Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

We use Dropbox so I tell people we're partly cloudy.

Adbot
ADBOT LOVES YOU

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

But we’re making the impossible possible and it might save money at some point!

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

incoherent posted:

Literally on my o365 deployment kickoff call and Microsoft decides to push exchange support to Oct 2020.

Waiting for this to happen with Windows Server 2008 R2 as well.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

kiwid posted:

We just sold half our company to another company.

What's the best way to migrate mailboxes from our Office 365 to their Exchange 2013?

Am I to export the mailboxes to PST files? Please tell me there is a more elegant way?

Hahahahahahahaha.

No.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Sickening posted:

Has windows update ever been fast?

Server 2016 is the absolutely worst with updates. It takes loving forever. 2019 is way way way better in my experience.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Did you go talk to the Azure AD guys so they can blame the Exchange folk?

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Don’t you need win10 ent for one drive licensing or is it included in 365 now?

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Thanks. We have old school Office 2016/2019. No 365 and not Ent for OS.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

wyoak posted:

You could setup Always-On VPN, it runs on Win 10 Pro and is about as seamless as DirectAccess. Device tunnels are restricted to the Enterprise SKU but user tunnels have been sufficient in most cases at my company.

We use AnyConnect and drives auto map so it's not difficult.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Good. I hope Microsoft breaks Windows 7 more and more.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

I haven't heard of that and we've just deployed it to 300 users. Maybe re-install?

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

We have on prem Cisco ESA for spam and we're moving to Cisco CES which is cloud only. So far it's pretty great.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

BaseballPCHiker posted:

I am soon going to have even more thrown on my plate I think, by getting tasked to help move our org to Exchange Online. Right now we have nothing in the cloud, or any Azure uses besides an old install of ADSync on our DC.

I am primarily a networking person. I do have my AWS SA cert, so I am comfortable with cloud concepts as a whole. My point to my company is that I am not the person for this job. We should hire an outside firm to get us to Exchange Online and setup ADFS and then our normal/useless Exchange admin can run the day to day operations at that point. However with budget cuts I dont think thats going to happen.

So with all that said, how screwed am I?

My plan right now is to first, sit down with management and all the other department heads and try to scope out what exactly they think this move is going to accomplish and what their end goal is. From their I can determine if ADFS, or Azure AD, or password hash sync is the way to go. Once that is setup we can discuss our Exchange plan. We have roughly 2000 users so it wont be done in a day, making me think that Hybrid deployment is the way to go.

This is going to be very frustrating but I am hoping I learn a lot from the process and can use my new found experience to make a jump for more money somewhere else down the line.

I'm in the middle of this right now. Hiring an MSP with a dude to help who has done it hundreds of times was a god send. We had to push out reg entries to the org before we could even start migrating to the cloud and I would have had no idea. There was alot of on prem AD work to do. Having someone who has run through all these fires before was the best move we made.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

BaseballPCHiker posted:

Awesome thanks for the links! We're definitely over 500 seats so thats something we'd qualify for. Going to make as hard a push as I can to get outside help for this.

You won't regret it. I'm still balls deep in the migration and occasionally run into some bullshit I've never seen before cause Microsoft and reach out.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

BaseballPCHiker posted:

This is going to sound very dumb because it is. I had a similar scenario, a computer mounted in a fire truck. It HAD to get the GPO that set screen lockout times for us to pass an audit. Despite it being in a fire truck thats parked in a fire station or out on a call at all times. But then the fire fighters would get pissed because one guy would have to sign in so that they could use their dispatch software to see where the hell they needed to go and what they were getting into.

The solution was a simple app called MoveMouse. It moved the mouse, every 30 seconds or so. I'm not sure if its still around or being developed anymore but it worked on older win10 builds.

This?

https://www.microsoft.com/en-us/p/move-mouse/9nq4ql59xlbf?activetab=pivot:overviewtab

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

kiwid posted:

In Office 365, what's the best way to give a consultant an internal email address that forwards to their gmail account without using a license or mailbox? There seems to be a few different ways like using a shared mailbox or a distribution group. Should I even be doing this in the first place? Should I just use a license/mailbox?

Shared mailbox then you can set auto forwarding in the exchange control panel. No license needed.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Yeah it’s a big one. Got all my exchange servers patched

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

All our generic accounts went to PINs. Works well.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

I don't care, we had someone who's email was shart@company.com and it always made me laugh.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Yeah but a second virtual nic doesn’t make any sense.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Bob Morales posted:

I removed all the entries that existed

It's a whole subnet of devices (it's own dhcp scope)

The other scopes work fine

Can't run ipconfig on an access point

Does the switch the device is connected to have that VLAN configured? Is the port a trunk port or an access port configured with the wrong VLAN?

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

I try to force reboots during the times the end user is busiest. Usually during Webex meetings are a pro move.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

It's my job to follow up with managers every 30 days on whether they want an account to continue being active or if IT can delete. Even our ex-CEO's account was deleted after 90 days.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

ElGroucho posted:

Anybody know where the hell you would pull a history of license assignment/unassignment for things like Power BI or Visio Pro? For some reason all our licenses were unassigned, and know I'm trying to figure out who the hell to assign back to again

Uhh, are these folks on prem? You can use something like PDQ Inventory to see who has Visio or Power BI Desktop installed.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

ElGroucho posted:

Good idea. I'll check SCCM for installed apps

Now I have to figure out what the hell happened, because people are not happy. And it looks like we can't blame Okta this time.

Na this time you can blame Microsoft.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Were the DC's patched recently? Been reading about authentication issues with the latest Windows patch.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Number19 posted:

Yes. but I had pre-verified that we would not be affected by the KRB issues. This is definitely some sort of weird race condition or some other stupid poo poo whereby Windows had it set to "only use THESE credentials for delegation" and ones those had changed there was no visible way to update them.

Did you try to remove the patches and see if that fixed it? While you pre-verified, it could have been an undocumented issue.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

the spyder posted:

We put the November patches in Test last week and auth broke on 9 of the 10 DC's.

Holy poo poo. You have test DC's? Awesome.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Like how you can get one azure ad p2 license and then enable the features for your whole org.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.


Cross-cloud (such as public cloud to Azure Government) isn't currently supported

Boo

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Moey posted:

Speaking of legal hold, I was just reviewing some crap I have squirreled away. Holds from 2020 and 2021.

Sure would be cool if we had some sort of line of communication for when we can nuke these.

Good, your email backups are working.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

The best is when you find rando AWS tenants that are running production workloads for customers and the dude left a year ago.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

At my job management decided it's like wearing shoes to the office. If you want to work remote, using your personal phone for MFA is required. Or you're required to be on site 5 days a week.

Adbot
ADBOT LOVES YOU

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

Thanks Ants posted:

You can't usually have the same domain active on two M365 tenants at once, there's a private preview for enterprise customers that lets this happen and then one tenant routes mail to the other if the user isn't found there.

Do you got a link to this?

Edit: nevermind, I see your other reply. Goddamn. We need this.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply