The recordings of all the LA webinar sessions are available below.
Application Account Conversion – new process
The recent Franklin-Jones release gave all Local Admins the ability to convert application accounts directly without the need for a HSS request.
Please be aware that user accounts which belong to actual individuals should not be converted to application accounts. The NHSmail team will be doing regular checks on recently converted accounts to ensure that no accounts belonging to individual users have been converted in error.
Example:
john.doe@nhs.net should not be converted to an application account as this account belongs an individual and a new generically named account needs to be created to then be converted
Delayed Email Delivery Issue – 18 July 2023 (INC37076937 – Delayed eMail Delivery – RESOLVED – NHSmail Support)
Email delivery delay issue potentially triggered by two Microsoft service degradations:
- https://support.nhs.net/2023/07/microsoft-365-alert-service-degradation-exchange-online-users-inbound-and-outbound-email-delivery-may-be-delayed-for-15-minutes-or-longer-in-exchange-online/
- https://support.nhs.net/2023/07/microsoft-365-alert-service-degradation-exchange-online-some-users-may-be-unable-to-send-exchange-online-email-messages/
Emails continued to be delivered throughout the incident, however, some users may have experienced delays in emails being received in the recipient’s mailbox.
Detailed overview of incident and remediation provided by Accenture.
GP Phone System Retirement (Information – GP Phone System Retirement – NHSmail Support)
As highlighted by the Digital Primary Care team in May, the central provision and availability for Teams Phone System for GPs to use for outbound called will cease on 31 July 2023 at the end of the grace period.
From this point onwards, users at impacted organisations will be unable to make outbound calls to external PTSN numbers via the Teams client. This will not impact any organisations who have purchased and are using their own Teams Phone System licences.
Please note that any NHSmail User Policies that were created as part of the central service roll out will be renamed to remove the Phone System suffix from the naming convention. After 31 July, LAs will then be able to edit or re-name these policies as required.
O365 Updates – Ideas Welcome
https://forms.office.com/e/LiBTKC8pcF
You’ll all be familiar with the central O365 updates that appear in Teams to keep you all in the loop. We’re keen to source ideas for these updates from the LA community – if there are any specific topics you’d like
REMINDER: SMTP on user accounts
Quick reminder that SMTP should not be enabled on standard user accounts. If you have an account which requires SMTP to be enabled, this needs to be converted to an application account prior to SMTP being enabled.
SMTP on standard user accounts is being removed as part of a standard BAU background process and we recommend that LAs check their mailbox reports regularly to capture and proactively remediate any standard user accounts that have had SMTP enable in error.
FastTrack Overview – Danish Mahmood
- General Updates
- Live demo of the released Self-Service Password Reset
- Bring Your Own Device security controls and deep dive webinar reminder
- An update on converting user accounts to shared mailboxes
- O365 Company Communicator updates from Centre of Excellence Team
- Q&A time
- This week LA bulletin covered developments on the new user account secret questions
- Intune and MFA updates. In terms of numbers, there are 5k Intune devices enrolled and 180k accounts with MFA enabled.
- The Franklin Jones release on Wednesday 5 July will give the ability for LA/PLA to convert user mailboxes to Application account – NHSmail Support
- SMTP on user accounts will be withdrawn from user accounts on a regular basis; it is critical that this protocol is not re-added.
- Discussion about Otter. Ai and similar tooling, local governance as to whether it should be used or not.
- PODS team general update
- Updates were done by the Technical Architects team
- Update on the Microsoft contract and the participation agreement
All User Comms – NHSmail Annual Survey
Many of you will have already spotted, an all user comms was sent out yesterday to thank everyone for their participation in the NHSmail Annual Survey and share the key scores on the door with everyone.
Myself and the wider Service Management team would also like to pass on our personal thanks to everyone who took part. We appreciate you taking time out of your hectic schedules to do so and for continuing to collaborate with us year-round to continually improve the service.
Infrastructure Upgrade 23-25 June
Information – Planned Infrastructure Upgrade (NHSmail Datacentre) – First Notice – NHSmail Support
We will be completing an infrastructure upgrade next week starting at 7:00pm on Friday 23 June and completing on 25 June. During this period, all traffic will be actively routed via the active data centre to ensure there is no impact on end users.
Any organisations that are using direct IP addresses rather than DNS to access the email gateways may potentially lose service during the upgrade and if you believe that this affects your organisation, we recommend using our standard DNS settings to prevent any loss of service. Guidance regarding the relay config – https://support.nhs.net/knowledge-base/relay-configuration/
Where switching to the standard DNS settings is not possible or you perceive that there could potentially be significant user impact resulting in a clinical risk, we would encourage you to contact the Helpdesk for further guidance.
We expect there to be no service impacts as mentioned earlier, but as ever I’d encourage you to review your service continuity plans.
Trend/Junk Issue
INC36247960 – Legitimate Mail Being Directed to Junk Folder – RESOLVED – NHSmail Support
This audience will also be aware of the issue we had last week around legitimately emails being falsely flagged as Junk mail and move to Junk Mail in error.
This issue has now been fully resolved and the Accenture team continue to work closely with our third-party security provider on this and any wider improvements that are required to prevent a recurrence.
Pronouns Option in Teams
As it is Pride Month this month, I am delighted to announce that the option to add your Pronouns to your profile in Teams will be available in the NHSmail tenant from the middle of next week.
Adding your Pronouns to your Teams profile card will be entirely optional. However, I would like to encourage as many of you to do so as possible as it is a quite uncomplicated way that you can show your support for your LGBT colleagues across health & social care all year round.
REMINDER: Public vs Private
Reminder that in most cases Teams, SharePoint and Stream content should be set to Private rather than Public or visible to Everyone in my organisation. If content is set to be accessible by Everyone in my organisation, this will make the content viewable by every user on the NHSmail shared tenant which is unlikely to be appropriate in most cases.
As you will all be aware, we have the privacy notifications in place that are triggered when any Teams, SharePoint or Streams content is change from the default Private setting to Public and notifies both LAs and the content owners. However, we are still seeing quite a lot of the content that is being set to Public and then left as Public. It is the responsibility of LAs and content owners to review and act on any privacy notifications received.
To try and help organisations with this we will be sending out some additional comms in the near future to give organisations a better picture of their numbers in this space.
Current guidance: Private vs. public settings in O365 – NHSmail Support
Privacy monitoring: O365 Privacy Monitoring – NHSmail Support
REMINDER: SMTP on user accounts
Another quick reminder that SMTP should not be enabled on standard user accounts. If you have an account which requires SMTP to be enabled, this needs to be converted to an application account prior to SMTP being enabled.
Accessibility Testing Volunteers – Portal Refresh – Last Chance!
We still have a few places left for Accessibility testers for the Portal refresh project, but they are filling up quickly.
If anyone on this call would be interested in taking part in this, please contact Hafsa (hafsa.hersi1@nhs.net) directly to register.
VN162 User Secret – New Users – presentation (see recording for full details)
Findlay Release – 22 May 2023 – Findlay Release – Content Summary – NHSmail Support
The Findlay release was successfully deployed on Monday 22 May. This release was largely aimed at completing further preparatory work ahead of the platform-wide MFA changes that will start rolling out from July.
Couple of key items to note include:
- A bug fix to improve the MFA reporting in relation to the Authentication Type information that is present in the current report.
- A new onboarding flow for the M365 E5 licence to enabled organisations to onboard this licence type.
- Improvements to the telephone field to allow extension numbers to be added.
Basic Auth Deprecation
Thank you to all LAs for the work they have put in to prepare their organisations for the basic auth deprecation and remediate affected accounts as needed.
Portal Issue – LA functions
Details of the issue whereby an error message was being throw when LAs trying to undertake certain LA functions on 23 May.
INC35997807 – Portal Local Administrator Functions – RESOLVED – NHSmail Support
Relay issue – Delayed delivery –
Details of the email delivery delay issue also identified on 23 May impacting various external and internal domains.
INC36002954 – Delayed Email Delivery – RESOLVED – NHSmail Support
Public vs Private
Reminder that in the majority of cases Teams, SharePoint and Stream content should be set to Private rather than Public or visible to Everyone in my organisation. If content is set to be accessible by Everyone in my organisation, this will make the content viewable by every user on the NHSmail shared tenant which is unlikely to be appropriate in most cases.
As you will all be aware, we have the privacy notifications in place that are triggered when any Teams, SharePoint or Streams content is change from the default Private setting to Public and notifies both LAs and the content owners. However, we’re still seeing quite a lot of the content that is being set to Public and then left as Public. It is the responsibility of LAs and content owners to review and act on any privacy notifications received.
To try and help organisations with this we will be sending out some additional comms in the near future to give organisations a better picture of their numbers in this space.
- NHSmail Roadmap – NHSmail Support has been published with addition of Microsoft Defender for Endpoint slides
- Overview of the new elements of licence agreement for example: audio conferencing.
- Basic Authentication Deprecation – NHSmail Support progress update
- Conditional Access for the MFA progress update
- Accenture Team update
General updates:
- Basic Authentication presentation covers how users can register their applications to use OAuth 2.0; how users can configure their applications depends on the software they are using.
- Brief Service management updates: Multi-factor Authentication abroad update,
- A reminder that the Teams Rooms Licencing expiration date is July 1st
- A reminder about the GP telephony deadline expired on 30 April 2023 and is now following a 30-day grace period
- Bulletins and communications – NHSmail Support – latest bulletin can be found here
- Latest LA bulletin is available on NHSmail support pages
Technical Architects updates:
- Roadmap now includes MDE changes and updated application approved/rejected
- Basic Auth deprecation updates for EAS/RPC
- GP Phone System decommissioning
- Security Groups work has begun; delivery is planned in 3-4 months.
- Self Service Password Reset – status – work in progress
Other information:
We will establish a page for events that are taking on in the NHSmail team. Various Deep Dive sessions are available on the NHSmail support pages and are listed below.
- Intune,
- Phone System Deep Dive
- Conditional Access Deep Dive for Bring Your Own Device
- Planning TanSync Deep Dive for June/July
Infrastructure Upgrade 21-23 April
Information – Planned Infrastructure Upgrade (NHSmail Datacentre) – Postponed – NHSmail Support
Updated note: this upgrade has since been postponed and new notifications will be added to the Announcements section of the NHSmail support site closer to the new dates.
Guidance regarding the relay config – https://support.nhs.net/knowledge-base/relay-configuration/
VN121B Release – 13 April 2023
The VN121B release was successfully deliver last week.
This release included a fix for the Multifactor Authentication (MFA) disablement bug mentioned on the previous session and after a period of monitoring post-release we can confirm that fix included in the release has resolved this issue.
The release also included a fix for the MFA status report issue we saw around the report timing out and not running for organisations. We have also been monitoring this since the release last week and can confirm that the timeout issue is resolved. We are aware that there are one or two tickets from organisations about this report, but these do not appear to be related to the timeout issue that the release fix was targeting and are being picked up separately
Portal Issue / Microsoft Global (SMB) Issue / Email Send Issue
We’ve had 3 key issues this week affecting the service, all of which are now fully resolved.
Further details on each can be found on the announcement links below:
- Portal Slowness:INC35358395 – Portal Slowness – RESOLVED – NHSmail Support
- Microsoft Global Issue (NHSmail impacts):
INC35398047 – Shared Mailbox Access Issue – RESOLVED – NHSmail Support - Intermittent email send issue to Microsoft email addresses:
7016347354 – Issues Sending Mail to Microsoft Email Addresses – RESOLVED – NHSmail Support
Public vs Private
Reminder that in the majority of cases Teams, SharePoint and Stream content should be set to Private rather than Public or visible to Everyone in my organisation.
Current guidance: Private vs. public settings in O365 – NHSmail Support
Privacy monitoring: O365 Privacy Monitoring – NHSmail Support
MFA Update
Update: the NHSmail MFA policy has now been published: NHSmail MFA Policy – NHSmail Support
Next webinar – Basic Auth demo – 5 May 2023
We will also have a demo on the next webinar around the basic auth process that will cover the use of both in-house and third-party applications that need to register with Azure Active Directory ahead of the basic auth deprecation deadline in June
Infrastructure Upgrade (Hemel) 14 April – 15 April –
Information – Planned Infrastructure Upgrade (Hemel Datacentre) – First Notice – NHSmail Support
Work will begin at 19:00 on the Friday and similar to the recent Slough upgrade, there will be 3 notices to raise awareness on the support site beginning from Tuesday 11 April.
During the change window, all traffic will be re-routed to the active data centre to ensure there is zero-impact on NHSmail users.
Please note that any remote organisations that use direct IP addresses rather than DNS to access the email gateways my potentially lose service during the upgrade activity. If you believe that your organisation is using direct IPs for any system config, we would strongly advice that these are changed to use our standard DNS settings to prevent any loss of service. The following guidance shows how this change can be made: https://support.nhs.net/knowledge-base/relay-configuration/
If changing to use DNS is not possible and significant end user impact that could potentially result in clinical risk during the change window is identified, please contact the Helpdesk for further guidance.
Whilst we expect there to be zero impact to end user, we would advise that you ensure that your service continuity plans are reviewed in advance.
High-Send Solution Issue (30 March) – INC35069133 – High Send Authentication Errors – Monitoring – NHSmail Support
This issue is fully resolved and the high-send solution is operating as normal. Full details of the incident can be found on the Announcements page.
Portal Slowness Issue (4 April) – INC35148773 – Portal Slowness – RESOLVED – NHSmail Support
Intermittent Portal slowness issue affecting the User Management section. This appears to have been a transient issue and no further impacts have been seen since.
MFA issue
Issue identified whereby a small number of platform uses have had MFA disabled as the result of a bug. An interim solution is now in place that will run every 30 minutes during the working day to reapply MFA to any users who have been affected by this.
Please note that this only impact users who fit a specific set of criteria and have also had MFA enabled via either their LA or self-enrol. Users with role-based MFA or who have had MFA enforced by the compromised account process remain unaffected.
A high priority permanent fix is under development and will be released as soon as possible.
Telephony Deep Dive – Reminder
Reminder that the Telephony Deep Dive session will take place on 17 April.
Form to register interest – https://forms.office.com/Pages/ResponsePage.aspx?id=slTDN7CF9UeyIge0jXdO48nRfTTqG_pEn5qR_xNEMv5UQlhPRFpWQ1lFWTBNMzdGUDExMlA0UTlNRSQlQCN0PWcu
Basic Authentication Deprecation
Update provided by David Middleton
SSPR demo
Overview provided by Hector from the Accenture team.
TA Update
Reminder that the legacy alluser groups will be removed later in the year. Organisations should review all uses of these groups to ensure that the new version is being used.
Platform-wide MFA
Update provided by Jess Davenport.
Technical Update:
- Basic Authentication Depreciation reminder about upcoming changes
- Phone system launch and deep dive webinar planned for 17 April 2pm-3.30pm.
Centre of Excellence:
An overview of the NHSmail Solution Store – an app that aims to encourage collaboration and share best practice
Multi-factor Authentication (MFA):
INC34945419 – Multifactor Authentication (MFA) Prompt – RESOLVED – NHSmail Support
It has been confirmed that the issue has been caused by a recent update applied to a section of Microsoft infrastructure responsible for regulating user geo-location.
MFA report – looking to fix in early April and will exclude deleted permanent accounts
Angela Goody from NHS HERTFORDSHIRE AND WEST ESSEX ICB – produced a video on XLOOKUP, this demo is for the MFA report and mailbox report and how best to utilise them both – Thank you very much for your support.
The next LA webinar will be held on Thursday 6 April and will include an overview of the new Self Service Password Service.
Technical updates:
The dates for the retirement of the EAS and RPC, EWS, POP, IMAP, and RPS protocols and the implementation of Basic Authentication have changed.
Please refer to the Basic Authentication Deprecation guide on the NHSmail support sites if you’re interested in learning more about the implications for your organisation.
Telephony update
INC34485546 – Scan to E-mail Delivery Delay – CLOSED
After mail delays and discussions with our third-party supplier, we changed the configuration of Relay to improve peak processing stability and efficiency. These modifications have eliminated mail delays. We appreciate your patience and apologise for the inconvenience.
Fast track availability reminder:
Until June 30, 2023, the NHS will be able to take advantage of the Fast Track tool for migrating personal and shared data to OneDrive for Business and SharePoint Online. Please see NHSmail FastTrack File Share Migrations | Requirements – NHSmail Support for further information regarding this service.
Centre of Excellence:
Update on Power Platform Data Lost Prevention Policy changes which can be found on NHSmail support pages Power Platform Guidance – NHSmail Support
New features and improvements for the Asset Booking Tool implementation process are on the horizon. Information on how to do this can be found on the NHSmail support sites dedicated to the Desk Booking App.
Multi-factor Authentication (MFA) update:
An up-to-date explanation of the issues affecting the MFA report and the proposed iterative approach to fixing them by combining the data from the Mailbox Report and the MFA report is now available. For more info, check out NHSmail Support Pages about – MFA Status Report
To further ensure the satisfaction of LA Webinar attendees, MFA will be added as a regular agenda topic.
Other information:
NHSmail all user survey: Please thank everyone who helped spread the word; we got almost 58,000 answers; this is fantastic!
On March 21, 2023, we will be disabling Yammer’s public Storylines to reduce spam communications.
Service Updates:
Portal Access issue – 20 February – Resolved
INC34412483 – Portal Intermittently Inaccessible – RESOLVED – NHSmail Support
Intermittent Portal access issue occurred on Monday 20 February causing an error when users attempted to log in.
MS Bookings issue – 14 February – Resolved
INC34265287 – MS Bookings Admin Functions – RESOLVED – NHSmail Support
Issue with MS Bookings preventing users from adding or amending Bookings calendars within the NHSmail Portal.
Release updates:
Dickson release delivered on Thursday 2 March – Dickson Release – Content Summary – NHSmail Support
Key items:
- PnP update – functionality returned to the platform for use by LAs.
- My Approvals performance update – 58913
- Guest Inviter view update – 47507
- MAC email notification updates – 70222 / 70928
The service will be moving to a new release cadence post-Dickson that will see smaller releases being delivered on a shorter cycle to ensure we get new features out onto the platform sooner.
Service Reminders:
Old NHSmail Power Platform default environment decommissioning
Reminder that the old NHSmail Power Platform default environment has now been decommissioned in full.
Information – Power Platform Old Default Environment Decommissioning – NHSmail Support
NHSmail access from outside the UK
Also a reminder for anyone who wasn’t able to make the last webinar, that we have recently made changes to NHSmail access from outside the UK and recommend that organisations ensure that MFA has been enabled on accounts prior to users leaving the UK if NHSmail access is going to be required.
Information – NHSmail users working outside of the United Kingdom (UK) – NHSmail Support
NHSmail annual survey reminder
Final reminder from me that the NHSmail annual survey is now live for responses and will be open until Friday 10 March.
We’d like to encourage as many people to respond as possible as the more feedback we get from yourselves, the more we can improve the service to meet your needs.
https://survey.nhs.net/nhsmail-user-survey-2023/
Other Key Updates:
- MFA Update – platform-wide enforcement announced.
- REMINDER: BYOD Technical Deep Dive session (28 February) – Bring Your Own Device Security Controls | Overview and Deep Dive Webinar – NHSmail Support
Telephony capability overview
- Delivery delay issues
Two issues with delayed delivery of emails either to or from external domains this week
The first issue occurred on Monday and only had intermittent impacts which were very minor. The issue was resolved quickly, and the queues completely cleared by close of play on the same day.
Further information here: INC34183362 – NHSmail Delivery Delay – RESOLVED – NHSmail Support
- The second issue occurred on Thursday and further details can be found here: INC34243035 – Mail Delivery Delay – RESOLVED – NHSmail Support
- Old NHSmail Power Platform default environment decommissioning
Information – Power Platform Old Default Environment Decommissioning – NHSmail SupportUpdate regarding the old NHSmail Power Platform environment which will be decommissioned from this week.This should have minimal to no impact on organisations as the new default environment with updated data residency in the UK has been in place since September 2022. Any specific PowerApp users who will be affected have been contacted via target comms over the last few weeks with details of any actions required.
- NHSmail access from outside the UK
Information – NHSmail users working outside of the United Kingdom (UK) – NHSmail SupportPlease be aware that a change was implemented on Friday evening (10 February) that will require any users attempting to access the service from outside the UK to have MFA enabled on their accounts.
- NHSmail annual survey – will go out this week for users to respond to.
- Chatbot walkthrough & demo – Accenture team
- Deskbooking App walkthrough – Centre of Excellence team
- Teams Delete Status Portal issue – resolved
On Tuesday of this week, we had a recurrence of Teams showing as deleted in the NHSmail portal, which has now been resolved.
Please take into account that the problem on Tuesday was only cosmetic, and there was no loss of Teams or Teams data at any point.
Full details – INC33938944 – Teams Group Status – UNDER MONITORING – NHSmail Support
- Microsoft O365 issue – resolved
Those on this call will also be aware that there was a global Microsoft issue this week that may have impacted your users’ access to O365 services.
This incident has been fully resolved and details can be reviewed on the support site:
- Portal slowness issue – resolved
On Wednesday morning, we experienced a brief intermittent issue that caused Portal slowness for some users.
This was quickly resolved with little disruption to the service.
Full information can be found on the Announcements page – INC33981101 – Portal Slowness – RESOLVED – NHSmail Support
- Multi-Factor Authentication (MFA) Number Matching
We enabled number matching for all users of the Microsoft Authenticator app on Thursday evening (25 January 2023).
This is to ensure the change is managed closely, prior to the enforced change by Microsoft starting 27 February 2023.
Number matching is a key security upgrade to traditional second factor notifications in Microsoft Authenticator.
When a user responds to an MFA push notification using the Authenticator app, they will be presented with a number. They need to type that number into the app to complete the approval.
We expect this change to have no negative impacts for users and any issues should be reported to the Helpdesk.
We have also updated our current guidance to reflect the new number matching capability and the guidance can be found here:
Getting Started with MFA – NHSmail Support
- NHSmail access from outside the United Kingdom (UK)
We would also recommend that MFA is applied to the accounts of any users who may have a valid need to access their NHSmail from outside the UK as permitted by your organisation’s own local policies before they leave the country.
We do not recommend that users access their account via non-corporate VPNs when outside of the UK as there is a risk that their access will be blocked.
In the near future, we will be enforcing MFA on any connections to the service made from outside the UK. Where MFA is not in place, the user will be unable to access their account or any other NHSmail services.
More details regarding timelines for when this will be enforced will be added to the Announcement page of the support site shortly.
- Accessibility: Teams Live Captions
Please note that function to turn on/off Live Captions in Teams has moved and now sits under Language & Speech within the extended settings menu.
- NHSmail survey
The NHSmail survey is due to go out in early February.
General update:
- All user survey – the questionnaire will be released shortly
- Accessibility: Sign Language View – available now in Microsoft Teams
- Information Governance – update on number matching on the authenticator app
Technical update:
- New roadmap published: NHSmail Roadmap – NHSmail Support
- MFA, which will shortly be implemented, is necessary for access from outside the UK.Planning to change the default behaviour for new accounts to require MFA by default, and you will need to delete it if doing so puts your organisation at clinical risk
- The projects for conditional access and the phone system have begun and are scheduled to be completed in the first quarter of 2023. Thank you to everyone who responded to the deep dive survey, and please feel free to join the deep dive sessions as soon as they are announced.
- Legacy Security group housekeeping – allusers moving to allusersgroup.
- MMA – Microsoft management agent – deprecation in MDE
- Azure will no longer accept connections from older versions of the Windows Log Analytics agent, also known as MMA that uses an older method for certificate handling. The affected versions are Windows 7 SP1, Windows 8.1, Windows Server 2008 R2 and Windows Server 2012 R2/2016. The new minimum supported MMA version is 10.20.18053.0 Expected: February 2023
- Office 2013 will reach end of Extended Support on April 11, 2023. MC482560 | December 10 – This is a reminder to post (MC357842, April 2022): Office 2013 end of support: Reduce your exposure to security risks by moving to a newer version of Office. Office 2013 will reach the end of Extended Support on April 11, 2023. This means Office 2013 will no longer receive security updates, bug fixes, technical support, or online technical content support after April 11, 2023.
- Additional guidance in CVE-2022-41099 for devices with WinRE. Devices with Windows Recovery Environment (WinRE) will need to update both Windows and WinRE to address security vulnerabilities in CVE-2022-41099. Installing the update normally into Windows will not address this security issue in WinRE. For guidance on how to address this issue in WinRE, please see CVE-2022-41099.
Presentation from Erin Barrett on the Portal Modernisation work.
Update from Nathan Steven on the forensics change
Reminder: this is the last webinar until Friday 13 January 2023.
Final Local Administrator (LA) Bulletin of the year will be sent on Monday 19 December.
Culley portal release went in on the 8 December. The release notes are available on the NHSmail support pages.
The NHSmail roadmap has been updated and is now available on the NHSmail support pages.
The NHSmail O365 onboarding partnership webinar and slide deck is available on the NHSmail support site for those interested in data migration options.
CIS2 – Reminder – NHSmail Services sign in page – Planned Upgrade – NHSmail Support
PLA – unable to assign a PLA, workaround is to ask the desk. KB article to be published shortly
Onboarding webinar on the 30th, open to any NHS organisation to hear about our on and off boarding offering from all suppliers. There will be a Forms to complete, invites for those registering an interest will be sent by 28th
Forensics output is to be changed – download direct from eDiscovery. Further update and guidance to be ready for next webinar
MFA – interim process for allocating MFA to more than 50 users in an org Interim Bulk Enable MFA process – Local Administrator (LA) Guide – NHSmail Support
NHS E/D merger – 6 January, brought forward from April. Everyone deals with change differently, we will continue to be professional but please be aware there is a likely 30 – 40% reduction in organisation size
Townhall – Slides will be published soon N365 Shared Tenant Town hall Events – NHSmail Support
Matt – tech update
Phil – SharePoint 2010 migration offering
Jess – MFA and a pilot around authenticator app
Tech update – Matt Brownhill provided an overview
Mailbox rules – now disabled when an account is compromised, please review them with the user before enabling
Safe Links/ Attachments – will be rolled out across the estate to all by 28th October, all user comms will be sent Monday. Existing applications accounts are excluded but new application accounts created after 28th October will be included.
MFA – thanks for those attending the webinar last week, recording is available. Please drive home the message to roll it out to your senior managers
Comms update – Chris provided a view of the comms route available to organisations and a couple of the planned comms next week
Portal release – expected next Tuesday, Self Service Password Reset will be re-enabled.
14th October 2022– Multi -Factor Authentication (MFA) webinar
NHSmail Collaboration Team minor changes have been made since the last webinar to improve the usefulness of the team and its associated channels, such as the NHSmail community support channel which has already been useful in highlighting a national issue.
SafeLinks Pilot – Safe Links and Safe Attachments are part of Microsoft Defender and will build on existing security features to protect NHSmail users from receiving and mistakenly interacting with malicious emails.
CSOC/Helpdesk interface improvements have been proposed to enhance the experience of LAs when accounts have been marked as compromised. This means the LA should know who to speak to within their own organisation when an account is compromised.
Basic authenication deprecation user comms sent via no-reply on 21 Sept to 74911 account users with legacy protocols identified as still being in place.
PLA comms will be sent on 27 Sept as a follow up.
TLS deprecation comms was sent on 22 Sept 2022.
Cotman release will be going ahead on the 27 Sep – Release notes are available on the support site – Cotman 1.0 Release – Content Summary – NHSmail Support
· Sarah Harding to give an update on the Auto expanding archive work
· Jess Davenport will cover MFA changes in the Cotman release
· TA updates from Zaheer Iqbal
· Hafsa Hersi to present a brief overview of the portal modernisation work
· Hector Pena Olarte to present on CIS smart card work
Teams end-to-end call encryption feature
This has been enabled within the tenant this week to add an additional layer of security to specific calls that may need additional encryption.
Teams is already secure, so this is an add on layer that users can switch on for one-to-one calls via their individual Teams instance.
Please be aware that both users involved in the one-to-one call have to enable the end to end encryption to access this feature.
We are also working with Microsoft to introduce live captions functionality for end to end encryption as this is not currently supported.
Inactive Accounts on NHSmail
As part of wider work we’re doing around aligning all account lifecycle activities on the service, we will be reducing the amount of time that accounts can sit in an inactive state from 90 days to 30 days in the near future.
This change will only apply to user accounts and application accounts will not be affected.
We’d like to encourage everyone to make sure that any accounts that are being used in your organisation for application account activities – including the bulk sending of appointment reminders and similar workflows – are correctly configured as application accounts on the NHSmail portal.
MFA newly created accounts/onboarding orgs
To ensure that our platform security posture fits with the current cyber security landscape, we are looking at introducing MFA as standard on all newly created accounts and for all onboarding orgs in the near future.
MFA – key user groups
As well as future planning around MFA, we would strongly encourage that all of you on this call consider applying MFA to certain key user groups – such as Finance, Procurement, HR and office-based staff – within your organisations straight away.
This will ensure that users in roles with a higher risk profile are better protected and this is also good first step towards preparing your users for any wider roll out of MFA in the future.
Teams Cloud Video Interoperability Service retirement – 28 October 2022
Reminder that the CVI service will be decommissioned on 28 October at 7:00pm
PLA/LAs for organisations who have made use of the CVI services have been contacted by the team.
NHSmail AD Sync Issue – INC31018469 – NHSmail AD Sync Issue – RESOLVED – NHSmail Support
Coombes release – Coombes 1.0 Release – Content Summary – NHSmail Support
Successfully deployed 11 August – full details of the release content can be found on the link above.
Welcome email update – Welcome new users to NHSmail – NHSmail Support
The Welcome email received by new users when their accounts has been updated and comes into effect as part of the release that went in last night.
New users will be redirected to a new support site area as part of the Welcome email that contains useful information on some NHSmail basics.
Disable MFA for 48 hours on compromised accounts – Disabling MFA for 48 hours – NHSmail Support
This will allow enforced MFA on a remediated compromised accounts to be removed for a 48 hour period where access is needed and the MFA cycle cannot be completed.
MFA will be reapplied to the account at the end of the 48 hour period.
Teams Cloud Video Interoperability Service retirement – 28 October 2022 – Teams Cloud Video Interoperability Service – NHSmail Support
This service was initially stood up to support organisations with the challenges of legacy VC equipment being in place and the interoperability of this with Teams during the Covid-19 response where virtual engagement became a key lifeline for the NHS. Over that period, we’ve seen a vast increase in the use of Microsoft Teams and a decision has now been made to decommission the CVI service on 28 October 2022.
Impact: any users who attempt to use the CVI service after 19:00 on 28 October will be unable to connect.
InTune update
Total of 129 organisations have now migrated to the new InTune model which is great news.
LA support site review – reminder LA support site review (Teams channel)
Reminder that we have a new channel in the LA Team for support site review contributions which has a terms of reference pinned at the top. This channel is very much designed to get your input on what support site areas that are frequently used by yourselves to support your users need our attention in terms of updates.
Chadwick release – Chadwick 1.0 Release – Content Summary – NHSmail Support
Successfully deployed on 7 July.
MFA enforcement on compromised accounts – Compromised Accounts – NHSmail Support
The Chadwick release introduced MFA enforcement on compromised accounts. This change is designed to enhance the security posture of the platform overall.
Please note that the NHSmail Helpdesk do not hold data on an organisation’s local security contacts as this is data held at organisation level. If you are unsure of who your local security team contacts are, these are typically the members of your organisation who are signed up to receive Cyber Alerts from the CareCert team.
Simulated Phishing Campaigns – https://digital.nhs.uk/cyber-and-data-security/training/simulated-phishing-training-tool
If your organisation is interested in running a simulated phishing campaign as part of cyber security awareness training for your users, the CSOC team are happy to work with organisations to do so. Please reach out to the team directly to discuss this further.
Security Deep Dive LA session
We will be running a specific LA-session focussed on the security posture of the NHSmail platform and the measures in place to ensure that the platform can be used for collaborative working across health & social care whilst remaining secure for the exchange of confidential/PID data.
ICS/ICB implementation – Phase 1
Phase 1 of the changes for ICS implementation is drawing to a close and we hope to complete the final batch of shortname changes w/c 18 July 2022.
To recap the changes that have been delivered as part of Phase 1:
- CCG organisation renaming to reflect their new role as sub-ICB locations.
- NHSmail GAL updates to rename all CCG GAL instances to reflect the new sub-ICB location naming convention.
- Shortname changes (part 1)
We are also currently in discussions with NHS England around the use if ICB level containers on the platform to ensure that any changes made align with NHS England’s overall strategic plans around this. We will provide an update to this group as soon as we have any further information to share.
LA support site review – LA Support Site Review channel
The NHSmail support site is one of the key resources for the platform and as a programme we work hard to keep this information as relevant and up to date as possible.
To enhance our current review process, we would like to involve the LA community in this to capitalise on your experiences of the support site as frequent users and those applying the information in the real world to help your users. We have created a new channel for LAs and PLAs to raise awareness of any support site content that needs attention.
This channel will focus on the following key areas:
- Out of date information
- Inaccurate information
- Missing steps within existing guidance
- Accessibility concerns such as information that cannot be accessed or clearly understood when using common accessibility tools such as screen readers. Or information within existing guidance that is in image or diagrammatic form that the does not have alt text attached, for example.
Full details on how to raise awareness of an article that needs attention for one or more of the reasons just mentioned will be pinned at the top of the new channel.
AUP update – Information – Acceptable Use Policy Update – NHSmail Support
The NHSmail AUP has now been updated which means that any accounts that have not accepted the AUP will be blocked from accessing Microsoft 365 applications until they have accepted the AUP.
Guidance on how to complete the AUP acceptance process can be found on the NHSmail support site: Acceptable Use Policy – NHSmail Support
Please note that it can take up to 2 hours for acceptance of the AUP to fully sync across the service.
Clinical Safety Case updated – O365 Shared Tenant Clinical Safety Case Report – NHSmail Support
Key updates include Section 4 and Section 5 regarding the AUP.
The hazard log has also been updated to reflect recent security enhancements that have been introduced on the service.
Microsoft FastTrack – NHSmail FastTrack File Share Migrations | Requirements – NHSmail Support
We are working with Microsoft FastTrack and Accenture to support organisations with the migration of local file share data (personal and shared) onto the NHSmail shared tenant.
Please note this programme is only available for a limited time with a set number of slots.
Acceptable Use Policy (AUP)
Presentation on the AUP changes. If you have not accepted the AUP after the update (completed 13 July) your access to Microsoft 365 applications, including non Microsoft 365 applications registered against Azure Active Directory will be blocked.
ICB/ICS
CCGs will be renamed to reflect their change to ICB sub locations and link them to their relevant Integrated Care Board, it may take some time to propagate across the tenant.
Licence top-ups for non-enterprise agreements
- New process allows these organisations to purchase a top up licence without the need for a Microsoft Enterprise Subscription Agreement
- All online and has a ‘catalogue’ of the approved licences for onboarding
- Microsoft licensing queries to come in to windows10@nhs.net
Centre of excellence published SharePoint best practice guide
Chadwick portal release due next week, MFA reminder
TA updates from Matt Brownhill
- Legacy browsers
- Basic authentication
- Solution to address the deprecation of TLS 1.0 and 1.1
Presentation from Nick Hall on Bookings and how that has helped his organisation.
Bird Portal release was implemented last night.
MFA on compromised accounts due w/c 4 July.
MFA mass enablement – foot off a little and is likely now NOT to rolled out by us but rather locally. We will be publishing our user research and suggestions to help you with discussions internally on how you may want to roll out locally within the next couple of months.
Company Communicator – starting a pilot for local orgs to use, contact us at feedback.nhs.net
New tool tip, aims to highlight first contact from a user that you do not usually receive email from. Helps to reduce phishing attacks/prompt for awareness. In place w/c 27th June –New anti-phishing safety tips – NHSmail Support.
Service Management updates:
Egress have combined their plugin with LFT after reacting to feedback, this is going through testing, a link will be provided and a support site updated.
Confirm that MFA is on compromised only accounts, this is just a recap of something that has been mentioned before. A date will be announced subject to testing. A support site article will also be updated.
Slough had a core switch and perimeter switch on 08/04/2022 which went through without issue, the Hemel On-Prem DC Core Switch and Perimeter Switch Software Upgrade will take place on the 6th May.
Revisited the escalations process
TA updates from Anne Anghelache
– Sensitivity labels coming soon coming around May – date to be confirmed
– Shared Channels
– Blocked filetypes
– Solution to address the deprecation of TLS 1.0 and 1.1
Data sensitivity – presentation from our Accenture colleagues Diulia and John
Viva Insight – presentation from Microsoft’s Jack Lauricourt
Digital Heroes – Digital Heroes – NHSmail Support nearly at our target of 3000
TLS comms – have been sent to over 1000 orgs to your PLA for the period 12-18 March 2022
CCG short name – written to every PLA impacted by the ICS creation
PLA role – should not be using an Out of Office (OOO) to state they don’t monitor their account
NHSmail Roadmap – has been updated. Please pay specific attention to the new Deprecation Roadmap, ensure you pass this detail to your infrastructure teams who would deal with this
NCSC Cyber Aware – NCSC.GOV.UK campaign, use three random words as a password. Already in our guidance, please re brief your user base
Security filters – amendments taking place, may result in NDR being received – Non Delivery Reports (NDRs) – NHSmail Support
MFA on compromised account – via portal release expected May
Slough DC – rescheduled work, due tonight
York release (key items)
- New system role: O365 Licence Admin (User Policy Management) – this role can add or remove users from a user policy on the system.
- Teams 1:1 call recording toggle (User Policy – 1:1 recording) has been added to User Policies and our recording guidance has been updated to reflect any relevant information around recording storage.
- Recent Log Ons (Recent Log On audit) – audit information available via the user management screen to help with the management of lock out events by showing details of all recent log ons including date/time, device and IP information, risk and result of the log on attempt.
- User Policy can be added as a searchable item in the User Management screen (User Policy search field option)
- Out of Office messages can now be set on shared mailboxes via the Portal (Shared Mailbox – OOO)
MFA enforcement for compromised accounts
As part of enhancing the security on the platform, we will be introducing a platform-wide change that will enforce MFA on any account that has been identified as compromised.
Please ensure that your organisation is aware of the MFA options available on NHSmail:
- Mobile authentication – Mobile authentication
- Authenticator app – Authenticator app
- FIDO – FIDO2 Guidance
We recommend that you encourage all your users to add a mobile number to their account where possible – this can be hidden from the Directory – to ensure they are able to access MFA should their account be compromised.
In instances where a mobile cannot be added to an account, the Authenticator app or FIDO tokens can be used.
Basic Auth Deprecation
Basic authentication will be turned off on POP/IMAP instances on the platform and we are working with Microsoft on this. Currently the timescales for this are October 2022.
We will be sending out comms to all relevant organisations and LAs around this starting from April which will include a data set showing the affected instances in your organisation and details of what actions are required.
Microsoft deprecation of TLS 1.0 and 1.1 in Azure Active Directory and ADFS:
As outlined in the LA communications sent in February, TLS versions 1.0 and 1.1. are no longer with the latest security requirements and are being retired. We strong advise that you start transitioning to TLS 1.2 as soon as possible to avoid any service impacts when TLS 1.0 and 1.1 are disabled on 30 June 2022.
We will be sending out further communications around this over the coming weeks and months.
Office 2010
Connectivity until 1 May 2022 – excellent work so far to move away from 2010, but we need a last concerted effort to move users off this. We’ll post a list of the top 20 organisations who are still using Office 2010 into the channel shortly for awareness.
TA Update
Topics covered:
- Deprecation road map
- Intune hybrid join
- Telephony via Teams project update
Guest Speaker
Accenture (Hector) – OneDrive Delegate Access capability
Joined by Egress on some initiatives they’ve been working on and an update of the security features of NHSmail, including compromised accounts and EOP
Compromised accounts – MFA will be enrolled onto all compromised accounts without exception
Portal release – on target for w/c 14th March, subject to testing. Currently includes EOL create accounts and user access to another user’s OneDrive for a period of 8 hours, one item to note it will give the delegate AND grantee access to the OneDrive. You need to set your own guidelines for this use, NHSmail will not be governing this
Outlook 2010 – issue with windows 7 and TLS 1.2 impact being not able to gain access. Please use the Easy as note here – Update to enable TLS 1.1 and TLS 1.2 as default secure protocols in WinHTTP in Windows (microsoft.com)
TLS Deprecation
Reminder of upcoming changes to the support for TLS 1.0 and 1.1 in Azure AD and ADFS. TLS versions 1.0 and 1.1 are no longer compliant with the latest security requirements and are being retired – as such we strongly advise that organisations start transitioning to TLS1.2 as soon as possible to avoid any service impacts.
Initial checks have identified that there are connections to business applications which are still using unsupported actions. Please ensure that you identify any users or applications within your organisation where unsupported TLS versions are still being used and ensure that appropriate actions are taken to transition these. Further guidance is available on the NHSmail support site.
The deadline for the deprecation is 30 June 2022.
Digital Heroes
As I know you’re all keen beans who like to champion technology in your own organisations, I wanted to make you all aware of the NHSmail Digital Heroes initiative.
A Digital Hero is a technology champion who will help colleagues improve their digital skills and provides training to those involved. This is a great way to help build peer learning networks in your organisations around Teams & O365. We’re currently recruiting for the first cohort which starts on 21 Feb and is open to 400 people. A further 400 people will be able to join the future cohort that is planned for March/April time.
People can sign up to take part via the NHSmail support site – Digital Heroes
Company communicator
Company Communicator will be pinned in Teams. This is something that was highlighted in the recent NHSmail survey as something that users would prefer to see rather than having updates appear as just another chat message in the list.
Local Company Communicator
We’re aware that some of you have asked about accessing your own local version of Company Communicator for use within your own organisations. This is now in the final stage of Technical assessment and we hope to be able to provide further details on when this will be available to you in the near future.
Office 2010 connectivity
Connectivity until 1 May 2022 – excellent work so far to move away from 2010, but we need a last concerted effort to move users off this.
We’ll post a list of the top 20 organisations who are still using Office 2010 into the channel shortly for awareness.
Any queries on this, please contact windows10@nhs.net
Brief SM updates:
Wellington 2.0 portal release, https://support.nhs.net/2022/01/wellington-2-0-release-content-summary/ support site summary released.
LA bulletin sent out 28 January – Local Administrator (LA) bulletin – 28 January 2022 – NHSmail Support one of the topics of which, is;
Microsoft Depreciation of TLS 1.0 and 1.1 in Azure Active Directory (AAD) and Active Director Federated Services (ADFS)
On 31 January 2022 Microsoft are planning to deprecate their support for TLS 1.0 and 1.1 in Azure AD (AAD) and Active Director Federated Services (ADFS). TLS versions 1.0 and 1.1 are no longer compliant with the latest security requirements and are being retired. We strongly advise that you start transitioning to TLS 1.2 as soon as possible to avoid any service impact.
TA updates from Mark Ward
Unsupported browser stats
Mailbox report – byte values will be changed to a more useful representation
New portal role for policy management under development
New app approval: Adobe Acrobat DC for editing PDF files is now available in Teams, but this is a licenced feature
Same Sign On – guest speaker from Accenture
Mark introduced John Anderson to discuss same sign on – PowerPoint to be shared
Company Communicator – pass on survey request to complete to your user base. Two reminders will be sent.
Password changes and LA comms – Application account letters are not going out with the mailbox id, this is being addressed in the point release due w/c 24 January.
More training is available – https://support.nhs.net/knowledge-base/n365-shared-tenant-virtual-training/
Portal release – The tentative date is W/C 24/01/2022 for a point release, this will be for the create account directly onto EXO that was descoped from Wellington. York Release is has tentative dates W/C 21/02/2022.
LA Bulletin – Local Administrator (LA) bulletin – 17 December 2021 – NHSmail Support
Portal release – delayed and create on Exchange Online is being de scoped due to identified issues during testing, hopefully due this weekend subject to successful testing
Teams Telephony – is being rolled out this weekend to support this NHS E/I/X initiative. Support site has all the relevant details listed and including contact details for GPs still wishing to register
New style meeting – restart on 14 January 2022 which will be agenda led. We really want to hear from you, your organisation and what works.
Training videos – N365 Shared Tenant Virtual training – NHSmail Support
Rekha provided update on Virtual Visits – Virtual Visits and Microsoft Bookings – NHSmail Support
Caroline will provide an overview of Teams Phone System and the implementation of that service for GP organisations only, guidance to be published early next week.
Shared mailboxes (SMB) – being marked as inactive if not sent an email in 6 months. Will move to inactive, please ensure SMB are actively used.
Visio Lite is now available across the tenant
Raised last week – Data mismatch between Portal and AD/Exchange – NHSmail Support
Raised last week about licences – worked with the organisation and issue is due to CSP not be a valid licence type.
Update for anyone in a CCG. A Live Event was held on 8th December, 2021 regarding potential changes to NHSmail as a result of the CCG/ICS reconfiguration. This has been sent to CCG PLAs, CIOs and ICS programme heads. The recording is available above.
Clinical safety case – published in full, https://support.nhs.net/article-categories/nhsmail-o365-shared-tenant-clinical-safety-case-report-and-hazard-log/
Egress – are finalising some how to/help videos, this will explain in more depth secure encryption, large file transfers as well as additional functionality that Egress provides, there will be around 5 videos in the coming weeks, we’ll post up an announcement in the collaboration channels when available.
Merger with NHS E/I and X – expected to be a lift and shift, this type of forum is vital to keep channels of communication open. No immediate change anticipated – https://www.gov.uk/government/news/major-reforms-to-nhs-workforce-planning-and-tech-agenda
ICB – look out for meeting invites over the next couple of weeks. Attendees will include all CCGs and ICB Programme leads
As a result of last week’s discussion and the submission of a couple of tickets we have been able to update and post the following – OWA/ Teams Display Name issue – NHSmail Support
OneDrive consumption report – data pulled direct from MSFT, ticket with them to understand why the duplicates – believed to be accounts that have been restored, pending their final feedback
MSFT training – the following is available Teams 100, Teams webinar, Teams Breakout. Link is here: N365 Shared Tenant Virtual training – NHSmail Support
Roadmap – will be published next week
Tech update
TLS versions – please be aware Microsoft plans to deprecate Transport Layer Security (TLS) versions 1.0 and 1.1 in Office 365 and Azure ADFS. We’re pulling out logs and will be contacting organisations impacted as soon as possible.
Power BI New workspaces
Meeting recording auto-expiry, not being rolled out
1:1 recording activating.
Call me button / External dial in to calls.
Exchange Plus addressing
SharePoint (Global and site) stores, Custom web apps, Teams app store, Office 365 add-ins, Term stores, – Self service approval request
Restricting exporting to excel – Power BI
Data Visualizer Add-in
Mindwave app
Salesforce
Stream (new) – looking to enable with the availability of the privacy alerts capability. Guidance is being drafted on this and how it is controlled via enabling/disabling recordings in the portal.
Accessibility – WCAG 1.0 – moving to WCAG 2.0 standards.
What do you do with the information from this meeting? Please ensure you cascade to all your team – up, down side wards via whatever briefing mechanism works best for you.
Hotfix for an issue identified Friday afternoon, Adam provided an overview but was fixed 16 November.
Wellington portal release – 14 December to include fix of various reports.
App store and requests discussed on last Friday’s LA webinar by Chris Kalko is now live and ready for use on Helpdesk Self-Service (HSS) – ServiceNow request process for Stores – NHSmail Support
Company communicator broadcast – due 17 November and will focus on digital tools
POP/IMAP legacy domains were retired Tuesday (9 November) as expected, limited tickets raised for this so positive so far. There was an unexpected issue related to send.nhs.net however, that was resolved by a DNS remap. Two organisations needed to amend their TLS.
Portal release –FIDO2 now live – FIDO2 and Point Release – Content Summary – NHSmail Support
FIDO2 had a couple of bugs that need to be resolved hence a slight delay, expected mid week next week.
Alluser.ods groups, Lisa and team will provide an overview, it is now Live across the tenant – Automated All Users Security Groups – NHSmail Support
POP/IMAP post changes testing identified an issue. Our mentality/risk appetite is to fix forward as far as possible but on this occasion need the RFC to be rolled back. Will be applied on Tuesday 9 November – Rescheduled Change – Retirement of legacy hostnames – 09 November 2021 – NHSmail Support
LA bulletin sent out 5th November – due to be published on support site: Bulletins and communications – NHSmail Support
Tech update:
308.0K people need to upgrade their browsers, the number is coming down each week which is good news. It would be awesome if it dipped below the 300k mark next week, let’s see what happens.
The Same Sign On project (Password Sync) that compliments TANSync is still on target to go live in November with early adopters.
Also of note this week, the Mentimeter app has been enabled in Teams, this app allows you to do live polls to get real time input during meetings.
Allusers.ODS will be going live shortly, join the meeting 5 November to hear more about this
Telephony SKU, will align to N365 national agreement, aiming for mid November to achieve target to roll out capability
Hygiene process. Please remember to ensure all accounts are logged into where needed to avoid any hygiene activities impacting on your accounts. The following will give you the detail needed – Data Retention and Information Management Policy – NHSmail Support
Legacy host name decom will go ahead as planned on Tuesday, 2 November.
TA update:
TLS versions – please be aware Microsoft plans to deprecate Transport Layer Security (TLS) versions 1.0 and 1.1 in Office 365
TPP, Vision and EMIS engaged with via GP IT future team on security standards and TLS version support.
Legacy browser
3.7% reduction.
MyAnalytics
This is being enabled and LAs will be able to turn it on for users via the portal. (user setting) – Due in the Wellington release.
Power BI
New configuration and article to be pushed – covers licencing, workspace setup etc. Changes include restrictions to exporting to Excel.
Estimated publication end of next week.
SharePoint configuration guidance
New configuration and article to be pushed – covers licencing, workspace setup etc.
Estimated publication mid November.
Encouraging and using Multi factor authentication.
FIDO 2 – Demo
https://support.nhs.net/article-categories/multi-factor-authentication-mfa/
https://support.nhs.net/article-categories/fido2/
ICB / ICS’s review of the year 1 summary from NHS X and ODS.
Analysis and impact assessment.
We’re working across NHS X and NHS E&I
We are working with all National NHS Digital services and the NHS Digital Enterprise Architecture Board to understand the impact and assess the changes.
22nd October 2021 – webinar cancelled this week, no recording available.
Legacy POP/IMAP hostnames decommissioning update (Guidance for Application Accounts (Legacy Hostnames))
We are currently targeting 2 November as the date for this work. This has been pushed back from the earlier September date as our reporting has highlighted that some accounts that are patient facing or linked to clinical systems are still using the legacy hostnames at this stage.
Please note that the 2 November date is the furthest extension we are able to apply to this decommissioning work and all relevant actions need to be completed by organisations in time for this deadline. If your organisation needs extra support to make the necessary changes, please engage with us via feedback@nhs.net at the earliest opportunity to discuss this.
The support site will be updated with further communications on this closer to the date and our IBC colleagues will also be helping to disseminate the communications around this.
DNS Service Disaster Recovery Testing (Planned NHS Extended DNS Service Disaster Recovery Testing)
To follow on from the update on 8 October, further Disaster Recovery Testing will be performed by the NHSmail DNS team on 16 October from 10:00am to 6:00pm.
This is being highlighted for awareness only as no service interruption is existing to occur.
If your organisation perceives that the testing has caused any issues, please contact your local support teams in the first instance. If any NHSmail related issues occur that you perceive as related to the testing, please raise a support ticket with the Helpdesk.
PowerBI auditing
Audit reports for Power BI are now available via the Forensic Discovery functionality on Helpdesk Self-Service.
Windows 10 update
Please refer to the recent email from Andréa via the Windows 10 mailbox regarding Windows 10 connectivity for full details on this.
Office 2010 connectivity
If your organisation is already on the NHSmail shared tenant, there is an agreed extension in place the Office 2010 connectivity until 1 May 2022. Please be aware that this only applies to connectivity and not support.
Support for Office 2010 ended in October 2020.
Office – critical vulnerability
Some of you will be aware of the critical vulnerability for Office suites highlighted as part of Patch Tuesday.
All supported versions of Office are covered by the Microsoft work to mitigate this.
Please note that this means the Office 2010 is not covered as this is no longer a supported version.
If you have any concerns around this specifically, please contact Windows10@nhs.net directly.
Tenant IDs
If you have not already done so, please send the details of your Tenant IDs to the Windows 10 mailbox (windows10@nhs.net) by 31 October 2021.
ICS update
To repeat previous updates on this, we are working closely with the NHS England and ODS teams on this
However, please be mindful that this is very much an NHS England directed project rather than an NHSmail one.
As soon as we have further information that is NHSmail relevant in this space, we will share this via our usual communication routes.
Please note that the NHSmail team will only be able to provide updates on any NHSmail related plans or impacts. We cannot provide information regarding impacts on other services or ICSs as a whole.
Company Communicator
A second Company Communicator message is expected to be sent out on Wednesday 20 October.
The message will focus on Privacy settings within the NHSmail shared tenant and link to current support site guidance on this: Private vs. public settings in O365.
We do not anticipate that this will have any impact on local service desks.
Events:
The date of the InTune webinar has now changed to Thursday 28 October 11-12:30.
You can register for the webinar here: InTune Webinar registration
TLS versions
Please be aware Microsoft plans to deprecate Transport Layer Security (TLS) versions 1.0 and 1.1 in Office 365
Legacy Browsers: a further 8% drop
We are aiming for a further 10% drop by mid December.
If you have specific concerns around moving away from legacy browsers due to specific supplier requirements, please contact feedback@nhs.net with full details of the supplier/system and your concerns.
PST File Migration
The Accenture PST migration service is now available.
The service can offer either a local onsite PST discovery or process an already identified list of pst files which will be imported into the users NHSmail email online archive.
If you would like further details on this service, please contact NHSMail.Central@accenture.com
Bit Titan – Onboarding:
Mig Wiz has been customised (available through all managed migration partners) to work with the RBAC model for NHSmail.
If you would like further information, please contact either Bit Titan directly or if the managed migration team at Accenture (NHSMail.Central@accenture.com)
Accessibility Standards
We can confirm that the NHSmail portal is WCAG 1.0 compliant.
We are currently actively working to make all elements of the NHSmail portal WCAG 2.0 compliant as accessibility for all of our users is of key importance to the service.
Shared Devices
We have been working with Microsoft on improving security on shared devices and enhancements to the use/storage of temp/cached files within the browser version of Teams in relation to kiosk mode.
This is currently being tested and the updated guidance around this will be added to the shared device guidance on the NHSmail support site.
Please note that it is crucial that organisations are following the current guidance around this: Using NHSmail on shared computers or unmanaged devices.
1 to 1 recording
We are currently working with Accenture to get this re-enabled within the NHSmail shared tenant.
Teams meeting auto -expiration.
With the migration of recording to OneDrive/SharePoint Microsoft have also introduced an auto-expiration setting.
However this is not currently in place due to wider Microsoft issues with this functionality.
We will work with Microsoft to configure this on the NHSmail shared tenant, however we will not be looking to automatically delete teams recordings.
MyAnalytics
This is being enabled and LAs will be able to turn it on for users via the portal.
MyAnalytics helps you set aside regular focus time for your top-priority work and track how your time is being used across each day.
Each of the insights produces by MyAnalytics are only visible to the user and not to their manager as it is designed to empower each user to better manage their time in a way that fits for their workload and wider wellbeing.
We currently expect this to go live across the platform as part of the next release.
Viva
We are currently looking for any details of specific requirements or use cases for MS Viva to potentially take this forward within the NHSmail shared tenant.
We have already assessed Viva Learning, which is – unfortunately – unsuitable in its current form for the NHSmail shared tenant.
If you have specific Viva requirements or use cases, please contact feedback@nhs.net with the details.
Power BI
We are working on updated and enhanced guidance around this that will cover key questions on workspaces, the new experience and other key topics that have been highlighted by this community via Feedback in recent months.
We currently expect the new guidance to go live from early November.
Re-enabling Stream
We are currently working with Microsoft and Accenture around re-enabling Stream across the NHSmail platform.
Further information on this will be made available via our usual communication channels.
FIDO 2
We are looking to deploy FIDO2 capabilities across the platform by mid-November.
We are hoping to demo the new FIDO2 capabilities on a future LA webinar.
App Enablements – In Progress
We are currently working on the enablement of the following applications within the NHSmail shared tenant:
- Verto
- Peoples Graph
- Mentimeter
- MedXPlanner
- Excel flow add-in
- Explorer functionality for Edge
- Pervasent
Phone system survey
Please refer to the link below to access the phone system survey that we are using to gather information and requirements around calling plan sizes as part of the development work for this within the NHSmail shared tenant.
Phone System – Calling Plan Sizing Survey
Only individuals who are registered with NHS England as GP locums via the National Performers List are able to be added to the National Administrator Service on NHSmail. Further information on the registration process can be found here.
Outside of the core NHSmail provision there is no further funding at this time for additional licences, however discussion are currently ongoing across NHSX and NHS England & NHS Improvement regarding this and we are unable to provide any further updates until these have been concluded.
The NHSmail DNS team will be performing Disaster Recovery testing of the NHS Extended DNS service on the 09th, 10th and 16th October between the hours of 10:00 and 18:00. No interruption to the Extended DNS service is expected during the planned Disaster Recovery testing. Due to the Extended DNS Service providing NHSmail ancillary services such as CVI, this announcement has been provided for awareness.
Your organisation may wish to review local BCDR plans though no interruption to any service is expected.
Since 1 April 21, we’ve hosted 14.515m calls and 32.244m meetings, fantastic achievement for us all in helping the NHS move forward in collaborative working
Invitation to the Intune Webinar on the LA channel
Advised ICS / ICB and ODS changes are being fronted off by NHS E/I with support from the ODS team. NHSmail team have no further info at the moment and cannot help with any calls or further updates at this time.
Licencing
Update provided by Andréa Perrot and Chris Hawes regarding licence anniversaries within the NHSmail portal.
HSSI (INC24165150 – HSSI – RESOLVED)
A severity 1 HSSI occurred on Wednesday 29 September which caused users to be unable to send emails from nhs.net to external email domains. This was due to a Microsoft security feature blocking external emails.
It is key to note that this problem did not affect nhs.net to nhs.net email flow or accounts using the high sending solution.
We are working with Accenture and Microsoft to understand the root cause of this issue and any next steps required to prevent future recurrences of this.
We have conducted an extensive period of monitoring since the issue was resolved and there have been no further issues with email flow from nhs.net to external emails.
Dumpster issue
Following the update on 24 September, we can confirm that reconciliation work targeting those accounts who had already reached or exceeded the maximum 100GB quota for the dumpster has been completed and these accounts are now all working as expected.
Further work has also been carried out targeting those accounts with dumpster quotas of 90GB and 80GB respectively to ensure that these do not experience the same problem.
All other accounts on the service – with the exception of those belonging to organisations subject to the Covid inquiry litigation hold – have had the updated data retention policy applied which will automatically remove any items older than two years from the dumpster to prevent it maxing out.
Please note that we do not expect to see a repeat of this issue, however, it’s worth being aware that the symptoms of this issue are the inability to delete items from a mailbox. The issue does not affect send/receive capabilities for an account.
Reminder: please ensure that you are encouraging your users to use Online Archive and archive content regularly. Where Online Archive cannot be used (e.g. shared mailboxes or users still using Outlook 2010), please ensure you have local archiving solutions in place and that your users regularly archive into these.
Company Communicator
Advanced note to make everyone aware that we will be sending out a second message via Company Communicator in the coming weeks. Further information around the specific date for this will be provided shortly to LAs.
Inactive accounts
Update provided by Accenture team.
TA Update:
Legacy Browsers
Currently there are still 328.2K users still accessing NHSmail via legacy browsers.
This is a reduction from 411k in mid-July, but there is still work to do in this space and we actively encourage you to work with your users and application providers to shift away from legacy browser usage.
This is currently expected to go live in November for early adopters and will allow organisations to sync their on-premise passwords with NHSmail in real time.
This capability enables two way syncing between NHSmail and on-premise passwords, allowing users to change either their on-premise or NHSmail passwords with a seamless sync between the two to update across both platforms reducing the number of passwords that users will need to remember to provide a better user experience.
Power Platforms
The following elements of the Power Automate Platform have recently been approved within the NHSmail shared tenant:
- Business Flow Processes – a business flow process is a series of ordered work steps that a user completes within a business process. These are designed to provide a guide to people on how to get a particular business process completed and provide a streamlined user experience.
- AI Builder – this provides AI models that are designed to optimise business processes. AI Builder enables the user of AI to automate processes and extract insights from the business data held/being used within Power Apps and Power Automate.
- Power Virtual Agents – these are adaptable AI chatbots within Teams. Power Virtual Agents enable users to build chatbots and include built-in natural language processing and no-code graphical interfaces. They are available via both the Teams app and the Teams web app.
Further information on all of the elements described above will be published on the NHSmail support site over the coming weeks.
ICS update
NHSmail will be working closely with the NHS England and Organisational Data Services (ODS) teams over the coming months on this topic.
A recent webinar session hosted by NHS England and the ODS team has provided a high level overview of the plans for this and it has been confirmed that there will be a transition year from 2022-2023.
During the transition year, the major change will be the legal closure of CCGs and this will mean that they are marked as closed on both the ODS and NHSmail portals. Any existing commissioning arrangements will remain in place during the transition year.
We will provide a further update on this as we receive more information from NHS England and ODS.
Alluser.ods group update
To follow on from Matt Brownhill’s update on 17 September on this topic: the creation of new alluser.ods groups has been paused whilst the new functionality for these is being developed.
This means that no new groups will be created by the Helpdesk team until the new capability goes live. Our current expectation is that this will be fully available from December.
If you already have an alluser.ods group set up for your organisation that is empty, we recommend against using this prior to the new capability being available.
If you already have an alluser.ods group set up for your organisation that is populated with users and experience any issues with it, please contact the Helpdesk team to raise a ticket for the issue to be investigated.
Litigation hold clarification
To clarify what has already been stated on this topic, the total number of organisations who are affected by the litigation hold is nine: NHS England & NHS Improvement, NHS Digital and all Commissioning Support Units.
If your organisation does not fall into any of the above, this does not affect you and there is no need to have any concerns with regard to this.
Dumpster issue
We are currently working with Accenture on this issue as we know it has affected a handful of organisations on the service.
Current guidance is three-fold:
- Encourage your users to make use of Online Archive and archive regularly.
Outlook users who struggle to find set time to archive regularly may benefit from having quick steps set up that include an archiving command. - If you have shared mailboxes that are dealing with high volumes with emails, we advise that content from these is archived locally on a regular basis to ensure they stay within quota and do not encounter the dumpster issue.
- If the above two steps have already been put in place and actively enforced and you are still encountering issues, a secondary mailbox can be created with forwarders in place from the original in the short-term.
Reminder re: Office 2010 extension for N365 Participation Agreement orgs
Quick reminder that all organisations who signed the N365 Participation Agreement have an extended deadline for Office 2010 connectivity until 1 May 2022.
Teams connect
We’re aware that Teams Connect is currently the future direction of travel from Microsoft in the Guest Access/Teams federation space.
A further update on what this means in terms of the NHSmail shared tenant will be provided shortly.
Company Communicator:
Brief update to say that we currently expect the first message from this will begin to appear from 3:00pm on Friday 24 September.
Indefinite hold updated across the Platform for those organisations in scope, working with each now to address the scope and next steps. Hygiene activities across the platform are being updated with Active/Inactive app settings now being included. SharePoint Online site capacity comms about to start with the top 20 site owners/org, for changes to be made. OneDrive/SharePoint reporting tests being carried out – to verify recent examples of data being incorrect. EMS/Intune updates provided by TA’s. Telephony updates provided by TA’s. Mailbox quotas and dumpster updates. ICS Planning with NHSE/Microsoft ongoing – with workshops being planned.
Point release: Vulcan portal release is unfortunately pushed back a week and is pencilled in for the week commencing 6 September.AUP update: Tied to the Vulcan release is the change to the portal to include the new AUP which includes overseas use.Legacy Hostnames: An FAQ has been created, the support site will be updated with this shortly.NHSmail Roadmap: The NHSmail Roadmap is now available on the support pages – https://support.nhs.net/knowledge-base/10230/. 1:1 calling: Having spoken to Accenture, and by extension the O365 team, the position is that the option has never been available. We require further evidence to progress this. Currently investigation is being raised by TDA to understand why it was disabled by default and the impact of re-enabling.
Teams iOS support for version iOS 13
Microsoft will be retiring the Teams mobile support on iOS version 13 and below. We recommend that users upgrade to newer iOS builds.
Key points
- Timing: The retirement will begin in early October and is expected to complete by mid-October.
- Action: Instead of using iOS 13 or below, we recommend updating to OS versions 14 and above.
How this will affect your organisation:
The exiting Teams build 3.17.0 will continue to work on iOS 13 devices but there won’t be any app updates going forward. In addition to this, you will not be able to reinstall the build from the app store if you uninstall Teams or reset your device.
Online Archive – Auto Archive Policy
There are now 1 and 3 month options in addition to the existing:
Personal six month move to archive
- Personal 1 year move to archive
- Personal 5 year move to archive
- Never move to archive
Early onboarding of iOS and Android – | August |
GA for iOS and Android | September |
Early onboarding of Windows 10 Domain joined and Hololens 2 | August |
GA for Windows 10 Domain joined and Hololens 2 | September |
Early onboarding of Windows 10 Hybrid Join | October |
GA for Windows 10 Hybrid Join |
EMS dates still on track, if you have any questions please get in contact with Feedback.
Browser stats
370.5K users working in Microsoft 365 online services on Microsoft Edge Legacy (unsupported) and Internet Explorer.
Sev 2 incident Tuesday 17 August (INC23223179 – Delayed email delivery from external domain – RESOLVED). Issue is resolved and the backlog which hit 1.3million at its height was cleared within 4 hours. Legacy Hostnames Guidance (Guidance for Application Accounts) – Guidance contains details of which hostnames will be retired on 7 September as well as key information on use cases associated with the following: Updated Teams meeting recording guidance (Recording Teams Meetings) Permanently deleted accounts – Email addresses attached the permanently deleted accounts cannot be reused. Permanently deleted email addresses have never previously been recycled so this a consolidation of guidance rather than a change in behaviour. Unsupported browser comms – We’re aware that some of you have received blank attachments and the team working to get this corrected ASAP. If you are someone who has received a blank file twice, please contact Feedback and we will pass this to the relevant person on the team for them to respond to you with a new file. External federated groups – External federated groups are an additional element of Guest Access and are not in any way related to Teams federation. What an external federated group allows you as the requestor organisation to do is dynamically manage guest access invites for multiple external users from the same domain in bulk. The support site guidance will be updated to remove the confusion that is currently being caused around this at the moment.
Calendar federation process overview.
EMS update for early adopters – Provide progress on Hybrid Join/Co-Management, Overview of BYOD and EMS
Update on Phone system deployment – solution options, early adopter interest
End of life support for Microsoft 356 App.
App enablement within the NHSmail shared tenant All app enablement requests should be submitted via Feedback and go through a technical assessment before any decisions around enabling or not enabling them are made. Further information on the technical assessment process can be found here: Application Hurdle Assessment. Disabling accounts for maternity/long term sick (Disabling a user account) Reminder that it is considered best practice for all accounts for users on either maternity leave or long term sick (or other long term leave) should be marked as disabled in the NHSmail portal by Local Administrators. Calendar federation The technical guidance for calendar federation has recently been updated on the NHSmail support site to include better differentiation between what is needed to federate between Exchange Online and Exchange on-premise instances. The updated guidance can be found here: NHSmail calendar federation partner guidance A full overview of the end to end process to request calendar federation will be provided on 20 August webinar. Legacy hostname – PLA comms sent week ending 6 August. Legacy hostname decommission will take place on 7 September 2021. TLS versions Please be aware Microsoft plans to deprecate Transport Layer Security (TLS) versions 1.0 and 1.1 in Office 365. Legacy browsers Starting on 1 November 2021, minimum versions of Outlook for Windows you need to be using to be able to connect to Microsoft 365 services, such as Exchange Online. Office versions and connectivity to Office 365 services – Deploy Office | Microsoft Docs NHSmail roadmap A new version will be published on the support site shortly.
Intune Survey – Pipeline questionnaire. PST Ingestion Accenture’s PST ingestion service is currently on track from general availability from week commencing 23 August 2021. Supporting documentation will be made available nearer to the time. The testing for the BDS/Quest equivalent service is going through its final stages and we hope to confirm an availability date for this soon. General updates on migrations can be found here: FastTrack and tenant to tenant migration update – NHSmail Support. The following tooling has been review and approved: SharePoint Migration Tool (SPMT), Quest Essentials , Quest Content Matrix. Backup requirements A survey will be shared with organisations over the coming weeks to collate requirements for backup capabilities.
6th Aug 2021 – 1st half of the webinar
6th Aug 2021 – 2nd half of webinar
NB – due to a recording issue the webinar recording is in two parts.
Work over the coming 3 weeks on the infrastructure, no impact expected – Information – Planned Infrastructure Changes – NHSmail Support.Data Loss Prevention (DLP) INC22958107 – Incident – RESOLVED – NHSmail Support now resolved, root cause still being identified. Legacy host name decommissioning, 7 September – targeted comms to PLA with accounts using protocols have been sent. Intune – remember to submit your survey, detail on the support site and portal. N365 Shared Tenant Virtual training – NHSmail Support – available throughout August. N365 townhall recording published – N365 Shared Tenant Town hall Events – NHSmail Support.Intune comms – brief out to wider team. DPIA is published – brief out to wider team. New external email disclaimer. Tech update: Browser update – 385+ users still on legacy browsers, targeted comms to PLA expected next week. PST from accenture should be ready W/C 19 August, PST from Quest / BDS – updates will be provided in the coming weeks. Bit Titan GA W/C 23 August. EMS Adoption – Overview of scope of coming deliverables. Phone Systems – Overview of potential solutions for orgs including Operator Connect, Teams Calling plan and Direct Routing, more detail to be available at the next webinar.
PLAs – you can have more than one, two as a minimum to allow for contingency leave, sick etc Support site and Portal – update re InTune / To register your interest, please complete the NHSmail Intune Service Information Gathering survey. Onboarding Guide for Local Administrators – NHSmail Support. Legacy host name decommission – reminder to review infrastructure for services interlinking to NHSmail Updated Escalation and complaints – Complaints and Escalations Process – NHSmail Support. CVI issue fixed Monday – HSCN connections, this is confirmed as now fixed 10% mailbox reminder, take action to reduce – there is a cost implications to buy licences for larger mailboxes, use Online Archive.
Unsupported browsers down to 398k, was over 400k the last time it was mentioned a few weeks ago. PST ingestion service will be GA w/c 16 August. We are currently refreshing the TANSync documentation, no major structural changes, just bringing the versions of OS and SQL up to date HoloLens pilot project is mid-flight with participating organisations preparing their devices and licenses for use on the central tenant.
NHSmail recommended best practice that organisations monitor this for their users to ensure that they are not exceeding the 2GB per user per licence. This can be done via running the OneDrive Consumption report on a regular basis and using this to target users who are approaching this limit to work with them to reduce this. Typhoon 2.0 Release (Typhoon 2.0 Release – Content Summary): Key points: Change to O365 reporting schedule to move reporting refresh job from daily to weekly to align with Microsoft data refresh, Change of SharePoint locale settings to UK from US, Timeout error for O365 licence allocation error fixed. Teams Federation (Teams Federation – NHSmail Support) – Overview of new Teams federation process provided. Key points: Federation does not enable file sharing between individuals. Please refer to the following information on the different capabilities provided by Teams federation and Guest Access before raising your request: Introduction to team federation process and capabilities – NHSmail Support and Introduction to guest access process and capabilities – NHSmail Support. Azure B2B allow list requests will still be required for a federation to be successfully implemented. Where an organisation cannot raise this for themselves (due to having no NHSmail presence) this can be raised on their behalf by the Feedback team. Federation Partnering Agreement (FPA) needs to be completed and signed by a Director-level representative at the organisation who wishes to. Baseline compliance standard for Teams federation is DCB1596 secure email accreditation. Where this cannot be achieved, information on equivalent accepted standards can be requested from the Feedback team. Federation requests will be submitted to Accenture for background configuration in two batches each month on 7th and 21st (or the nearest preceding working day), so please ensure that FPAs and compliance evidence is submitted in advance to ensure it can be checked ahead of the submission date.
Point release: Typhoon point release will be out on the 20th however as with any release this is subject to change, release notes will be published shortly. Legacy Hostnames: Comms were sent out to LAs this week and next week we’ll be following up directly with organisations that have specific accounts that are linking in with the legacy protocols. MS teams rooms guidance: We’ve updated the MS Teams Rooms guide- an additional licence is required for setting up Teams room devices which wasn’t the case earlier. https://support.nhs.net/knowledge-base/adding-surface-hub-to-ms-teams/. Junk email: A standard update to the security patterns had the unforeseen impact of legitimate emails going to junk, many thanks to everyone who raised tickets, the supplier has now rectified the issues, whilst we’re on the subject of junk. HSSI details: The update from Microsoft for Root cause: A section of infrastructure, responsible for facilitating mailbox requests, was performing below acceptable performance thresholds. MS Teams Collaboration Invites have increased: As mentioned previously this as per design, an MS Business Impact Analysis has been sent to MS to request a design change and we’ll keep you updated on progress.
Browser stats – There are still currently 411k users utilising legacy browsers. CVI DNS fault – There are currently issues with some orgs attempting to use CVI over an HSCN connection. Accenture are investigating the issue. Teams Live Component is coming later this year – Fluid components in Teams chat allow end users to send a message with a table, action items, or a list that can be co-authored and edited by everyone in line and in the future will be shareable across Office applications like Outlook. Microsoft will begin rolling this out in mid-August and expect to complete rollout late August. We’re currently reviewing this new feature. Intune Survey is scheduled to be published next week. As mentioned in previous LA webinars,work is ongoing to deliver NHSmail Intune – a new, cloud-based centralised mobile device management (MDM) service. The NHSmail Intune solution will centralise device management under NHSmail’s Intune tenant, while maintaining a high degree of customisation, oversight and local autonomy for organisations. Testing is ongoing with general availability of the service planned for the near future. Priority for General Availability is being given to mobile devices (iOS/iPadOS and Android) first, with Windows10 and HoloLens2 to follow shortly after. If your organisation has not yet completed an expression of interest questionnaire, but is interested in utilising the service, please keep an eye on the support site as we plan to update the site with a link to the survey next week.
Point release due in the latter part of next week – this will cover some key updates regarding O365 reporting available in the portal. Further information will be published via the support site next week. Retirement of legacy hostnames/service URLs (Advanced Notice: Retirement of legacy hostnames/service URLs). Communications will be sent out to LAs regarding the retirement of legacy hostnames/service URLs in the coming weeks which outline the details of the hostnames being retired and any actions that are need around updating any relevant configuration details. The affected hostnames/service URLs will be permanently disabled on 7 September 2021. Regular reminder communications will also be sent. Company Communicator First message due to be sent out on Monday 12 July. Regular users of NHSmail teams will see this when they log in to Teams on Monday morning. Infrequent users will see this come through after a short time delay once they have logged into Teams for the first time after Monday 12 July. It is worth noting that this has now been re-badged as O365 Update and will be used in a similar manner to All User email communications that have been sent out by the central team to communicate information to the entire NHSmail userbase. Support site updates: Two key IG-related support site updates have been published this week: Joint Data Controller info – Joint Data Controller Tableand updated DPIA – Data Protection Impact Assessment. Please disseminate the above updated information to the relevant teams at your organisations as required. Teams federation: Teams federation is now live on the NHSmail service and the support site has been updated to reflect the new process. We would recommend that all organisations review the following intro video which outlines the capabilities provided by Teams federation and an overview of the process as a starting point: Introduction to Teams federation on NHSmail. Further support site information on Teams federation can be found here: Teams Federation – NHSmail Support. If you have any queries about Teams federation that are not covered by the existing guidance, please send these to feedback@nhs.net. Virtual Training: Additional Microsoft training session including one on the new Teams webinar functionality will be running throughout July. Further details are on the support site: N365 Shared Tenant Virtual training – NHSmail Support. Upcoming events: Partnership Collaboration Event on Friday 16 July at 10:00am. Professionalism: Polite reminder to all that we should all strive to treat our NHSmail colleagues (including those in the Feedback and Helpdesk teams) with the same professional courtesy and respect as we would expect to be treated with in return.
EMS update for early adopters – Any organisations interested in early adoption at this stage should contact the following email address: justyna.wolczyk@nhs.net. The current focus is on Android/iOS early adoption and Windows 10 domain joined. FIDO 2 tokens: A form has been set up to gauge interest/potential uptake of FIDO 2 tokens as an alternative MFA method along with any additional support that may be needed to help organisations enable this for their user base. The form can be accessed here:FIDO 2 survey.Update on phone system deployment -We are currently working with Accenture on the initial stages of phone system deployment within the NHSmail shared tenant. Further updates on this work will be briefed out on future webinars. Microsoft Security Update – Microsoft Security Update – Printer Spooler Vulnerability. Legacy browsers – We’ve had a further drop in numbers here, but still have a long way to go at this stage.
- Support site and Portal – new items
- Teams – NHSmail support site embedded within Teams
- Federation now available and new video/guidance to be published next week
- Remember the free Microsoft training that is available for the user base
- Covid public inquiry affecting solely CSU and a change in process to leavers and joiners for those organisations only
- Legacy host name decommission – look out for the LA bulletin due today and specific LA comms
Presentation on available options to onboard with Accenture provided by Andrew Pearson
Technical update from Matt Brownhill: Migration: Bulk creation of Sharepoint and Teams site to migrate into sites; and the Bulk application of permissions to those teams/Sharepoint sites or users OneDrive’s – exact availability dates are being confirmed for an automated service and for an interim solution. PST ingestion service – This has slipped and has been escalated at all levels. Alternative solutions products and suppliers are being progressed. RFC guidance for on and off boarding – Guidance and RFC form has been created and is being published on the Migration pages very soon. Offboarding Guidance is being produced. Further updates regarding other developments including FastTrack are expected in the coming days. Allusers.ods: We believe we have identified the issue and are working on the required remediation. Until then please do not use these security groups if you’ve had them created already. Timescales are to be confirmed but the intention is ASAP.Blocked filetype: Annual review is being completed and the permanent relaxation of media files has been proposed across all capabilities. Licences: Power Platform (no capacity SKU) – Being enabled. SP and OD additional Storage SKU. Being enabled. Bug fixes: Bulk import of users into a policy – will be part of next release. B2B requests disappearing – Root cause identified – re-working the validation logic. Reporting: The Office 365 usage reports are being changed to a weekly refresh frequency. Change should be applied next week. Browsers- Office Support: Starting on November 1, 2021, the following versions are the minimum versions of Outlook for Windows you need to be using to be able to connect to Microsoft 365 services, such as Exchange Online.
- Version 1706 of Microsoft 365 Apps
- Version 16.0.4600.1000 of Office 2016 (with the November 2017 Update, KB 4051890)
- Version 15.0.4971.1000 of Office 2013 (Service Pack 1 with the October 2017 Update, KB 4043461)
- All versions of Outlook 2019 should be able to connect to Microsoft 365 services, but only the most current version is supported.
Even though newer versions of Outlook 2013 might be able to connect to Microsoft 365 services, it’s not supported and you may encounter performance or reliability issues. Versions of Outlook that are newer than those listed, but aren’t the most current (supported) versions, may experience connectivity issues. To find what is the most current (supported) version, see the following articles: Below is the specific link to the Message Centre article. Office versions and connectivity to Office 365 services – Deploy Office | Microsoft Docs. Office versions and connectivity to Office 365 services – Deploy Office. Provides Office admins with information what versions of Office are supported for connecting to Office 365 services and the implications of using older Office clients.
NHSmail support site carousel update: Update to the carousel on the NHSmail support site expected over the weekend to provide direct links to CVI, Exchange Online and Public vs Private guidance. Support site embedded into Teams: This change is due to go in this evening and this can then be added by clicking on the 3 dots and searching for support site. Webinar registration form: Change to update the Teams webinar registration form also went in 24/06 to enable the ‘Everyone’ option. Organisations can now select this when organising meetings which have external attendees and all attendees from both inside and outside the NHSmail tenant will be required to complete the registration form. Company Communicator: NHS Digital will soon be making use of this tool to send out short messages to all nhs.net users within the shared tenant covering a range of key topics around the O365 platform and collaboration tools available on the service. Further details on this are due to be communicated out to LAs in the coming days. Teams federation: Still currently expected to be available from early July and an introductory video – similar to the Guest Access – including a process overview will be made available on the support site very soon. Interim licence allocation process: Interim licence reconciliation process – Local Administrator (LA) Guide – NHSmail Support. Bulk updates known error: Exception Error received when making bulk updates – NHSmail Support. Upcoming events: N365 Shared Tenant Townhall event will take place on Thurs 1 July at 10:30, Shared Tenant IG event will take place on Thurs 8 July at 14:00.
CVI > Now live and general availability: https://support.nhs.net/knowledge-base/teams-cloud-video-interoperability-service/. NHSmail roadmap: A new version will be published on the support site shortly. Migration: Bulk creation of SharePoint and Teams site to migrate into sites and the bulk application of permissions to those teams/SharePoint sites or users OneDrive’s – exact availability dates for both the interim solution and overarching automated service for this are still to be confirmed but we hope to have this in the near future. PST ingestion service – our expected timeline for this has slipped, unfortunately. We have escalated this to ensure that this service is made available as soon as possible to organisations and widened the scope of the products/suppliers being included in this as part of the work to make this available as soon as possible. RFC guidance for on and off boarding – guidance and RFC form has been created and will be published on the migration pages shortly. Further updates regarding other developments including FastTrack are expected in the coming days. Gateway The NHSmail gateway (malware and ant-virus protection ) is being upgraded which will allow segregation of NHS.uk and NHS.net mail-flows. This is due to complete within the next 6 months. Legacy browsers: 421.8K organisations are using unsupported browsers. This is a drop of 60K since last month, so well done to everyone who has been putting in work at their organisation in this space, but we still have some way to go to ensure that all users are accessing the service via supported browsers.
Online Archive (Exchange Online Archiving Guidance and FAQs – NHSmail Support). A new 6 month archiving policy now in place as per popular request. Further information regarding Online Archive can be found on the support site link above. Typhoon release – we are in ongoing discussions with Accenture regarding the Typhoon release and the reporting elements of this release is being treated as a high priority. Cloud Video Interoperability (CVI) – we are expecting the CVI team to present on this new capability on next week’s webinar.
CVI Testing of the new CVI capabilities which will allow organisations to make use of their legacy video conferencing set ups has gone well and we expect this to be generally available on the service in the coming weeks. Further information will be made available via the upcoming presentation and the NHSmail support site. Microsoft Teams Rooms on Windows version update: Changes to the Microsoft Teams Rooms application on Windows will take place on 28 June across the Teams service as a whole. The minimum application version requirement will be updated to v4.7.19.0. If the version of the application that your organisation is running is not updated to the new minimum version ahead of 28 June, you will be unable to sign in to Teams via the Teams Rooms application. Please ensure that all relevant devices are updated to the new minimum version. Further information can be found on the Microsoft website:
- Microsoft Team Rooms app version support
- Microsoft Teams Rooms Release notes
- Microsoft Teams Rooms maintenance and operations
- Manually update a Microsoft Teams Rooms device
Legacy Browsers
458k users are still currently using legacy browser at this stage which need to be updated. This is a 14k drop since 27 May, which is testament to the great work that LA teams are doing in this space. Keep it up and let’s see if we can get that figure down further by the end of June.
Sev 3 incident (INC21618413 – Incident- RESOLVED – NHSmail Support) Small number of users unable to use send.nhs.net. Issue quickly identified and investigated by Accenture. Fully resolved by 8pm on the same day after a period of post incident monitoring to confirm this.Typhoon portal release – 03/06/2021 (Portal – Typhoon 2.0 Release – NHSmail Support). Teams call recording issue – (Known issue: Teams call recording). Proactive work to resolve the Teams call recording issue continues and the fix for this was due to be tested over 4/5/6 June. Any further updates on the issue will be added to the support site information as they become available. Hygiene activities due to commence from this week. This will initially target the oldest Active ‘Leaver’ accounts which are eligible for deletion. Upcoming events: Fasttrack & Partnership Collaboration webinar – Fri 11 June at 10am – Please email feedback@nhs.net to request an invite to this session.
MS Teams Upgrade. Move away from Skype for Business to Teams due to take place on 19 August 2021. Any existing Skype for Business users will find that this is replaced by Teams at this point.
Actively seeking early adopters for iOS and Android at this stage. If you would like to register your organisations interest as an early adopter, please contact feedback@nhs.net.
Please note that the recording for 03 July is not available
Service updates: Severity 2 incident (INC21369143 – HSSI – RESOLVED – NHSmail Support). Delays to email being sent from external domains to NHSmail recipients. Incident investigated by Accenture & Microsoft engineers who identified an issue regarding the NHSmail domain being block listed. Issue resolved and full backlog cleared. Accenture are continuing to work closely with MS to put proactive measures in place to prevent this reoccurring and a root cause analysis is currently being worked through. Portal outage: (INC21379065 – HSSI – RESOLVED – NHSmail Support). Infrastructure issue caused a total Portal outage for 11 mins on Tuesday afternoon, but quickly identified and resolved by the Accenture team. Preventative actions have been taken by Accenture to ensure that this issue does not repeat itself. Teams call recording issue: (Teams Call Recording issue – NHSmail Support). An issue has now been identified and the support site information has been updated to reflect this. Upcoming events: IG Live Event – 3 June at 1:00pm and Fasttrack & Partnership Collaboration webinar – 11 June at 10:00am. If you’d like to join either event, please contact Feedback and the team will pass your details to the relevant event leads. Future functionality (service updates): Teams federation: Currently aiming to have Teams federation up and running for general availability on NHSmail by the end of June. Portal release – Typhoon: Next portal release is expected in early June (subject to the successful completion of testing). An overview of what will be included in the Typhoon release can be found here: NHSmail – Portal Release Schedule – NHSmail Support. Security groups: We currently expect the Typhoon release to include the alluser.ods security group functionality. Further guidance on how this can be requested will be published in time for the portal release.
Migration related: SPMT This has now been updated on the support site – FastTrack and tenant to tenant migration update – NHSmail Support. Quest Content Matrix and Essential tooling: Guidance for this is due to be published imminently. Migration related capabilities coming soon: Bulk creation of SharePoint and Teams site to migrate into sites, Bulk application of permissions to those Teams/SharePoint sites or users OneDrives, PST ingestion service, Self off-boarding guidance, RFC guidance for on and off boarding. Migration Tooling: Further updates on additional tooling and FastTrack offerings will be made in the coming weeks. O365 changes/updates: Online Archive policy enhancement: Request has been raised with Microsoft to enhance the online archive policy and provide a custom archive policy of 6 months. Teams changes: Teams auto recording will be disabled in the NHSmail shared tenant. Teams webinar registration page will be open to either external attendees or all attendees depending on how a meeting is configured.
Security and Governance: Legacy browsers – 482.3K identities are using unsupported browsers.
Early onboarding of iOS and Android – | July |
GA for iOS and Android | August |
Early onboarding of Windows 10 Domain joined and Hololens 2 | August |
GA for Windows 10 Domain joined and Hololens 2 | September |
Early onboarding of Windows 10 Hybrid Join | October |
GA for Windows 10 Hybrid Join | November |
Anticipated within the next 2-3 weeks for general availability.
We are beginning to look at the technical ability for us working with Jisc and GovRoam/.gov Wi-Fi so that access can be authenticated using NHSmail credentials at local organisations sites/buildings.
LA Bulletin (14 May) The LA bulletin went out last week Local Administrator (LA) bulletin – 14 May 2021 – NHSmail Support which included information on NHSmail shared tenant IG Community and Teams Channel, N365 shared tenant virtual training, 10% large mailbox quota update, Exchange Online archiving, specifically about Licencing expiry and renewal, Private vs Public settings and updated Junk Email guidance. N365 shared tenant live (27 May) – Next N365 shared tenant live event which is scheduled on Thursday 27 May at 10:30 was publicised in the Broadcast channel on how to register, may want to pass this detail over to other members of your wider team who would ordinarily attend these events. DPIA – The next IG webinar Thursday 3 June at 13:00 will focus on DPIA. Infrastructure changes – The infrastructure changes we’d announced on the Announcements page have now fully completed, effectively we are now out of the data centre. Typhoon release – New portal release is now expected in week commencing 31 May.
Portal Migration Azure AD on 15 May (NHSmail Portal – Planned Maintenance 15/05 – NHSmail Support)- NHSmail Portal migration to Azure AD due to take place on 15 May 2021. During this time, the portal will be unavailable and a banner announcement will in place to inform any users or LAs accessing the portal during the change window that it is temporarily down for maintenance. EXO account creation (15 May) -Interim EXO account creation change will also take place on 15 May. This change is the next step in moving account creation fully over to EXO and we recommend that LAs wait an hour between creating new accounts and making any changes to new user accounts to allow for them to migrate over to Exchange Online. Junk Mail ( Junk Mail Guidance Update – NHSmail Support) – New Junk Mail guidance now available on the support site which provides additional steps that organisations can undertake if they are seeing issues with false positives that will help resolve this issue. In addition to this, the Helpdesk team have also put in place a new minimum data set that will help to better capture and assess the scale of the issue in each case and provide the most appropriate support. Incident Procedure (Incident Procedure) A new guidance page has been published on the support site which outlines and clarifies the incident procedure for the NHSmail. This guidance should help to clarify the steps that the Helpdesk team take to initially triage incidents along with further information regarding RFIs and re-opening tickets if an issue persists after a resolution has been provided. Portal slowness – This issue has been investigated by Accenture and proactive monitoring continues at this stage. Email sending issues (Thurs 13/05) – The issue identified affecting sent emails for some users/organisations has been investigated by Accenture in liaison with the relevant third party supplier and a resolution is being actively put in place to ensure the affected emails are delivered.
SharePoint/Team sites now support both the classic & modern template experience. Teams meetings will now support up to 1000 members. Once the number of members in the meeting reaches more than 1000, Teams will automatically create a town hall style event. We are working on a process to bulk create SharePoint and Teams sites for orgs migrating into NHSmail. This is currently expected to be available to organisations from the end of June. The recent Microsoft notification regarding the default recording of Teams meeting will not be enabled within the NHSmail shared tenant environment.
Portal migration to Azure AD – On Sat 8 May the NHSmail portal will be unavailable for up to two hours whilst the change takes place and a banner will appear on the Portal during this time making users aware that the portal is down for maintenance. Sentry 1.1 portal release – announcement of the successful implementation for Sentry 1.1 to fix the duplicate toggle. Create new user/shared mailbox –during the same Portal Migration change window on Saturday 08 May, a solution is being implemented to the new user/shared mailbox creation process. An FAQ and Support site guidance will be published shortly. Autodiscover change –Brief mention of the Autodiscover change planned in for the Tuesday 11 May, this change is expected to be non-user impacting. A placeholder will be added to the Support site highlighting that NHSmail infrastructure changes are going ahead on the Tuesday. NHSmail process updates – Update that based on LA/user feedback, changes to process and supporting documentation relating to Complaints & Escalations, and the Clinical Safety incident process and Clinical Safety case are all planned to be uplifted on the Support site in the next couple of weeks, if not, sooner.
New reporting capability is being developed into the portal for Licence management – Apps for enterprise usage and user license allocation across the O365 licences and when the capability was last utilised. MyAnalytics – Concerns form IG and data protection being addressed before progressing further. SPMT – This has now been updated on the support site – FastTrack and tenant to tenant migration update – NHSmail Support. Fido 2 – Additional MFA capability being introduced and is targeted for end of June. Legacy Browser usage: past 30 days.
Important note: – the portal migration to Azure AD will now take place on Sat 15 May – NHSmail Portal – Planned Maintenance 15/05 – NHSmail Support.
Portal migrating to Azure AD on 8 May (NHSmail Portal – Planned Maintenance – NHSmail Support). NHSmail portal will be unavailable for up to two hours whilst the change takes place and a banner will appear on the portal during this time making users aware that the portal is down for maintenance. Duplicate toggles in user policies issue – A bug has been identified after the Sentry release which is causing an issue where by duplicate toggles are appearing in user policies. This bug may also be causing Teams call recording errors for some users. Both issues are under investigation by Accenture and a fix is undergoing testing for a potential future point release to resolve this. Toggle for non-admin user Teams creation – to request that this functionality is switched on for your organisation, please contact the NHSmail Helpdesk via helpdesk@nhs.net to request this and the team will enable this for your organisation. 10% 50GB mailbox allocations – review work around this will commence shortly and target those organisations who are using in excess of their 10% allocation. Communications to the affected organisations will be sent out in the coming weeks and further updates provided on future LA webinars.
Privacy Alerts – Overview of proactive and automated monitoring delivering alerts to LAs. EMS – Covered off updates on EMS project at a very high level including technical capabilities. Security Enchantments – Reduce NHS cyber risk, provide better intelligence to NHS by enhancing core security features.
Application hurdle assessment page has been updated to show the details of what has been enabled so far. This page will continue to be enabled with the details of hurdle assessments for any future enablements: Application Hurdle Assessment – NHSmail Support. Sentry release went in successfully on 21 April (Portal – Sentry Release – NHSmail Support). Teams Usage Report now live: shows Team Owners, number of members and number of guests within each Team that your organisation has created.Teams creation for non-admin users now live – Creating a team and adding owners or members and permission levels for non admin users – NHSmail Support. This functionality needs to be enabled by an LA for the organisation before non-admin users can create new Teams. Once enabled, any newly created Teams will generate a notification that sends to all the LAs within an organisation asking them to approve or reject the newly created team. Teams email addresses will now be hidden from the GAL – this includes newly created and already created Teams. MFA self-enrol is now live – further guidance on this is available on the support site (Self-Enrol for Multi Factor Authentication (MFA) – NHSmail Support). Private vs Public settings reminder (Private vs. public settings in Microsoft Teams – NHSmail Support). YourVoice ideas forum launched on 22 April 2021. TA updated provided by Matt Brownhill including details of upcoming features and early FIDO2 information for organisations to consider their procurement strategy for FIDO tokens prior to this going live within the shared tenant.
Portal release – likely due next week, overview of key items provided. Online Archive – please brief this message to your user base, cost saving and improves mailbox management. Please complete this Form if a .pst ingestion service for Online Archive is appropriate. Shared tenant training aimed at low/medium level maturity to promote usage of the tools we have, please brief to your organisation and encourage take up. Expectations for PLAs are to keep their organisation and senior team updated with relevant updates from NHSmail and to brief and share those updates. Remember you can have multiple PLA from a contingency/sick/leave perspective. Public vs Private – we are still seeing sites being placed as public when the information within those sites/channels look to need a private tag please reinforce this message. Licence management renewals do, please arrange in plenty of time. Partnership collaboration and FastTrack service meeting has moved to 23 April, please contact feedback for an invite – feedback@nhs.net.
Rangoon 1.2 release successful- (Portal – Rangoon 1.2 Release – NHSmail Support). SMTP change – this has been re-scheduled for 29 and 30 March post further acceptance testing. The impact of the change of date for the SMTP change is that account creation in EXO has moved. We currently have no set date for this, but any newly created accounts are moved to EXO on a daily basis. Sentry release – this is currently expected for mid-April. MS issue – an issue reported to the Helpdesk on 22 March regarding an intermittent exception error identified a previously unknown issue within Microsoft’s infrastructure and allowed a same-day fix to be deployed to resolve this. This shows the importance of reporting incidents to the NHSmail Helpdesk to enable tracking and early problem identification. Full details on announcements page (Microsoft Alert – Service Degradation: Exchange Online – Some users may be unable to access the Exchange Online service using either Outlook on the web or Exchange ActiveSync – NHSmail Support). Egress overview.
Town Hall / IG webinars – natural cross over but please keep specific questions to those forums. Call recording – ability to record restored for this webinar, ticket raised with Microsoft to understand why. Incidents: Wednesday – NHSmail Portal Unavailable, recycled some services to restore service. Now – having an issue with delayed email, unlikely to be noticed by general user but those with applications monitoring might notice that delay. SMTP/high sending solution – to start next Tuesday/Thursday. Portal release – minor release due tonight (Rangoon 1.2) plus future releases will be updated this afternoon. Please visit the Portal Release Schedule for further information on the portal release and capability road map.
12 March 2021 – no recording available
Junk email – working through some options with our joint technical teams please continue to report issues. NHS Digital Data Security Centre offer a phishing simulation service. High sending accounts/SMTP migration – targeting 16 March, staggered over a couple of days to ensure stability, working with organisations that have previously had a large impact. EXO account creation still ongoing work with Microsoft. Sentry release – not expected until April, so we will have a Rangoon 1.2 release, content being refined. Despite best efforts of support team during the event itself, recording was not able to be enacted.
5 March 2021– no recording available
Project plan 3 and 5 now available in the portal, support site has been updated. CSOC – Exchange Server Critical Vulnerabilities . NHS Digital CSOC team have provided the following critical alert to NHS organisations and their suppliers for immediate action. NHSmail technical team have confirmed they have fully patched the infrastructure in accordance with Microsoft guidelines. Junk mail – team are reviewing but third party suppliers do have obligations to ensure their sending meets the framework for SPF/DKIM/DMARC, they can use mxtoolbox or similar tools. HoloLens Remote Assist – about to start testing and looking to roll out Q2. Graph API – guidance to be developed. Power Platform Environment Strategy – more from default to new dedicated environment. GP locums – those funded via NHS England/Improvements managed by NAS do have licences allocated, those with a “parent site” eg CCG, are not covered by the NAS. Working towards a solution
26 February 2021 – no recording available icon was greyed out for all users
SMTP migration – now provisionally 3rd and 4th March, EXO create user – still going through test with Microsoft colleagues, no date available, incident – with queued email, IG Live Event on March 11, TLS will enacted over next few months, Helpdesk Self Service (HSS) overview.
EXO account creation 24 February, SMTP migration 25/26 February, orgs to create their own MFA policy, weekend changes updated on the support site, Teams recordings, CVI on track for Late Q1, EM&S – on track for Q2, phone system – Investigating deployment and capabilities with the appropriate RBAC in place, recordings transcription is being investigated and discussion around desk tickets and initiatives to improve end organisation perception.
8 January 2021 – no recording due to meeting rescheduled
Information Governance Webinar 18th September 2020:
Last Reviewed Date | 17/01/2024 |