Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Shaggar
Apr 26, 2006
password reset with ad synced users requires atleast a P1 license because self service password reset (the main way passwords get changed via azure ad) is an extra license cause of loving course it is.

I think you can also have it write back devices from MDM to on prem, but yeah gently caress user/group writeback.

AADC seems to be pretty nice from what ive used of it. the transform rules worked for what i needed them to do.

Adbot
ADBOT LOVES YOU

Pile Of Garbage
May 28, 2007



AADC is really good and solid because it's built on the legacy of FIM/MIM which are really good and solid identity management systems but get super complicated very quickly the moment you integrate another system and/or write your own integration plugins. AADC avoids all that ofc because it only has to deal with AAD and on-prem AD, easy mode.

Shaggar
Apr 26, 2006
yeah i like the internal design with the metaverse or w/e. makes it easy to understand how its doing things when troubleshooting

Pile Of Garbage
May 28, 2007



earlier this year they tried to make me support some turbo-hosed on-prem FIM/MIM solution which was syncing between 3 AD domains, 4 SAP environments and 2 salesforce environments, allll relying on custom poo poo. i told them to eat poo poo basically.

it's wild FIM/MIM unconstrained is pure hosed but when you lock it own you get AADC which owns.

Shaggar
Apr 26, 2006
AD -> Azure AD -> everyone else via saml/oidc/wsfed w/ SCIM if needed (even tho scim is poo poo)

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Shaggar posted:

AD -> Azure AD -> everyone else via saml/oidc/wsfed w/ SCIM if needed (even tho scim is poo poo)

shaggar was right

Shaggar
Apr 26, 2006
also if your federation implementation doesnt allow users to be created/updated during token login then its poo poo and you need to redesign it. i should never have to create or update a user out of band.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Shaggar posted:

also if your federation implementation doesnt allow users to be created/updated during token login then its poo poo and you need to redesign it. i should never have to create or update a user out of band.

that’s what your application admin is for

Pile Of Garbage
May 28, 2007



Shaggar posted:

AD -> Azure AD -> everyone else via saml/oidc/wsfed w/ SCIM if needed (even tho scim is poo poo)

this is 1000% correct and if anyone says otherwise they work for SAP/IBM/consultants.

bobbilljim
May 29, 2013

this christmas feels like the very first christmas to me
:shittydog::shittydog::shittydog:

Pile Of Garbage posted:

SAP->AD->SAP->AD->Salesforce->SAP->AD).

:yikes:

Shaggar
Apr 26, 2006

Captain Foo posted:

that’s what your application admin is for

if i can provide all the attributes necessary for user creation in the security token at sign in i expect the user to be created from those attributes at sign in.

Shaggar
Apr 26, 2006
and im talking about tertiary systems like salesforce, sap, or whatever dumb bullshit the HR people got scammed into buying this week. actual important stuff like ad/azure ad is different

Shaggar
Apr 26, 2006
oh, one of my favorite other things about AADC is that if you want to do single sign on using windows auth to azure AD they got rid of the requirement of using ADFS by spinning up a VM in azure and joining it to your domain for the purposes of trust and windows auth lol.

Captain Foo
May 11, 2004

we vibin'
we slidin'
we breathin'
we dyin'

Shaggar posted:

if i can provide all the attributes necessary for user creation in the security token at sign in i expect the user to be created from those attributes at sign in.

more applications in my experience than not don’t do provision on first use

Shaggar
Apr 26, 2006
i know and it really annoys me

flakeloaf
Feb 26, 2003

Still better than android clock

ours has a fun trick where a user whose first login is over vpn gets told to frig off, because people who don't have a corresponding AD account can't open vpn sessions, and you can't be authenticated if the machine doesn't have a cached credential it can check -- so even if you're issued a laptop you physically have to go into the office to activate it, which is fine by me because it's another chance to do 100% id verification, see the client's pass, check their clearance and make sure they have a working pki token

flakeloaf
Feb 26, 2003

Still better than android clock

also apparently that "no vpn without a valid AD account" bug/feature extends to disabled accounts too, which we learned by accident when someone did something stupid in a no-stupid zone

we locked his account, corrections were made, and after we re-enabled him he still couldn't open a VPN, because you need an enabled account to do that and the locally cached version insisted the account wasn't active :dumbbravo:

Silver Alicorn
Mar 30, 2008

𝓪 𝓻𝓮𝓭 𝓹𝓪𝓷𝓭𝓪 𝓲𝓼 𝓪 𝓬𝓾𝓻𝓲𝓸𝓾𝓼 𝓼𝓸𝓻𝓽 𝓸𝓯 𝓬𝓻𝓮𝓪𝓽𝓾𝓻𝓮
hey what’s a good ssd to get these days. I’m looking for 2 TB and probably PCIe 4, unless there’s a reason PCIe 4 is a bad deal. I’ve historically always bought Kingston for flash memory, are they still good? any other good brands?

spankmeister
Jun 15, 2008






Silver Alicorn posted:

hey what’s a good ssd to get these days. I’m looking for 2 TB and probably PCIe 4, unless there’s a reason PCIe 4 is a bad deal. I’ve historically always bought Kingston for flash memory, are they still good? any other good brands?

Kingston SSD's aren't bad per sé but not the brand to get I think.

Samsung EVO is the best price/performance, but the current model (970 Evo plus) is PCIe 3 not 4, so if that really matters to you the 980 Pro is the best.

Other good SSD brands are Intel and Western Digital (WD Black).

git apologist
Jun 4, 2003

is there a practical difference between a super fast nvme ssd and an even faster nvme ssd for desktop use

Silver Alicorn
Mar 30, 2008

𝓪 𝓻𝓮𝓭 𝓹𝓪𝓷𝓭𝓪 𝓲𝓼 𝓪 𝓬𝓾𝓻𝓲𝓸𝓾𝓼 𝓼𝓸𝓻𝓽 𝓸𝓯 𝓬𝓻𝓮𝓪𝓽𝓾𝓻𝓮
I’m not just doing regular desktop use. I’m a gamer

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl

Silver Alicorn posted:

I’m not just doing regular desktop use. I’m a gamer

:mods:

Jenny Agutter
Mar 18, 2009

:dogtits:

Shaggar
Apr 26, 2006

spankmeister posted:

Kingston SSD's aren't bad per sé but not the brand to get I think.

Samsung EVO is the best price/performance, but the current model (970 Evo plus) is PCIe 3 not 4, so if that really matters to you the 980 Pro is the best.

Other good SSD brands are Intel and Western Digital (WD Black).

the evo 980 pro is pcie gen 4.

Silver Alicorn
Mar 30, 2008

𝓪 𝓻𝓮𝓭 𝓹𝓪𝓷𝓭𝓪 𝓲𝓼 𝓪 𝓬𝓾𝓻𝓲𝓸𝓾𝓼 𝓼𝓸𝓻𝓽 𝓸𝓯 𝓬𝓻𝓮𝓪𝓽𝓾𝓻𝓮
I’m just leery of buying sarnsung but I’ll think about it

Jonny 290
May 5, 2005



[ASK] me about OS/2 Warp
i run sarn 980 pros for all my important drives and they're incredibly fast and good.

tier2 is wd blacks, i have 3 of those in my linux box and they also seem to do it nicely, though they're gen3

do. not. buy. sabrent. i got burned by them really hard

spankmeister
Jun 15, 2008






Shaggar posted:

the evo 980 pro is pcie gen 4.

yes that's what I said

spankmeister
Jun 15, 2008






Silver Alicorn posted:

I’m just leery of buying sarnsung but I’ll think about it

they're the best ssd op

Farmer Crack-Ass
Jan 2, 2001

this is me posting irl
i thought samsung was considered overpriced these days

echinopsis
Apr 13, 2004

by Fluffdaddy
feels like a component that you don’t wanna skimp on

like you’re not just paying for performance, hopefully also reliability

namlosh
Feb 11, 2014

I name this haircut "The Sad Rhino".
understood, op

this is the only thing I’ll buy from Samsung as far as I know. only stuff that can’t connect to the internet on its own and spy on me.

kinda funny that I trust a hard drive not to spy on me but here we are

Agile Vector
May 21, 2007

scrum bored



i've always though samsung to be a proper chaebol, where the various divisions are their own silos

i always figured storage and screens were different entities, especially since samsung was battling with apple on design similarities while apple was orders stacks of components for iphones

spankmeister
Jun 15, 2008






oh yeah I don't buy anything from samsung except ssd's, gently caress their phones and tv's.

echinopsis
Apr 13, 2004

by Fluffdaddy
I leave their phones and tvs alone, loving then seems a little bit ott in todays culture

spankmeister
Jun 15, 2008






i gently caress my sarnsung and cum in it

flakeloaf
Feb 26, 2003

Still better than android clock

this phone is fine, as is my sabrent drive for the moment, but I fully expect to be left in the cold when it does fail because their support is garbo

the WD/Samsung decision is made by waiting for one of them to go on sale, because they are both good

cowboy beepboop
Feb 24, 2001

is there a good usb bluetooth adapter

my "targus" thing disconnects all the time

Private Speech
Mar 30, 2011

I HAVE EVEN MORE WORTHLESS BEANIE BABIES IN MY COLLECTION THAN I HAVE WORTHLESS POSTS IN THE BEANIE BABY THREAD YET I STILL HAVE THE TEMERITY TO CRITICIZE OTHERS' COLLECTIONS

IF YOU SEE ME TALKING ABOUT BEANIE BABIES, PLEASE TELL ME TO

EAT. SHIT.


cowboy beepboop posted:

is there a good usb bluetooth adapter

my "targus" thing disconnects all the time

I have a tp-link one from amazon and it's okay.

Private Speech
Mar 30, 2011

I HAVE EVEN MORE WORTHLESS BEANIE BABIES IN MY COLLECTION THAN I HAVE WORTHLESS POSTS IN THE BEANIE BABY THREAD YET I STILL HAVE THE TEMERITY TO CRITICIZE OTHERS' COLLECTIONS

IF YOU SEE ME TALKING ABOUT BEANIE BABIES, PLEASE TELL ME TO

EAT. SHIT.


I picked it specifically because it's not a no-name brand

Adbot
ADBOT LOVES YOU

Jenny Agutter
Mar 18, 2009

market opportunity: Bluetooth audio adapter that just presents as a usb audio adapter so you don’t have to deal with windows terrible Bluetooth implementation

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply