 1700. As far as integrating with the Luminis Portal, SCT provides a MOWA connector that you just need to setup and activate in your environment.
  5. So what about Faculty and Staff email? Well, there was no desire to leave them on the Lotus Notes system due to the overall dissatisfaction of the software. We decided to build a local Exchange server environment and migrate them to this new server. This migration process is still underway as we speak, moving people by department or building, keeping the action contained to ensure they get the best support possible in the process. What’s nice about this solution is that we already owned the Exchange server and Outlook client licenses so the cost really came down to hardware. We were also able to upgrade the hardware for our spam appliance and reduce licensing costs since the number of local mailboxes dropped from 15000 to 1700. As far as integrating with the Luminis Portal, SCT provides a MOWA connector that you just need to setup and activate in your environment.
  6. Heart of presentation.
  7. Heart of presentation.
  8. Okay now I would like to take a minute or two to run down the terminology list from the LiveAtEdu setup guide. (summarize definitions)
  9. So when the user clicks on the Email Icon, this is the link they get. You can see the service ID being passed into CAS. CasRedirect.aspx was put together for the sole purpose of handling the authentication of the user to the IIS server. Once authenticated, the browser is sent directly to Redirect.aspx
  10. So when the user clicks on the Email Icon, this is the link they get. You can see the service ID being passed into CAS. CasRedirect.aspx was put together for the sole purpose of handling the authentication of the user to the IIS server. Once authenticated, the browser is sent directly to Redirect.aspx
  11. Here is a portion of our CASRedirect code. What we are looking at here is the code that sends the LiveID to Redirect.aspx which was part of the code package for SSO. When authentication to CAS happens, the string returned is the word ‘yes’ followed by a comma, followed by the username. So for me it would be yes,millermm. So the first part of the if statement is checking for the word ‘yes’ in the reply. If this is true, then we extract the username from stringReply by trimming off the first 4 characters. wlUserID is built by calling the GetWindowsLiveID function and passing in the username and scenario. The scenario is within the web.config file. At the bottom, if windowsLiveUserID is not null then the ID is passed to redirect.aspx
  12. Okay so now we have been authenticated through CAS to the IIS Server. What now? This is the segment of the Solution that is provided to you by Microsoft (minus CASRedirect.aspx)
  13. Lets start with Redirect.aspx. Once Redirect.aspx gets the LiveID it processes it and passes it to the Windows Live™ ID SOAP (Single Object Access Protocol) Service by requesting an SLT (short-lived token) using the getSLT function API (provided with this SDK) via SSL. The SLT is received by the IIS server from the Windows Live ID SOAP Service via SSL and converted to a URL such as (see link). You can see that the Token issued is specifically for mail service. The URL is redirected to the Luminis portal server, which is then send to the client browser.
  14. The clients browser is then redirected to the Windows LiveID Login Service with a Valid SLT. I have highlighted the token in the example above from a session that was captured via a firefox add-in called liveheaders. The Windows Live ID Login Service issues a ticket for requested service (Mail). The client browser is redirected to Windows Live Mail Service. The Windows Live Mail Service redirects the student to their mailbox.
  15. Ok so what else was involved in this thing? Well there was the IIS Server installation and setup, Web.config customizations, and days upon days of certificate and site troubleshooting. I’ll talk a bit about the Server installation.
  16. One of the first things you need to do is obtain and Import a provided security certificate into LocalComputerPersonal store. This procedure is illustrated in the SDK Appendix - Security Certificate Installation. You would have obtained that cert from Microsoft. Then, Copy your SDK files into created web-site root directory (such as "C:inetpubwwwrootSSOPortal or EmailSSO, whatever you decide. Create and configure a web-site for your SSO Portal on IIS. This portal will be the middleman between your Luminis Server and Windows Live Authentication servers. These procedures are illustrated in the SDK Appendix - Portal Web Site Configuration (IIS).
  17. Next you will configure the IIS Windows Authentication for the ‘Public’ sub-directory to allow anonymous access. If you refer to the instructions for the previous step, the SDK Appendix instructed to uncheck the “Enable Anonymous Access” check-box on the root web-site. This is correct; however, the reverse instructions should be used to check the “Enable Anonymous Access” check-box on the ‘Public’ sub-directory. Modify access control list (ACL) for the previously installed certificate. Since the “code behind” of ASP.NET will be executed under the IUSER_ ServerName context, you will need to ensure that the IUSER_ ServerName user account has appropriate security permissions to read the installed certificate from certificate storage and you must also have network service . . The PfxNSAcl.exe utility included in this SDK will adjust the access control list (ACL) accordingly. You then export the certificate for use with the solution and make modifications to web.config to fit your solution. I don’t want to get into too much detail on the specifics of the IIS server setup since they are well documented by Microsoft, and I know that since I used release 3.5 they have released a version 4 which I believe has changed slightly. I would download what they provide and get the IIS portion working before worrying about getting the CAS hooked up. They provide you with Test pages that test your connection to Microsofts various authentication servers and will inform you if there is a problem.
  18. Some things I have learned along the way is to allow plenty of time to deal with support issues. Microsoft is working on there support model and as of this writing this is still in progress. In particular the Windows Ed Desk was a major sticking point in trying to resolved certificate issues. Make sure you are clear from the beginning on your domains and if you will have sub domains or separate domains because that changes EVERYTHING as far as they are concerned. If you can land yourself one or two senior tech support people they will be your best friends and help escalade the process in a way that you cant.