Category: Microsoft 365

  • Disable MFA requirement in Microsoft 365 for specific users

    Disable MFA requirement in Microsoft 365 for specific users

    We would require a specific user or a migration process to have MFA disabled. Although it’s not suggested due to security reasons, we might be forced to have it disabled.

    If you disable the Multifactor authentication from the Multi-factor authentication in the Active Users, it will not matter as the system will still be enabled.

    Before proceeding, a group should be created for example MFA Excluded and put the users needed in the group.

    For this and the new portal changes Microsoft have done, you need to get into the Entra ID admin portal.

    https://entra.microsoft.com

    Click on Protection from the side pane and click on Authentication Methods.

    Click on Policies and click on Microsoft Authenticator.

    Click on the Exclude tab and add the group that was created earlier.

    This should allow you to use an account without MFA.

  • Pre-Provision a user’s OneDrive in Microsoft 365 using PowerShell

    Pre-Provision a user’s OneDrive in Microsoft 365 using PowerShell

    When a new account is created in Microsoft 365, its OneDrive is not provisioned, which the user must do. If you needed to pre-provision it for the user, you would need to log in with every user or use the below method to pre-provision it using PowerShell. Usually, this is done to pre-fill the OneDrive of a user with startup data and folder structure as well as it is needed to be provisioned for a migration process.

    A requirement for this is to have the SharePoint Online Management Shell installed, which can be downloaded from the Microsoft site https://www.microsoft.com/en-US/download/details.aspx?id=35588&msockid=3765afd8b0d06ff03ce2baf8b1a76eb2.

    Once downloaded and installed, open a PowerShell window.

    Type the following command

    Connect-SPOService -Url <your admin sharepoint URL>

    The admin SharePoint URL is usually the domain -admin.sharepoint.com for example https://mydomain-admin.sharepoint.com

    Then you will need the following command to pre-provision the Onedrive.

    Request-SPOPersonalSite -UserEmails <email address of user>

    This will provision the OneDrive or the user.

  • Microsoft 365 online archive never starts

    Microsoft 365 online archive never starts

    When having a user mailbox, you enable the online archive mailbox and set the archive policy, but the emails never move from the user mailbox to the online archive. You run the full crawl with PowerShell but nothing happens.

    The problem could be that the Retention Hold is enabled. This can be fixed by running the below.

    Get-Mailbox "<email address of user>" | Select RetentionHoldEnabled

    This will show if the feature is enabled. Run the following command to remove the Retention Hold flag.

    Set-Mailbox "<email address of user>" -RetentionHoldEnabled $false

    Once this is complete, run the following command to re-run the job.

    Start-ManagedFolderAssistant -Identity "<email address of user>" -FullCrawl

    After some time you should see the archive being populated.

  • Fix Remote server returned ‘550 5.7.520 Access denied, Your organization does not allow external forwarding

    Fix Remote server returned ‘550 5.7.520 Access denied, Your organization does not allow external forwarding

    This is a security feature from Microsoft 365 where it will block emails from being forwarded outside the tenant. If you get such a message, this means that the recipient has forwarding set outside its tenant. To allow this feature, follow the below guide.

    Open the Office 365 Admin Center and click on Security.

    Under Email & Collaboration, click on Policies & Rules.

    Click on Threat Policies.

    Click on Anti-Spam under Policies.

    Click on Anti-spam outbound policy (Default).
    Scroll down and click on Edit protection settings.
    Under Forwarding Rules, change the Automatic forwarding rules from Automatic – System-controlled to On – Forwarding is enabled.
    Click on Save.