Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Thanks Ants
May 21, 2004

#essereFerrari


I've found this document quite useful

https://docs.microsoft.com/en-us/azure/virtual-network/virtual-network-peering-overview

Adbot
ADBOT LOVES YOU

Count Thrashula
Jun 1, 2003

Death is nothing compared to vindication.
Buglord
Well, the only thing left to get working is allowing the point-to-site VPN to talk to the on-prem network.

Tunnel is up.
Routes are set.
Firewall allow rules are in place.

I'm starting to get stumped.

edit-- Turns out the Azure VPN client is garbage and I had to go into the software settings Routes.txt and add a manual route back through. Now DFS isn't working - can't connect to the namespace over the VPN. That might be a problem for Monday.

Count Thrashula fucked around with this message at 21:43 on Mar 8, 2019

Thanks Ants
May 21, 2004

#essereFerrari


Does anybody know if it's possible to filter out the drives that get mapped in an RDS session? Scenario is people are connecting to remote desktop and I need to give them access to their local drives in the remote session, as well as needing to leave the feature enabled to have copying and pasting of files working.

The RDS hosts have a drive mapped by GPO that is also mapped on the clients to the same drive letter, and this is causing conflicts when people click the redirected drive in the remote session as connections end up coming via the local machine and then back up to the data centre, whereas if they just use the GPO-mapped drive the server hosting the share is about 2m away.

All I can find so far is a way to turn off having local drives available in RDS, but that's not really an option. Can I filter the duplicates out somehow?

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else
I know in the RDP client options you can select individual drives to be redirected to the session. How easy that is to push via GPO may depend on how variable drive letters are.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

I assume changing the drive lettering on one side is not a possibility?

The easiest solution seems to be changing the mapped drives on the RDS servers.

Docjowles
Apr 9, 2009

I need to spin up two new domain controllers in a new location for an existing domain. The current ones are Server 2012 R2. Is there any reason NOT to install Server 2019 on the new hosts and upgrade the older ones over time? It's a small and very boring domain, we're not doing anything special or outside the box.

Thanks Ants
May 21, 2004

#essereFerrari


If you're at a 2012 functional level then there's no reason to not use 2019 on your DCs

Mordor She Wrote
Nov 17, 2014
I'm not entirely sure if this is the right thread for it, so forgive me if it's not, my bosses tasked me with finding out a way for users to opt in to subscribe to a feed in sharepoint for news updates, with the end result if we put a update to the sharepoint page like "network outage" users would have a button they could opt into receiving email updates from. I haven't touched sharepoint in like 8 years so I really don't even exactly know where to start, and I'm not an admin.

Docjowles
Apr 9, 2009

Thanks Ants posted:

If you're at a 2012 functional level then there's no reason to not use 2019 on your DCs

TIL that the previous admin never upgraded us to DFS replication (when dcpromo yelled at me), so that's cool. I get to learn about that now.

devmd01
Mar 7, 2006

Elektronik
Supersonik

Docjowles posted:

TIL that the previous admin never upgraded us to DFS replication (when dcpromo yelled at me), so that's cool. I get to learn about that now.

It’s super easy, has no impact, and you can do it in the middle of the day. Just follow the guide and make sure all of your DCs are replicated before going to the next step.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

devmd01 posted:

It’s super easy, has no impact, and you can do it in the middle of the day.

Famous last words.

Thanks Ants
May 21, 2004

#essereFerrari


Moving sysvol replication is easy, you just need to be patient and resist the urge to try and intervene. Make a change, leave it a couple of days to sort out the replication, move to the next step, repeat.

vanity slug
Jul 20, 2010

go straight past the no return zone, 50% of the time it works every time

Agrikk
Oct 17, 2003

Take care with that! We have not fully ascertained its function, and the ticking is accelerating.

GreenNight posted:

Every day I admin Windows file permissions is how often I miss admining a Novell file server. I don't miss ConsoleOne but man Novell was nice.

What’s up NetWare buddy!

snackcakes
May 7, 2005

A joint venture of Matsumura Fishworks and Tamaribuchi Heavy Manufacturing Concern

I got stuck trying to upgrade FRS to DFSR and it turns out windows firewall was blocking me. Oops

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Disable Windows firewall on all servers, thx.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

GreenNight posted:

Enable the Windows firewall on all servers, thx.

The Fool
Oct 16, 2003


GreenNight posted:

Properly configure Windows firewall on all computers, thx.

Docjowles
Apr 9, 2009

Thanks Ants posted:

Moving sysvol replication is easy, you just need to be patient and resist the urge to try and intervene. Make a change, leave it a couple of days to sort out the replication, move to the next step, repeat.

This did in fact end up being super easy, thanks goons! :cheers:

Is there any practical benefit to DFSR (faster or more reliable replication or anything) beyond "FRS is old as hell and deprecated and unsupported"?

e: nm found an article on the subject (from 2010 lmao) https://blogs.technet.microsoft.com/askds/2010/04/22/the-case-for-migrating-sysvol-to-dfsr/

Docjowles fucked around with this message at 18:30 on Mar 14, 2019

Mr. Clark2
Sep 17, 2003

Rocco sez: Oh man, what a bummer. Woof.

Somewhat odd question here: I'm currently testing a user/computer migration between two AD domains using this guide: https://blog.thesysadmins.co.uk/admt-series-1-preparing-active-directory.html

When testing a computer migration, I accidentally used the incorrect credentials in the Security Translation Wizard and as expected, it failed with an "access denied" message. On subsequent runs, it uses those same incorrect credentials every drat time. Is there any way to remove or reset these credentials without uninstalling/reinstalling ADMT? Thanks in advance.

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010

Docjowles posted:

This did in fact end up being super easy, thanks goons! :cheers:

Is there any practical benefit to DFSR (faster or more reliable replication or anything) beyond "FRS is old as hell and deprecated and unsupported"?

e: nm found an article on the subject (from 2010 lmao) https://blogs.technet.microsoft.com/askds/2010/04/22/the-case-for-migrating-sysvol-to-dfsr/

It was probably microsoft smartest move, in 2010. I'm not surprised admins are getting snapped up in 2019 over it seeing how 08 R2 is lurching to the finish line.

Djimi
Jan 23, 2004

I like digital data
So I tried to search the most recent SH/SC threads for info on Skype4Business and regular Skype interoperability. Not a lot there for the last 18 months.
We're using the latest versions, updated etc.etc.

B2B calls/video work fine. We have Office365 online, and the settings for Skype4B are set apparently correctly for allowing our users to make calls/chats with outside 'external' Skype users. And IM is allowed for outside use, no domains are blocked. Specifically the Office365 Skype user is C-Level, and he's one of the only people that uses a Mac, and his contacts on regular Skype and 4B Skype are most likely on PCs, but that shouldn't make a difference.

Should I toggle the settings, and wait and check the boxes back on or is there some other place to check? All settings appear to be good—what am I missing?
I am hoping somebody has had this same issue and knows what is up. Also I would be happy to do this in powershell if it's possible. TIA. :tipshat:

Fruit Smoothies
Mar 28, 2004

The bat with a ZING
One of my clients has had a GDPR request for all e-mails pertaining to a person. They're on Office 365. Is there a way to text search across mailboxes, or shall we tell staff to search their mailboxes individually?

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Djimi posted:

So I tried to search the most recent SH/SC threads for info on Skype4Business and regular Skype interoperability. Not a lot there for the last 18 months.
We're using the latest versions, updated etc.etc.

B2B calls/video work fine. We have Office365 online, and the settings for Skype4B are set apparently correctly for allowing our users to make calls/chats with outside 'external' Skype users. And IM is allowed for outside use, no domains are blocked. Specifically the Office365 Skype user is C-Level, and he's one of the only people that uses a Mac, and his contacts on regular Skype and 4B Skype are most likely on PCs, but that shouldn't make a difference.

Should I toggle the settings, and wait and check the boxes back on or is there some other place to check? All settings appear to be good—what am I missing?
I am hoping somebody has had this same issue and knows what is up. Also I would be happy to do this in powershell if it's possible. TIA. :tipshat:

You didn't explicitly state what wasn't working here. Is nothing working, either calls or messages? Or is it partially working and you're looking for the missing piece?

Fruit Smoothies posted:

One of my clients has had a GDPR request for all e-mails pertaining to a person. They're on Office 365. Is there a way to text search across mailboxes, or shall we tell staff to search their mailboxes individually?

Compliance and Security center will allow you to search mailboxes but I'm not entirely sure how the legal framework around these requests works (or even what it's asking for).

Djimi
Jan 23, 2004

I like digital data

ChubbyThePhat posted:

You didn't explicitly state what wasn't working here. Is nothing working, either calls or messages? Or is it partially working and you're looking for the missing piece?
Sorry B2B is working. Business to non-Business Skype and non-Business to Business doesn't work at all. Sorry. It says the user isn't online. Well it did that a few attempts, now it doesn't report anything, just closes the call / video window after about 1 second, and makes its goofy little noise.

Thanks Ants
May 21, 2004

#essereFerrari


My advice for SfB -> Skype interop is to deny that it's even possible, even when presented with all the evidence of Microsoft touting it as a feature.

Djimi
Jan 23, 2004

I like digital data

Thanks Ants posted:

My advice for SfB -> Skype interop is to deny that it's even possible, even when presented with all the evidence of Microsoft touting it as a feature.

That may work, but this guy will throw a fit and he says that his colleagues have it working, so _fix_it! But it was my hunch that it would have some bugs or something.

Is this something that MS is trying to quash? Please give your experience(s) about Skype4B and Skype Regular. Thanks, Thanks Ants.

Thanks Ants
May 21, 2004

#essereFerrari


I think you want to make sure your SfB DNS records are set properly (the Office 365 control panel will check this for you), and you need to communicate using the email address form of the Skype user ID - not just the short name.

Also

https://docs.microsoft.com/en-us/skypeforbusiness/set-up-skype-for-business-online/let-skype-for-business-users-add-skype-contacts posted:

Skype for Business on Mac doesn't have the ability to search for and communicate with Skype contacts.

ChubbyThePhat
Dec 22, 2006

Who nico nico needs anyone else

Djimi posted:

Sorry B2B is working. Business to non-Business Skype and non-Business to Business doesn't work at all. Sorry. It says the user isn't online. Well it did that a few attempts, now it doesn't report anything, just closes the call / video window after about 1 second, and makes its goofy little noise.

Ah, I had assumed as much but wanted to make sure.

Thants has said it already but getting this to work generally sucks a lot. Main issues are usually somewhere involved in the DNS settings for your tenant (or DNS somewhere in the communication). I have seen some rare cases where O365 federation just decides nope you cannot do that, but I can't remember the exact issue (nor the fix) for whatever is triggering that memory.

e:
Well looks like the above is a pretty relevant piece of text.

Djimi
Jan 23, 2004

I like digital data

Thanks Ants posted:

I think you want to make sure your SfB DNS records are set properly (the Office 365 control panel will check this for you), and you need to communicate using the email address form of the Skype user ID - not just the short name.

Also

Thanks Ants. So, probably never to be 'fixed' (...?)

Djimi
Jan 23, 2004

I like digital data

I should have visited your link before I said anything. That's where I started this morning, and I already checked that before posting my issue. That was the part about "settings look correct". Didn't catch the "communicate" part regarding MacOS though.

I thought with parity on the Outlook 2016 Mac client that M$ was going to turn over a new leaf and not hose MacOS anymore. smdh.
(double post)

Thanks Ants
May 21, 2004

#essereFerrari


SfB is a dead product, it's just not been officially killed yet.

Djimi
Jan 23, 2004

I like digital data

Thanks Ants posted:

SfB is a dead product....
Teams taking over?

vanity slug
Jul 20, 2010

Djimi posted:

Teams taking over?

we're going back to OCS

Djimi
Jan 23, 2004

I like digital data
Also, I just found out that the Admin panel has two locations for SfB -- and your link mentions the one, but here's the Teams (separate and probably overriding one). I suppose in 24 hours maybe we will have some more connectivity—not holding my breath.



Again thanks for your help, y'all.

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

Yeah Teams is replacing SfB

Also


Don’t do this. It’s tired and played out.

The Fool
Oct 16, 2003


I was having slashdot ptsd for a minute there

Djimi
Jan 23, 2004

I like digital data

skipdogg posted:

Don’t do this. It’s tired and played out.
Sorry I was around and in the industry when it was invented, and I don't think about as 'a joke' it's just my learned emoji for it.

Seems funny that it would ever offend anybody. Hey look at that, Nov. 2004, you're old as well! I was using my brother in law's account for 3 years before I joined. Would be cool to be 2001. I was a stupid newbie. Oh well. Message received SD (not $D) :v:

Dirt Road Junglist
Oct 8, 2010

We will be cruel
And through our cruelty
They will know who we are

skipdogg posted:

Also

Don’t do this. It’s tired and played out.

Now, imagine having to tell that to your boss :v:

Adbot
ADBOT LOVES YOU

Sudden Loud Noise
Feb 18, 2007

Apparently I'm a giant GDPR nerd because that "personal data in email bodies" is a super fascinating question that I've never considered. I've always just thought about explicit entries and derived info, I've never considered email bodies themselves. I suppose it must still count...

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply