Sonntag, 8. Oktober 2017
Samstag, 9. September 2017
Using site classification for SharePoint Sites
Site
classification is a must-have when we talk about Governance, Compliance and
also topics around GDPR.
Beside 3rd party solutions focusing on site
and content classification we have also some out of the box options and
developer opportunities in Office 365 and SharePoint on-prem. Depending on if
we are talking about classic SharePoint Site Collections or if we talk about modem
Team Sites, being part of an Office 365 Group, we have different szenarios.
To create a new SharePoint site in Office 365 we know two different ways.
- We can create a SharePoint Online Site using the SharePoint Online Administration. This will create a SharePoint Site based on WebTemplate STS
- We can go to SharePoint Home and click “create” in the upper left corner or we can go to Outlook Online and create a new Group. Both will create a SharePoint Site based on WebTemplate GROUP
- Define and set site policies
- Insert a custom action
- Custom site classification
- Add a classification indicator to site page
Using the opportunities
we have with Groups and Group Policies some of these things can be automatically
put to a SharePoint Site based on WebTemplate GROUP.
This video by Vesa Juvonen is showing the steps and
the final results:
As you can
see we need to create the site bases on option 2.
(Dialogs already
including policies)
SharePoint Home - Create:
Outlook
Online -> Create Group:
Final
result:
Step by Step
To enable
this functionality in Office 365 we need to set up an “Settings Object” and a “Settings
Template” in Azure AD. To do this we can use the Azure
Active Directory cmdlets for configuring group settings.
First of
all we need to install the preview of Azure Active Directory V2 PowerShell
Module:
Install-Module -Name AzureADPreview
To set up the site
classification options and configure properties like ClassificationList and ClassificationDescriptions etc follow these steps also shown in Vesas video:
#Connect
Connect-AzureAD
Get-AzureADDirectorySettingTemplate
#Create
$Template = Get-AzureADDirectorySettingTemplate -Id
62375ab9-6b52-47ed-826b-58e47e0e304b
$Setting = $template.CreateDirectorySetting()
$setting["UsageGuidelinesUrl"] =
"http://sharepointtalk.com"
$setting["ClassificationList"] = "Public, Internal,
TopSecret"
$setting["DefaultClassification"] = "TopSecret"
$setting["ClassificationDescriptions"] = "Public:no
restrictions,Internal:all internal users can access,TopSecret:only special
users can access"
$setting["GuestUsageGuidelinesUrl"] =
"http://sharepointtalk.net"
New-AzureADDirectorySetting -DirectorySetting $setting
#Check
Get-AzureADDirectorySetting -All $True
(Get-AzureADDirectorySetting -Id %%YOUR
ID%%).values
As described in the
video we can now use the CLASSIFICATION property to assign a site policy or any
other custom action. Details about site policies are part of Implement
a SharePoint site classification solution.
Here the script taken
from the video to get the CLASSIFICATION property:
#Get PnP PowerShellOnline
Install-Module SharePointPnPPowerShellOnline
#Get Site classfication value
Connect-PnPOnline https://%YOUR TENANT%.sharepoint.com/sites/%YOUR SITE%
Get-PnPSite
$Site.Classification
Get-PnPProperty
-ClientObject $Site -Property ClassificationSonntag, 30. Juli 2017
Overview of shared with Externals and shared Anonymous in Office 365
The GDPR
highlights the need for protection of personal data held by organizations. To
be able to do this Microsoft inverted a lot in new features and functions like the
Office
365 Security & Compliance Center or the GDPR Assessment.
One of the
backend systems helping to fulfill those regulations is the SharePoint Online
Search Service. In the SharePoint Online Search schema, we can find two managed
properties focusing on sharing and access from outside of your organization.
ViewableByExternalUsers and ViewableByAnonymousUsers
Both had
the same setting: Query, Retrieve, Refine
and Sort. So we can use them to
create some reports based on search queries.
Personal overview
Office 365
let every user search in his SharePoint Online sites, OneDrive for Business
files and also in Emails for content. In this scenario Email is of topic. But
using this search function at the landing page of Office 365 a user can create
a personal overview of content he shared to externals or anonymous.
To do this
a user needs to fill in the following query in the search box at the Office 365
landing page:
ViewableByAnonymousUsers=true
In this example,
I search for documents located in SharePoint Online sites or in my personal
OneDrive for Business which are shared based on an anonymous guest link.
Using the query
ViewableByExternalUsers=true shows me the files shared with
external users through a sharing link that requires them to log in before they
can view the file.
This gives
a user an overview of documents he has shared from his OneDrive for Business
with externals or anonymous. Because the URL is generic you can use this link
for all your users and every user get his person overview: https://www.office.com/search?auth=2&home=1&q=ViewableByAnonymousUsers%3Dtrue
Also you
can use this link to create a tile in the Office 365 App Launcher as described
in the article: Add
custom tiles to the app launcher
The result may look like this:
Team Site overview
Microsoft integrated a new out the box reporting
capability in every Team Site. The article: View
usage data for your SharePoint Online site is showing all details you need
to know. There is also a new tab called “Shared externally”.
The article
says: List of files you have access to
that have been shared with users outside your organization through a sharing
link that requires them to log in before they can view the file. Files shared
with anonymous users or files available to users with guest permissions are not
included.
To get a
list of files shared anonymous in this Team Site we can again use the query: ViewableByAnonymousUsers=true followed by a path filter like for
example: path:https:\\yourTeamSiteName.sharepoint.com.
Using Search Center to get
an overview
As an administrator,
you can also use the search center to get an overview of anonymous shared content
or about data and also SharePoint Online Sites them self, shared to externals.
The queries are basically the same and you can extend them with additional
keyword queries properties.
For example,
search all Office 366 Groups external users can access:
ViewableByExternalUsers=true contentclass:sts_site WebTemplate:GROUP
(Because of security trimming in SharePoint
Search the user who runs the query needs access to all Team Sites to gets an
complete report.)
Of cause
there are also options archiving this using PowerShell
for Office 365 Groups or using Reports
in the Office 365 Security & Compliance Center. Using the SharePoint
Online search gives you the power and flexibility to integrate all managed
properties as metadata in you report like for example ViewsLifeTime, LastModifiedTime,
CreatedBy or ModifiedBy. In addition you can easily scope
your report to only show documents using the IsDocument=true query parameter or to focus to
special Site Templates like WebTemplate:GROUP to only show Office 365 Groups Team Sites etc.
Using PowerShell to get
the report
Using
PowerShell to get results from SharePoint Online Search also offers the option
to save the report as an *.csv file. To call SharePoint Online Search API using
PowerShell and save the result to an *.csv file you can follow the steps explained
by Prasham
Sabadra in his article Office
365/Sharepoint Online - PowerShell Script To Call Search API And Get The Result.
This example
is based on his description. The report is showing all external shared content
and sites in an Office 365 Tenant and is saving the result to C:\Temp\ViewableByExternalUsers.csv
# add references to SharePoint
client assemblies and authenticate to Office 365 site - required for CSOM
Add-Type -Path "C:\Program
Files\Common Files\Microsoft Shared\Web Server
Extensions\16\ISAPI\Microsoft.SharePoint.Client.dll"
Add-Type -Path "C:\Program
Files\Common Files\Microsoft Shared\Web Server
Extensions\16\ISAPI\Microsoft.SharePoint.Client.Runtime.dll"
Add-Type -Path "C:\Program
Files\Common Files\Microsoft Shared\Web Server Extensions\16\ISAPI\Microsoft.SharePoint.Client.Search.dll"
#Specify tenant admin and
URL
$User =
"Admin@yourTenant.onmicrosoft.com"
#Configure Site URL and User
$SiteURL =
"https://yourTenant.sharepoint.com"
#Password
$Password
="yourPassword"
$securePassword =
ConvertTo-SecureString -String $Password -AsPlainText –Force
$Creds = New-Object
Microsoft.SharePoint.Client.SharePointOnlineCredentials($User,$securePassword)
#client context object and
setting the credentials
$Context = New-Object
Microsoft.SharePoint.Client.ClientContext($SiteURL)
$Context.Credentials = $Creds
#Calling Search API - Create the
instance of KeywordQuery and set the properties
$keywordQuery = New-Object
Microsoft.SharePoint.Client.Search.Query.KeywordQuery($Context)
#Sample Query - To get the last
year result
$queryText="ViewableByExternalUsers=true"
$keywordQuery.QueryText =
$queryText
$keywordQuery.TrimDuplicates=$false
$keywordQuery.SelectProperties.Add("LastModifiedTime")
$keywordQuery.SelectProperties.Add("ViewsLifeTime")
$keywordQuery.SelectProperties.Add("ModifiedBy")
$keywordQuery.SelectProperties.Add("ViewsLifeTimeUniqueUsers")
$keywordQuery.SelectProperties.Add("Created")
$keywordQuery.SelectProperties.Add("CreatedBy")
$keywordQuery.SortList.Add("ViewsLifeTime","Asc")
#Search API - Create the instance
of SearchExecutor and get the result
$searchExecutor = New-Object
Microsoft.SharePoint.Client.Search.Query.SearchExecutor($Context)
$results =
$searchExecutor.ExecuteQuery($keywordQuery)
$Context.ExecuteQuery()
#Result Count
Write-Host $results.Value[0].ResultRows.Count
#CSV file location, to store the
result
$exportlocation =
"C:\Temp\ViewableByExternalUsers.csv"
foreach($result in
$results.Value[0].ResultRows)
{
$outputline='"'+$result["Title"]+'"'+","+'"'+$result["Path"]+'"'+","+$result["ViewsLifeTime"]+","+$result["ViewsLifeTimeUniqueUsers"]+","+$result["CreatedBy"]+","+$result["Created"]+","+$result["ModifiedBy"]+","+$result["LastModifiedTime"]
Add-Content $exportlocation
$outputline
}
Montag, 5. Juni 2017
SharePoint 2016 – The Values of Hybrid, Cloud and on-prem
SharePoint 2016 – The Values of Hybrid, Cloud and on-prem
Hier das Video zu meinem Vortrag auf der Cloud and Datacenter Conference 2017 in München:Samstag, 18. März 2017
Delve and the Office Graph Inside Out Part II
In addition
to my first post about the insides of Office Graph and Delve (Delve
and the Office Graph Inside Out) this article is focusing on which signals
are used by the Graph to generate the individual Delve experience.
Signals used by the Graph
You can
find all the information you need about signals used by the Graph in this msdn
article: https://msdn.microsoft.com/office/office365/howto/query-Office-graph-using-gql-with-search-rest-api
Based on
this article we have the following Action Types:
- PersonalFeed
- Modified
- OrgColleague
- OrgDirect
- OrgManager
- OrgSkipLevelManager
- WorkingWith
- TrendingAround
- Viewed
- WorkingWithPublic
As you can
see in the msdn article the list of signals can be dived in private signals and
public signals so that data privacy is respected all the time:
In addition
Mark Kashman published an article on Microsoft techcommunity about Understanding
security and privacy of Delve and intelligent experiences in Office 365. In
this article, we can find the following diagram:
So we can
extend the list taken from the msdn article to this aggregated version:
- PersonalFeed
- Modified
- OrgColleague
- OrgDirect
- OrgManager
- OrgSkipLevelManager
- WorkingWith
- TrendingAround
- Viewed
- WorkingWithPublic
- Member of
- Created by
- Shared with me
- Direct reports
- Public
Some of
this signals are clear like for example Modified,
Viewed, Created by, etc. some others are a little bit mystic like TrendingAround. We can imagine what TrendingAround means, but we cannot get
an information about how this signal is processed in all details.
Anyway, it
is easy to understand how this signals are used to generate the individual
Delve experience.
The myth about the People suggestion in Delve
It is easy
to imagine how content suggestions are generated based on signals. But one of
the most asked questions about the Delve experience is about the difference
between People list on the left and Related People in my personal Delve
feet. Based on the signals list we can definitely get a better understanding
about this. People on the left are other users we visited in Office 365
respectively we have clicked on their Delve profile. Related People are based
on signals like “Member of”.
So for
example if you are Member of
- Member of a Distribution List in Exchange Online
- Member of a Office 365 Group
- Member of the same Manger or “Direct Reports” entity
this is processed
by the Graph to generate the Related People overview in your Delve feet.
As we can
see also in this scenario data privacy and data security is respected by the
Office Graph and Delve. If you are a “Member of” the same Distribution List or
Office 365 Group, you can see all the other members anyway.
More details
about this and also about compliance in Delve can be found in Mark Kashmans
article “Understanding security and privacy of Delve and intelligent
experiences in Office 365” I mentioned above.
Related
articles:
Abonnieren
Posts (Atom)








