Differing DNS Records
When working with [U.S.] GOV tenants in Office 365, there are a couple different types of tenants that reflect varying levels of compliance & security requirements. Namely, there is:
- Office 365 GCC
- Office 365 GCC High and DoD
There are a number of compliance requirements that are met by each type of tenant, as can be guessed by the difference in names. Clearly, the Office 365 GCC High and DoD tenants meet a more strict set of requirements, as well as those that specifically target DoD entities.
There are several components to the architecture of these tenants that allow them to meet a more stringent set of requirements, and one of them is reflected by the difference in FQDNs and URLs that are used by endpoints to connect into these environments. Specifically, the Office 365 GCC High tenants (DoD is still being worked on) have a different list of required DNS records than your typical commercial tenant. While we are focusing on Skype for Business Online here, this also applies to Exchange Online.
The DNS records that are required for Skype for Business Online in a GCC High tenant are below:
CNAMEs
- 'sip'
- Points to: sipdir.online.gov.skypeforbusiness.us
- 'lyncdiscover'
- Points to: webdir.online.gov.skypeforbusiness.us
SRV
- '_sip'
- Points to: sipdir.online.gov.skypeforbusiness.us
- Port: 443
- Protocol: _tls
- '_sipfederationtls'
- Points to: sipfed.online.gov.skypeforbusiness.us
- Port: 5061
- Protocol: _tcp
Configuring Hybrid
As you can imagine, given the difference in the DNS records, you will want to slightly modify the PowerShell cmdlets that you use when setting up Hybrid for a Skype for Business environment that includes a GCC High tenant. Specifically, when running the New-CsHostingProvider cmdlet, you will want to do so like this, with the specified ProxyFqdn and AutoDiscoverUrl attributes:
New-CsHostingProvider -Identity SkypeforBusinessOnlineGov -ProxyFqdn -"sipfed.online.gov.skypeforbusiness.us" -Enabled $true -EnabledSharedAddressSpace $true -HostsOCSUsers $true -VerificationLevel UseSourceVerification -IsLocal $false -AutodiscoverUrl https://webdir.online.gov.skypeforbusiness.us/Autodiscover/AutodiscoverService.svc/root
The rest of the Hybrid configuration is pretty much the same. Next, when it comes to moving users via the Management Shell, you will modify the cmdlets like so:
Move-CsUser -Identity <user@domain.com> -Target sipfed.online.gov.skypeforbusiness.us -Credential $cred -HostedMigrationOverrideUrl https://admin1g.online.gov.skypeforbusiness.us/HostedMigration/hostedmigrationservice.svc.
So, to summarize, while I hate to seem like I am simplifying, we are pretty much putting 'gov.skypeforbusiness.us' anymore that 'lync.com' would typically show up in our Hybrid configuration process.
I hope this is able to save someone even a little bit of pain, somewhere. It seems like such a small thing, but if you are not aware of these differences, the errors that you will run into do not do a great job of letting you know where to start, and none of the "Configure Hybrid" documentation does a great job at calling out that there are differences for GCC High tenants.
New-CsHostingProvider -Identity SkypeforBusinessOnlineGov -ProxyFqdn -"sipfed.online.gov.skypeforbusiness.us" -Enabled $true -EnabledSharedAddressSpace $true -HostsOCSUsers $true -VerificationLevel UseSourceVerification -IsLocal $false -AutodiscoverUrl https://webdir.online.gov.skypeforbusiness.us/Autodiscover/AutodiscoverService.svc/root
The rest of the Hybrid configuration is pretty much the same. Next, when it comes to moving users via the Management Shell, you will modify the cmdlets like so:
Move-CsUser -Identity <user@domain.com> -Target sipfed.online.gov.skypeforbusiness.us -Credential $cred -HostedMigrationOverrideUrl https://admin1g.online.gov.skypeforbusiness.us/HostedMigration/hostedmigrationservice.svc.
So, to summarize, while I hate to seem like I am simplifying, we are pretty much putting 'gov.skypeforbusiness.us' anymore that 'lync.com' would typically show up in our Hybrid configuration process.
I hope this is able to save someone even a little bit of pain, somewhere. It seems like such a small thing, but if you are not aware of these differences, the errors that you will run into do not do a great job of letting you know where to start, and none of the "Configure Hybrid" documentation does a great job at calling out that there are differences for GCC High tenants.
This comment has been removed by a blog administrator.
ReplyDeleteThis comment has been removed by a blog administrator.
ReplyDeleteWhen conceptualizing the most ideal approaches to earn steady show consideration with your advertising group, consistently recollect that the group isn't the huge machine that numerous businesses improperly take it for.Best Bitcoin Trading online
ReplyDeleteThere are numerous MLM plans that turned out to be inadequate in light of the fact that individuals donít realize the subtleties to be put on them. 소액결제현금화
ReplyDeleteVery useful info. Hope to see more posts soon!. Bolt Posts
ReplyDeleteI have added and shared your site to my social media accounts to send people back to your site because I am sure they will find it extremely helpful too. Corporate Headshots
ReplyDeleteYou have a good point here!I totally agree with what you have said!!Thanks for sharing your views...hope more people will read this article!!! Cheapest bulk sms provider in Qatar
ReplyDeleteI really like your take on the issue. I now have a clear idea on what this matter is all about.. Bolt Posts
ReplyDeleteThanks for the blog post buddy! Keep them coming... Bitcoin profit review
ReplyDeleteYou have beaten yourself this time, and I appreciate you and hopping for some more informative posts in future. Thank you for sharing great information to us. as low as 3.95 a month
ReplyDeleteNice to be visiting your blog again, it has been months for me. Well this article that i've been waited for so long. I need this article to complete my assignment in the college, and it has same topic with your article. Thanks, great share. Classified site in Dubai
ReplyDeleteSometime it becomes very hard to find a well written and well established bog which give you correct and useful information. However, I found this blog and got some relevant information which are really helpful for me. 출장서비스
ReplyDelete