<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Microsoft 365 on justinverstijnen.nl</title><link>https://projectkaasplank.justinverstijnen.nl/blog/microsoft-365/</link><description>Recent content in Microsoft 365 on justinverstijnen.nl</description><generator>Hugo</generator><language>en</language><atom:link href="https://projectkaasplank.justinverstijnen.nl/blog/microsoft-365/index.xml" rel="self" type="application/rss+xml"/><item><title>Getting started with Microsoft 365 Backup</title><link>https://projectkaasplank.justinverstijnen.nl/getting-started-with-microsoft-365-backup/</link><pubDate>Fri, 03 Apr 2026 00:00:00 +0000</pubDate><guid>https://projectkaasplank.justinverstijnen.nl/getting-started-with-microsoft-365-backup/</guid><description>&lt;p&gt;Microsoft 365 Backup ensures that your data, accounts and email is safe and backed up into a separate storage space. A good and reliable back-up solution is crucial for any cloud service, even when having versioning and recycle bin options. Data in SharePoint or OneDrive stays data in one central place and any minor error is made within seconds.&lt;/p&gt;
&lt;p&gt;In this guide, I will explain how Microsoft 365 Backup works and how you can start using it.&lt;/p&gt;</description></item><item><title>What is MTA-STS and how to use it to protect your email flow</title><link>https://projectkaasplank.justinverstijnen.nl/what-is-mta-sts-and-how-to-protect-your-email-flow/</link><pubDate>Thu, 08 Jan 2026 00:00:00 +0000</pubDate><guid>https://projectkaasplank.justinverstijnen.nl/what-is-mta-sts-and-how-to-protect-your-email-flow/</guid><description>&lt;p&gt;MTA-STS is a standard for ensuring TLS is always used for email transmission. This increases security and data protection because emails cannot be read by a Man in the Middle. It works like this for inbound and outbound email to ensure security is applied to all of the messages processed by your emailing solution and domains.&lt;/p&gt;
&lt;p&gt;In this guide I will explain how it works. Because it is a domain specific configuration, it can work with any service and is not bound to for example Exchange Online. In this guide we use Azure to host our MTA-STS policy. I present you 2 different options for you to choose, and of course only one is needed. You can also choose to use another solution, its it supports HTTPS and hosting a single TXT file, it should work.&lt;/p&gt;</description></item><item><title>Disable users' self service license trials</title><link>https://projectkaasplank.justinverstijnen.nl/disable-users-self-service-license-trials/</link><pubDate>Thu, 04 Dec 2025 00:00:00 +0000</pubDate><guid>https://projectkaasplank.justinverstijnen.nl/disable-users-self-service-license-trials/</guid><description>&lt;p&gt;One day I came across an option in Microsoft 365 to disable the users&amp;rsquo; self service trials. You must have seen it happening in your tenants, users with free licenses for Power Automate, Teams or Power BI. I will show you how to disable those and only let administrators buy and assign new licenses.&lt;/p&gt;
&lt;p&gt;&lt;img src="https://sajvwebsiteblobstorage.blob.core.windows.net/blog/disable-users-self-service-license-trials-5454/jv-media-5454-b2e8595ef8fb.png" alt=""&gt;&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="why-should-you-disable-trial-licenses"&gt;Why should you disable trial licenses?&lt;a class="td-heading-self-link" href="#why-should-you-disable-trial-licenses" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;You can disable self service trial licenses if you want to avoid users to use un-accepted apps. This could result in shadow-it happening in your environment.&lt;/p&gt;</description></item><item><title>Enhance email security with SPF/DKIM/DMARC</title><link>https://projectkaasplank.justinverstijnen.nl/enhance-email-security-with-spf-dkim-dmarc/</link><pubDate>Mon, 16 Jun 2025 00:00:00 +0000</pubDate><guid>https://projectkaasplank.justinverstijnen.nl/enhance-email-security-with-spf-dkim-dmarc/</guid><description>&lt;p&gt;When it comes to basic email security, we have 3 techniques that can enhance our email security and delivery by some basic initial configuration. Those are called SPF, DKIM and DMARC. This means, configure and mostly never touch again.&lt;/p&gt;
&lt;div class="alert alert-info" role="alert"&gt;
&lt;p&gt;&lt;a href="https://techcommunity.microsoft.com/blog/microsoftdefenderforoffice365blog/strengthening-email-ecosystem-outlook%E2%80%99s-new-requirements-for-high%E2%80%90volume-senders/4399730"&gt;Microsoft announced&lt;/a&gt; that starting from May 5, 2025: SPF, DKIM and DMARC will become mandatory for inbound email delivery. Not configuring all three can result in your emails not being delivered correctly.&lt;/p&gt;</description></item><item><title>Disable DirectSend in Exchange Online</title><link>https://projectkaasplank.justinverstijnen.nl/disable-directsend-in-exchange-online/</link><pubDate>Sun, 04 May 2025 00:00:00 +0000</pubDate><guid>https://projectkaasplank.justinverstijnen.nl/disable-directsend-in-exchange-online/</guid><description>&lt;p&gt;Microsoft has published a new command to completely disable the unsafe DirectSend protocol in your Microsoft 365 environment. In this guide I will explain what DirectSend is, why you should disable this and how we can achieve this.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="what-is-directsend"&gt;What is DirectSend?&lt;a class="td-heading-self-link" href="#what-is-directsend" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;DirectSend (Microsoft 365) lets devices or applications (like printers, scanners, or internal apps) send email directly to users inside your organization without authentication. Instead of using authentication, it uses your MX record directly with port 25.&lt;/p&gt;</description></item><item><title>Set a domain alias for every user in Microsoft 365</title><link>https://projectkaasplank.justinverstijnen.nl/set-a-domain-alias-for-every-user-in-microsoft-365/</link><pubDate>Fri, 13 Dec 2024 00:00:00 +0000</pubDate><guid>https://projectkaasplank.justinverstijnen.nl/set-a-domain-alias-for-every-user-in-microsoft-365/</guid><description>&lt;p&gt;Sometimes, we add a new domain to Microsoft 365 and we want to have a domain alias for multiple or every user.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="logging-in-exchange-online-powershell"&gt;Logging in Exchange Online Powershell&lt;a class="td-heading-self-link" href="#logging-in-exchange-online-powershell" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;To configure a alias for every user, we need to login into Exchange Online Powershell:&lt;/p&gt;

 &lt;div class="td-card card border me-4"&gt;
&lt;div class="card-header code"&gt;
 &lt;strong&gt;POWERSHELL&lt;/strong&gt;
 &lt;/div&gt;
&lt;div class="card-body code p-0 m-0"&gt;
 &lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-powershell" data-lang="powershell"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="nb"&gt;Connect-ExchangeOnline&lt;/span&gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;
 &lt;/div&gt;

&lt;p&gt;If you don&amp;rsquo;t have the module already installed on your computer, run the following command on an elevated window:&lt;/p&gt;</description></item><item><title>Configure DNSSEC and SMTP DANE Microsoft 365</title><link>https://projectkaasplank.justinverstijnen.nl/configure-dnssec-and-smtp-dane-with-exchange-online-microsoft-365/</link><pubDate>Thu, 31 Oct 2024 00:00:00 +0000</pubDate><guid>https://projectkaasplank.justinverstijnen.nl/configure-dnssec-and-smtp-dane-with-exchange-online-microsoft-365/</guid><description>&lt;p&gt;Recently, Microsoft announced the general availability of 2 new security protocol when using Microsoft 365 and the service Exchange Online in particular. SMTP DANE and DNSSEC. What are these protocols, what is the added value and how can they help you secure your organization? Lets find out.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="domain-name-system-security-extensions-dnssec"&gt;Domain Name System Security Extensions (DNSSEC)&lt;a class="td-heading-self-link" href="#domain-name-system-security-extensions-dnssec" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;DNSSEC is a feature where a client can validate the DNS records received by a DNS server to ensure a record is originated from the DNS server and not manipulated by a Man in the Middle attack.&lt;/p&gt;</description></item><item><title>Solved - Microsoft 365 tenant dehydrated</title><link>https://projectkaasplank.justinverstijnen.nl/microsoft-365-tenant-dehydrated/</link><pubDate>Fri, 20 Sep 2024 00:00:00 +0000</pubDate><guid>https://projectkaasplank.justinverstijnen.nl/microsoft-365-tenant-dehydrated/</guid><description>&lt;p&gt;Microsoft will sometimes &amp;ldquo;pause&amp;rdquo; tenants to reduce infrastructure costs. You will then get an error which contains &amp;ldquo;tenant dehydrated&amp;rdquo;. What this means and how to solve it, I will explain in this post.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="what-is-tenant-dehydrated"&gt;What is &amp;ldquo;Tenant dehydrated&amp;rdquo;?&lt;a class="td-heading-self-link" href="#what-is-tenant-dehydrated" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Microsoft sometimes will dehydrate Microsoft 365 tenants where things will not often change to the tenant. This closes some parts of the tenant for changing, even if you have Global Administrator permissions.&lt;/p&gt;</description></item><item><title>Create a Catch all mailbox in Exchange Online</title><link>https://projectkaasplank.justinverstijnen.nl/create-a-catch-all-mailbox-in-exchange-online/</link><pubDate>Thu, 11 Jul 2024 00:00:00 +0000</pubDate><guid>https://projectkaasplank.justinverstijnen.nl/create-a-catch-all-mailbox-in-exchange-online/</guid><description>&lt;p&gt;Sometimes a company wants to receive all email, even when addresses don&amp;rsquo;t really exist in Exchange. Now we call this a Catch all mailbox, where all inbound email is being catched that is not pointed to a known recipient. Think of a sort of *@domain.com.&lt;/p&gt;
&lt;p&gt;In this guide I will explain how to configure this in Exchange Online and how to maintain this by limiting our administrative effort. I also created a full customizable PowerShell script for this task which you can find here:&lt;/p&gt;</description></item><item><title>Microsoft 365 create a shared mailbox with same alias</title><link>https://projectkaasplank.justinverstijnen.nl/microsoft-365-exchange-online-create-shared-mailbox-with-same-alias/</link><pubDate>Thu, 06 Jun 2024 00:00:00 +0000</pubDate><guid>https://projectkaasplank.justinverstijnen.nl/microsoft-365-exchange-online-create-shared-mailbox-with-same-alias/</guid><description>&lt;p&gt;When using Microsoft 365 and using multiple custom domains, sometimes you are unable to create a shared mailbox that uses the same alias as an existing mailbox.&lt;/p&gt;
&lt;p&gt;In this guide I will explain this problem and show how to still get the job done.&lt;/p&gt;
&lt;hr&gt;
&lt;h2 id="the-problem-of-multiple-shared-mailboxes-with-same-alias"&gt;The problem of multiple shared mailboxes with same alias&lt;a class="td-heading-self-link" href="#the-problem-of-multiple-shared-mailboxes-with-same-alias" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Let&amp;rsquo;s say, we have a Microsoft 365 tenant with 3 domains;&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;domain1.com&lt;/li&gt;
&lt;li&gt;domain2.com&lt;/li&gt;
&lt;li&gt;domain3.com&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;When you already have a mailbox called &amp;ldquo;&lt;a href="mailto:info@domain1.com"&gt;info@domain1.com&lt;/a&gt;&amp;rdquo; you are unable to create a &amp;ldquo;&lt;a href="mailto:info@domain2.com"&gt;info@domain2.com&lt;/a&gt;&amp;rdquo; in the portal. The cause of this problem is that every mailbox has a underlying &amp;ldquo;alias&amp;rdquo; and that this alias is the same when created in the portal. I have tried this in the Microsoft 365 admin center, Exchange Online admin center and Powershell. I get the following error:&lt;/p&gt;</description></item><item><title>Migrate data to SharePoint/OneDrive with SPMT</title><link>https://projectkaasplank.justinverstijnen.nl/sharepoint-data-migration/</link><pubDate>Mon, 20 May 2024 00:00:00 +0000</pubDate><guid>https://projectkaasplank.justinverstijnen.nl/sharepoint-data-migration/</guid><description>&lt;p&gt;When still managing on-premises environments, but shifting your focus to the cloud you sometimes need to do a migration. This page helps you to migrate to SharePoint or Onedrive according to your needs.&lt;/p&gt;
&lt;p&gt;At the moment, SharePoint is a better option to store your files because it has the following benefits over a traditional SMB share:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Single permissions system (No SMB/NTFS permissions)&lt;/li&gt;
&lt;li&gt;High available by default&lt;/li&gt;
&lt;li&gt;No server infrastructure needed&lt;/li&gt;
&lt;li&gt;Users can work at the same file simultaneously&lt;/li&gt;
&lt;li&gt;Integration with Microsoft Teams&lt;/li&gt;
&lt;/ul&gt;
&lt;hr&gt;
&lt;h2 id="the-microsoft-sharepoint-migration-tool"&gt;The Microsoft SharePoint Migration Tool&lt;a class="td-heading-self-link" href="#the-microsoft-sharepoint-migration-tool" aria-label="Heading self-link"&gt;&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Microsoft has a tool available which is free and which can migrate your local data to SharePoint. The targets you can specify are:&lt;/p&gt;</description></item><item><title>Dynamic Distribution Groups in Microsoft 365</title><link>https://projectkaasplank.justinverstijnen.nl/dynamic-distribution-groups-in-microsoft-365/</link><pubDate>Sat, 21 Oct 2023 00:00:00 +0000</pubDate><guid>https://projectkaasplank.justinverstijnen.nl/dynamic-distribution-groups-in-microsoft-365/</guid><description>&lt;p&gt;Sometimes you want to have a distribution group with all your known mailboxes in it. For example an &lt;a href="mailto:employees@justinverstijnen.nl"&gt;employees@justinverstijnen.nl&lt;/a&gt; or &lt;a href="mailto:all@justinverstijnen.nl"&gt;all@justinverstijnen.nl&lt;/a&gt; address to send a mail company wide. A normal distribution group is possible, but requires a lot of manual maintenance, like adding and removing users.&lt;/p&gt;
&lt;p&gt;To apply a little more automation you can use the Dynamic Distribution Group feature of Exchange Online. This is a feature like the Dynamic groups feature of Microsoft Entra which automatically adds new user mailboxes after they are created to make sure every new employee is added automatically.&lt;/p&gt;</description></item></channel></rss>