Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

We've been implementing 2FA at a lot of our customers due to insurance requirements, so that's a good thing.

What I've found amusing about the whole thing is that our HD folks are extremely resistant/butthurt about having to deal with 2FA when logging into an admin account on a server. Like, yeah it's a couple extra seconds, but no, it's not going away no matter how much you whine.

I really wish there would good 2FA solutions for MSPs though, we've setup a VM in azure with VOIP apps/auth apps installed, but it's clunky.

Adbot
ADBOT LOVES YOU

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

I mean having a second NIC for redundancy isn't the worst but, yeah, just for management purposes is stupid.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

GreenNight posted:

Yeah but a second virtual nic doesn’t make any sense.

ohhh I didn't see that, I thought i meant adding a second physical NIC and then using that for management purposes for the hosts/vms. Both things are dumb though.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

PDQ just bought smartdeploy, which is an imaging and agent based software control tool, so PDQ might finally be getting an agent and able to manage remote devices. I assume at minimum a year out since they have to integrate.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Not sure which thread it was, but someone within the last month or so threw out a link to an article about setting up patching GPOs, which I thought I had saved, but apparently did not. Might have been Thanks Ants that posted it? I can't for the life of me find it though, if anyone can link again I'd be super greatful.

I have literally never had to deal with patch management as we've always had an RMM system that handled it all and someone else dealt with it, but now I'm getting tossed a client that has no WSUS server and like 100+ PCs that aren't patching correctly via windows update (they also want to try to block the win11 update) so I need to get up to speed quickly I suppose.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE


Yeah, everything seems to be in order based on cursory looking but they're still not updating and I'm looking for more real world examples to see if something is wrong somewhere or at least a better explanation of all the possible policies involved.


Sweet thanks.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

i am a moron posted:

Splunk (and I’m assuming other SIEMs) can pull that data down directly without a workspace. That is the only other non-headache inducing way of getting that data I’m aware of

Did you just say splunk is not a headache?

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

i am a moron posted:

If you’re small enough you can also just ignore the CAL thing indefinitely, Microsoft doesn’t give a poo poo about it anymore and the last audit I sat through (six years ago?) they tried to get my client to true up and upsell them on some things and client just ignored them and MS never pursued any part of it

ehh sounds like a good way to get wrekt

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

dexter6 posted:

I have (what I hope is) a quick question about deleting a user account and litigation hold.

Our normal process is when someone leaves, we just hit delete user in the admin center. This process grants access to their OneDrive to another employee and creates a shared inbox for their emails. And then 90 days later we delete the shared inbox. This works fine.

The wrinkle is when HR requests litigation hold be turned on, as that is not compatible with shared inboxes.

Is there a way to turn on litigation hold and convert the mailbox to shared or is it one or the other?

I have never messed with accounts/mailboxes that are in litigation hold but according to a random reddit post I found, you can convert after doing the litigation hold as long as the account is licensed with EOP1 and online archiving or an EOP2 license.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

snackcakes posted:

A follow up question... Anyone know if hosting a QuickBooks database in Azure files with multiuser mode is possible? Based on what I am reading I think no, but my boss feels certain the answer is yes.

Trying to kill off a file server if possible, the only thing it still hosts is QuickBooks.

It probably will not work.

Move to the hosted version of quickbooks instead.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

kiwid posted:

Question, is PKI required for an RDP cluster/farm using a domain with a .local TLD?

We're having all kinds of certificate warnings and random errors in a new deployment. Is PKI absolutely required in this scenario?

It is not required, no.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

kiwid posted:

How do you get around the certificate issues?

Unrelated, I'm doing a print server migration this weekend. Is there really no easy way to deploy printers still because of print nightmare?

If I turned off the require RestrictDriverInstallationToAdministrators setting for the purposes of the migration and then re-enabled it after printers were deployed, would this cause issues after re-enabling?

Putting Type 4 drivers aside, how are you guys installing printers these days? I've heard some sysadmins are installing locally on each machine, while others are typing domain admin creds to install (which is bad practice).

You could deploy the cert to all machines so they trust it, not saying that's a great idea, but it's possible.

For driver installation, there's another GPO that you can specify allowed print servers, so clients can install the driver from your print server.

Other option is to push the drivers via your RM software which looks to be the route you went.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Serfer posted:

lucky you, I wish there was a tool to move the machines without disjoining rejoining every single one

Yeah, this :(

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Hughmoris posted:

I'm a data guy trying to learn AD DS from zero, for a new gig. For practice, I've used virtualbox to spin up a DC and a Win10 workstation. I then set up DNS and NAT and have the basics working together.

Rookie question on a practical scenario I want to try:
  • I have a new group of employees coming in. I have a list of their names.
  • I'd like to automate the creation of a user account for each employee
  • I'd like to create a fileshare for the new employees, and inside the fileshare I'd like to create a folder for each employee
  • Make it so each employee can only see their own folder
  • Automate all this with a powershell script
  • BONUS: what controls a network fileshare being automatically mapped when a user logs into a workstation? From what I've seen they have to manually type the network path to find their folder.

This seems relatively doable for beginner, given my current virtual environment, right? Any other practical, or realistic, steps I should add to the exercise to improve my learning?

Use powershell for #1/2 - have it iterate through a CSV via for loop and create user accounts, I would add a bunch of info like email address, phone number etc so you have multiple fields to fill out.
#3/4/6 can be done through GPO, do NOT use homefolders in AD, some places still use it but it's dumb, if you want to learn it... you input the info into a single field in AD and it creates the folder with correct permissions, just google it.

It wouldn't hurt to know this stuff because your place might (I can almost guarantee you it does) still have plenty of legacy on-prem data living in fileshares.

Many/a lot of places have moved to folder redirection to OneDrive, so they'll redirect your desktop/documents and maybe a few other profile folders to OneDrive so they sync.
- Old way was to do it via GPO as well and have docs/desktop/etc redirected to file server, I'm sure plenty of places still have this in place as well and you can look into it


None of this stuff is hard and will be a pretty quick thing to learn, it's useful to know imo despite plenty of people being on the "durrr use the cloud hurf durf" train, yes, you should try to get away from as much legacy stuff as you can but there's plenty of places out there still using it and your goal would be to migrate away from it.

MF_James fucked around with this message at 19:03 on Dec 23, 2023

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Thanks Ants posted:

On the subject of groups, I'm convinced I've seen documentation somewhere that says you can use security groups to grant access to Exchange features like mailbox permissions, but I've never gotten this to work, and the group has always needed to be mail-enabled to work. This would be fine but then you lose the ability to do this with dynamic security groups.

Was I reading something that had a typo in, or should it be possible to grant access to things in Exchange using security groups that aren't mail enabled?

It has to be mail-enabled as far as I've seen, I have NOT gotten a regular security group to work and I was just trying again a few days ago.

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

The Fool posted:

Related, make sure you have a "break glass" account that is excluded from MFA.

Also setup alerts for when this account is logged into.

Adbot
ADBOT LOVES YOU

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

kiwid posted:

Another question I suppose. We have two locations that are in the middle of nowhere and the only ISP available other than Starlink is a PTP wireless provider that does double-nat and doesn't provide static IPs. It's been a nightmare for site-to-site VPN but FortiGate's dial-up VPN has gotten us by. However, this means I can't setup these locations as trusted locations for MFA. What are my options here? Now that you mentioned Yubikey, I'm considering just using these for the general use PCs and leave the Yubikey plugged in 24/7. Is there an alternative?

You could route traffic over the tunnel so they present the static IP from whatever office the tunnel terminates at, obviously puts more strain on that connection and adds some latency.

that's just the first thing that popped into my head, wouldn't be the best solution but could be a temporary measure.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply