SFU Mail - Policy Map

Overview

This article is intended to help IT support staff navigate change as the university transitions to Exchange Online. It charts the current state (Exchange 2016) and the future state (M365) and contains information regarding:

Details

Minimum OS Requirements

  SFU Exchange 2016 On-Premises Environment SFU Mail Hybrid Environment
  Mailbox: On-Premises Mailbox: On-Premises Mailbox: Cloud
Minimum OS Requirements

Minimum system requirements:

Microsoft allows the following as a minimum to connect to Exchange 2016:

Desktop:

  • Outlook 2016. Requires Windows 7 Service Pack 1
  • Outlook for Mac (2019). Requires macOS 10.13

Mobile:

  • iOS 9.0
  • Android 4.0

Web:

  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Same as on-premises environment.

Minimum system requirements:

Desktop:

  • Windows 10 build 14393
  • macOS 10.14

Mobile:

  • Android OS 5.0 (Gmail) or 8.0 (Samsung Mail)
  • iOS 11.0; iPadOS 13.1

Web:
Latest versions of the following:

  • Microsoft Edge
  • Firefox
  • Chrome
  • Safari
Minimum Requirements for Outlook Mobile Outlook Mobile is blocked and not available. Same as on-premises environment.

Outlook for iOS/iPadOS requires iOS/iPadOS 16.0 or later. Support is limited to the two most recent versions. For the latest updates regarding this app, see Outlook on the App Store.

Outlook for Android requires Android 9.0 or later. Support is limited to the four most recent versions. For the latest updates regarding this app, see Outlook on the Play Store.

 

Approved and Supported Desktop and Mobile Clients

  SFU Exchange 2016 On-Premises Environment SFU Mail Hybrid Environment
  Mailbox: On-Premises Mailbox: On-Premises Mailbox: Cloud in Hybrid Environment
Approved and Supported Desktop Clients and Setups

Account Setup
Outlook (Windows, Mac) allows Exchange and IMAP accounts.

Same as on-premises environment.

Account Setup 
Outlook (Windows, Mac) allows M365 accounts only. IMAP accounts are no longer allowed. 

Managed Devices: 
Only Outlook 2016 is available and supported. 

Unmanaged Devices: 
Any third-party mail app can be used. Only Outlook 2016 is fully supported. 

Managed Devices: 
Only Outlook 2021 is available and supported. 

Unmanaged Devices: 
Any third-party mail app can be used. Only M365 and Outlook 2021 are fully supported. 

Outlook 2016 and 2019 may still be able to connect but are not supported. 

Managed Devices: 
Only Outlook 2021 is available and fully supported. 

Unmanaged Devices: 
Only
approved mail apps can be used. Only M365 and Outlook 2021 are fully supported. 

Outlook 2016 and 2019 may still be able to connect but are not supported. 

Third-Party Mail Clients 
The following mail apps are available with setup instructions:  

  • Apple Mail (includes integration with Calendar, Contacts Notes, Reminders) 

  • Mozilla Thunderbird with TbSync or the OWL for Exchange** add-in 

** OWL is a paid add-in and is not endorsed by Microsoft or SFU. IT Services recommends using the other listed apps instead.

Third-Party Mail Clients

Same as on-premises.

Third-Party Mail Clients 
The following mail apps are available with setup instructions: 

  • Windows Mail 

  • Apple Mail (includes integration with Calendar, Contacts, Notes, Reminders) 

  • Mozilla Thunderbird with TbSync or the OWL for Exchange** add-in 

** OWL is a paid add-in and is not endorsed by Microsoft or SFU. IT Services recommends using the other listed apps instead. 

Approved and Supported Mobile Clients

Outlook for Mobile is not available. 

Setup instructions are available for: 

  • Apple Mail (includes integration with Calendar, Contacts, Notes, Reminders) 

  • Gmail for Android 

Same as on-premises environment.

Outlook for Mobile is available and fully supported. 

Setup instructions are available for: 

  • Apple Mail (includes integration with Calendar, Contacts, Notes, Reminders) 

  • Samsung Mail 

  • Gmail for Android 

 

Permitted Authentication and Synchronization Protocols

  SFU Exchange 2016 On-Premises Environment SFU Mail Hybrid Environment
  Mailbox: On-Premises Mailbox: On-Premises Mailbox: Cloud
Permitted Authentication Protocols Basic Authentication only. Basic Authentication only. Modern Authentication only.
Internet and Synchronization Protocols

Exchange/Active Sync, EWS, IMAP, SMTP allowed.

IMAP setup instructions available in help guides.

POP allowed at organizational level but disabled at mailbox level. Requires permission from Exchange Admin. No setup instructions in help guides.

Same as on-premises environment.

Exchange/Active Sync, EWS, IMAP, SMTP allowed (on approved applications only).

IMAP setup instructions (for approved apps) are available in help guides.

POP allowed at organizational level but disabled at mailbox level. Requires permission from Exchange Admin. No setup instructions in help guides

 

Permitted Services and Add-Ins

  SFU Exchange 2016 On-Premises Environment SFU Mail Hybrid Environment
  Mailbox: On-Premises Mailbox: On-Premises in Hybrid Environment Mailbox: Cloud in Hybrid Environment
Permitted services connecting to mail via allowed protocols (eg. TDX, Riva, Salesforce, etc.) All services are permitted to connect to mail. All services are permitted to connect to mail.

Services must support OAuth and go through the IT approval process, which includes a completed PIA. 

List of approved services/apps/add-ins.

O365 Desktop App Add-ins (Salesforce, Zoom)

Managed Devices:
Add-ins are deployed by IT Admins with GPO to deploy on scoped devices.

Unmanaged Devices:
No desktop apps or add-ins allowed.

Managed Devices:
Add-ins are deployed by IT Admins with GPO to deploy on scoped devices.

Unmanaged Devices:
No desktop apps or add-ins allowed.

Managed Devices:
Add-ins are deployed by IT Admins with GPO to deploy on scoped devices and match M365 policies.

Unmanaged Devices:
Third-party add-ins are required to go through an approval process before being deployed centrally by the M365 System Analyst.

Add-ins can be deployed per user or across enterprise depending on the use case. 

Thunderbird Add-Ons: TbSync, OWL

TbSync and OWL add-ons are allowed. 

OWL is a paid add-on and is not endorsed by Microsoft or SFU. IT Services recommends using the listed alternatives instead.

 

M365 and Third-Party Apps

  SFU Exchange 2016 On-Premises Environment SFU Mail Hybrid Environment
  Mailbox: On-Premises Mailbox: On-Premises in Hybrid Environment Mailbox: Cloud in Hybrid Environment
Permitted M365 Apps

List of available apps: 

  • Delve 
  • Engage (Viva Engage) 
  • Excel 
  • Forms 
  • Insights (Viva Insights)* 
  • Learning (Viva Learning)* 
  • Lists 
  • Loop 
  • OneDrive 
  • OneNote 
  • Planner 
  • Power Apps 
  • Power Automate 
  • Power BI**
  • Power Pages 
  • PowerPoint 
  • Project 
  • SharePoint 
  • Stream 
  • Sway 
  • Teams*
  • Visio 
  • Whiteboard 
  • Word 

* Available to staff/faculty accounts only.
** Available with Teams license

Non-staff accounts can be added to an SFU Team to grant them access. Bookings is not available.

Same as on-premises environment.

Same as On-Premises Environment.

In-addition to apps listed for on-premises: 

  • Bookings (1:1 meetings) 
  • Calendar 
  • Outlook 
  • People 
  • To Do 
MS Teams Apps (Teams Calendar App, Planner)

MS Teams apps are not available.

MS Teams apps are available, but some apps are hidden by default.

Calendar App will be pinned.

MS Teams apps are available. Calendar App and other notable apps will be pinned.

Third Party Apps/add-ins (ex. Zoom)

Third party apps and add-ins are available. Support is provided by publisher.

Same as on-premises environment.

Not available for managed or unmanaged devices by default. 

Apps that undergo the approval process can be made available.  

Support for third-party apps and add-ins is provided by the publisher. 

List of approved apps/add-ins 

 

 

Retention, Backup, and Recovery

  SFU Exchange 2016 On-Premises Environment SFU Mail Hybrid Environment
  Mailbox: On-Premises Mailbox: On-Premises Mailbox: Cloud
Retention and Backup Retention of deleted items for 30 days. Full mailbox backup (restoration of folder structure and items) for 4 months. Same as on-premises environment. 30 day retention period for single item recovery. No more backup or mailbox restore capabilities.

Disabled or old mailboxes(accounts that have become lightweight)

Mailboxes of accounts that were full-weight and changed to lightweight are marked for deletion.

Changing account to full-weight re-instates mailbox and its contents, provided that mailbox contents were not already deleted.

Same as on-premises environment.

Mailboxes of accounts that were full-weight and changed to lightweight are deleted.

 

Mailbox and Send As Permissions

For a comprehensive list, see SFU Mail - Cross-Premise Mailbox Permissions.

  SFU Exchange 2016 On-Premises Environment SFU Mail Hybrid Environment
  Mailbox: On-Premises Mailbox: On-Premises Mailbox: Cloud
Supported Mailbox Permissions

Full Access, Send on Behalf, Send As, Private Items, Folder Permissions

Cross-premises mailbox permissions (Full Access, Send on Behalf, Send As, Private items) are only fully supported on the Outlook desktop client for PC.

Folder permissions are not supported cross-premises.

All permissions work when both accounts are in the cloud.

Cross-premises mailbox permissions (Full Access, Send on Behalf, Send As, Private items) are only fully supported on the Outlook desktop client for PC.

Folder permissions are not supported cross-premises.

 

Mailbox Storage

  SFU Exchange 2016 On-Premises Environment SFU Mail Hybrid Environment
  Mailbox: On-Premises Mailbox: On-Premises Mailbox: Cloud
Mailbox Storage Quotas

All accounts are given an initial quota of 5GB.

When staff, faculty, sponsored accounts, and retirees reach 88% of the storage quota, another 1GB is automatically added. No hard limit.

Students' storage quota maxes out at 5GB.

Same as on-premises.

Staff, faculty, sponsored accounts (with license upgrade): 100GB

Students: 5GB

Retirees, sponsored accounts (without license upgrade): 50GB

 

Custom Domains

Custom domains will remain on-premises as SFU transitions to cloud.

 

Role of Local IT

The role of local IT is to do the initial triaging, forward knowledge articles, and direct users to IT support when necessary.

Details

Article ID: 7318
Created
Mon 10/16/23 2:29 PM
Modified
Thu 4/18/24 10:46 AM