Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
devmd01
Mar 7, 2006

Elektronik
Supersonik

tehinternet posted:

We just let that bad boy disappear after 93 days, no files, no problems bay-beeeee

gently caress that, you get 60 days to go through your employee’s email and files, if requested. Otherwise, account gets removed nearly instantly upon term, to sit in the deleted users for the 30 days.

Adbot
ADBOT LOVES YOU

devmd01
Mar 7, 2006

Elektronik
Supersonik

Wizard of the Deep posted:

At least one of the phishers uses an email header for allow-listing through the usual filters.

You can set up Outlook filters on those same email headers and send them straight to a folder, marked as read, read receipts off.

I would do this for proofpoint but the exchange rules that I set up for it strip the header, unfortunately.

devmd01
Mar 7, 2006

Elektronik
Supersonik
The kids went back to school today so I get the house to myself all day again. It’s beautiful weather so I’m sitting on the back patio with my laptop, getting distracted by the butterflies and bees on the butterfly bushes.

Bees are much more entertaining than work any day.

devmd01
Mar 7, 2006

Elektronik
Supersonik
thread title needs to subtract an r

Working in IT 3.0: IT woker VFW

devmd01
Mar 7, 2006

Elektronik
Supersonik
Probably told this one before but a VP at a now gone retailer wanted a super powerful laptop…for spreadsheets. So my boss told me to spec out a maxed out Alienware.

The director then ended up with a more portable ultra-light, and the Alienware sat on his desk as his dedicated Remote Desktop for when he traveled, which was a lot.

Still have the mousepad that came in the box.

devmd01
Mar 7, 2006

Elektronik
Supersonik
Hahaha Jesus, ICE. Went through the training for that way back in 2010 as the network team was considering it, so I got dragged in as the desktop admin.

What an utter pile of poo poo, I’m glad it was never implemented.

devmd01
Mar 7, 2006

Elektronik
Supersonik
No exceptions except for service accounts and time-limited, minimally scoped, very specific purpose test accounts handed out to vendors so they can sort out their SSO problems.

devmd01
Mar 7, 2006

Elektronik
Supersonik

gey muckle mowser posted:

Does anyone have any experience doing anything like this? Is this a thing companies even do?

lmao, wtf, no it’s not normal. If orientation is that important, they can drive in for a day.

devmd01
Mar 7, 2006

Elektronik
Supersonik

Crosby B. Alfred posted:

Gotcha but overall... that sync agent is going to have access to a lot of things. Even if worked a different way, if that resource is compromised you are still is a bad, bad place. Granted, it still makes it harder for the attacker.

Way back when we originally set up Okta they basically wanted to just give the service account domain admin. Lmfao hell no, it got very restricted write access to the regular user and contractor OUs, and a specific sub-OU for the groups we generate with Okta rules and push down to AD.

It only gets read to the elevated admin accounts OU so we can import them for sso to AAD.

devmd01
Mar 7, 2006

Elektronik
Supersonik
Not to mention the scheduling assistant can auto pick the next available time for everyone. They’re just lazy.

devmd01
Mar 7, 2006

Elektronik
Supersonik
My role was switched to be under the infosec team this week, along with the IAM analyst. For us, it makes sense to have IAM under the infosec umbrella.

This new manager is even more hands off than my previous one. And more importantly the team has weekly meetings that are over in half an hour instead of a far too long daily standup, and no more on-call ever. :getin:

devmd01
Mar 7, 2006

Elektronik
Supersonik
Oh yeah, did I mention that I demanded a promotion back in 2021 and wrote my own job description? Being in a pod is nice.

devmd01
Mar 7, 2006

Elektronik
Supersonik

Ihmemies posted:

I have no idea about how the guy has survived this far.

Then it sounds like you’re getting a good education on the real world, and especially IT work!

devmd01
Mar 7, 2006

Elektronik
Supersonik
king poo poo

devmd01
Mar 7, 2006

Elektronik
Supersonik
So far today I have attended two meetings for about 15 minutes each, and I'm about to hop into an hour-long one wherein I will be walking my dog in the woods and just listening to the bullshit.

The only other real, actual work accomplished at all has been fixing a saml assertion in Okta for a third party developer. Straight up dgaf mode, I told my boss two days ago that I'm not working on my main project until after the 1st. Skate tomorrow and then I'm off until the 2nd.

devmd01
Mar 7, 2006

Elektronik
Supersonik

Silly Newbie posted:

If their SharePoint and OneDrive needs to come over, it's a similar thing but God have mercy on your soul.

Did exactly this a couple of years ago for an acquisition. Definitely need to release from the previous tenant.

And don’t bother with bittitan if you have SharePoint/Teams to migrate, it doesn’t work and their support is nonexistent. Thankfully I only had three Teams worth of data to move and could do it manually. Email migration works well though.

And for the love of $deity have a comprehensive spreadsheet of what maps to what, DL members, etc. so things don’t go south. In order to release the domain from the tenant, you will have to remove all trace of it and switch everyone to @oldtenant.onmicrosoft .com. That will also be the source address to migrate from with bittitan or whatever tool.

Here is my checklist, hopefully this helps. We had the additional wrinkle of Okta in the middle for iDP and user provisioning:

code:
WEEK PRIOR
	Full User export including aliases
	Full DL export
	Full Shared Mailbox Export w/ permissions 
	Full Teams Export 
	Build translation csvs
	Configure Bittitan Migration Project

COMMUNICATE to ______ users that migration has begun/recovery instructions. Allow 30 min for email delivery to propagate.


MX Record change to Proofpoint
		
Infosec to validate mail receipt and holding.
Infosec to disconnect proofpoint o365 import from _____ tenant.

Run through Source Tenant Prep for domain removal
	https://docs.microsoft.com/en-us/exchange/mailbox-migration/migrate-mailboxes-across-tenants
Initiate token reset on all accounts in old tenant. 
	https://docs.microsoft.com/en-us/powershell/module/sharepoint-online/revoke-spousersession?view=sharepoint-ps
	
Remove domain from old O365 tenant.

Add domains to new tenant. Validate domain ownership in O365 before next steps.  

Add domain as a federated domain in O365 / Okta configuration.

Validate domain with Okta/O365 Provisioning.

Provision test _____ user into AD from Okta and validate.

Confirm license assignment in O365 via automated methods/push groups.

Validate login process for the test user. 
	
	Provision remaining _____ users to Local AD/O365 / Reapply aliases
		
	Enable Okta automation for group push to O365, validate group population.
	
	DESKTOP Team notification that user migration is complete. Test Mobile/Workstation login
	
	Recreate distribution lists - ADD COMPANY ATTRIBUTE FOR ADDRESS BOOK AUTOMATION
	Recreate Shared Mailboxes w/ permissions
	Recreate 3 key teams groups identified for data migration.
	
	INFOSEC - Force proofpoint sync to update users, etc to pull from new tenant.
	Validate mail flow for the domain. 
	INFOSEC - Release held mail. 

COMMUNICATE - Notify Users that migration is complete. Data migration may take up to 24 hours. 	
	

BITTITAN - Initiate mailbox/onedrive content copy.
BITTITAN - Initiate shared mailbox content copy.
BITTITAN - Initiate Teams content migration. 
	

Set email address policies to default 365 group creation to domain.com for _____ users
	https://docs.microsoft.com/en-us/microsoft-365/solutions/choose-domain-to-create-groups?view=o365-worldwide

Set attributes on distribution lists, etc to add to the _____ Address List in exchange online. Validate population of everyone in Address Lists.
	New-ManagementRoleAssignment -name "Address List Management" -SecurityGroup "Organization Management" -Role "Address Lists" -whatif
	New-GlobalAddressList -Name "_____" -IncludedRecipients AllRecipients -ConditionalCompany "_____" -whatif
	

We had the luxury of getting everyone created and logged in already in Okta so they could access workday, so it was mostly a matter of enabling them for user automation the rest of the way into AD/AAD and doing the data copy. Friday, they stopped using their old company laptops, and come Monday they all logged into their new autopilot intune machines and got right back to work. The last two items are just details to make it all a little more polished, hopefully you have a company attribute populated. Don't forget SPF records!

devmd01 fucked around with this message at 14:17 on Jan 14, 2024

devmd01
Mar 7, 2006

Elektronik
Supersonik
Pure support has been consistently fantastic for a long time, that’s about the only vendor I can say that about.

devmd01
Mar 7, 2006

Elektronik
Supersonik

Thanks Ants posted:

At least you're finding out before you buy it. The setup fee is because you know it's the jankiest implementation you've ever seen and that price has been set to put people off.

Probably getting close to about ten apps in the last seven years that I’ve had to hand-hold a vendor through implementing SSO for the first time. It has gotten a lot easier over the years.

devmd01
Mar 7, 2006

Elektronik
Supersonik
Our helpdesk is actually really good, we don’t get a ton of mis-escalated tickets. It’s amazing what having a good service desk manager can do. And if I do have a complaint he’s a teams message away and I know he’ll address it.

We also empower the helpdesk techs to solve problems well beyond what a normal helpdesk does. We are big on promoting from within, there are quite a number of people here who got their start on the helpdesk, including their current manager.

devmd01
Mar 7, 2006

Elektronik
Supersonik
I do the same thing with edge/powershell running as my elevated account, they get red-themed to make sure I pay attention.

devmd01
Mar 7, 2006

Elektronik
Supersonik
I don’t have to go to PI planning in any capacity unless my speciality is needed to speak to a story, it rules.

I send every email from our agile coach to the trash with an outlook rule, I’m not joining your lunch and learn

devmd01
Mar 7, 2006

Elektronik
Supersonik
I just don’t give a gently caress about any of the agile bullshit and do my own thing. For the most part unless I’ll helping with the occasional story I literally do what I want, I’m pretty much left to my own devices by everyone, including my manager.

devmd01
Mar 7, 2006

Elektronik
Supersonik

post hole digger posted:

can you give zscaler private access a look next

:hmmyes:

devmd01
Mar 7, 2006

Elektronik
Supersonik
My boss canceled our team meeting, the only one I had scheduled for today. I’ve received zero emails or teams messages needing me to do anything at all.

devmd01
Mar 7, 2006

Elektronik
Supersonik

tehinternet posted:

it’s marketing and they can eat poo poo

:hmmyes:

Without fail, wherever I’ve worked, Marketing has been the worst department to deal with.

devmd01
Mar 7, 2006

Elektronik
Supersonik
There is open testing at the Indianapolis Motor Speedway today for the upcoming 500, so I went down there for a couple of hours today. I took a table for my laptop and worked off the hotspot; legitimately got some work done. “Sorry, I can’t take a call right now, I’m at the track” is a valid excuse in this company.

I took our weekly team meeting with the cars in the background. My boss didn’t care and was planning on coming down later. It’s gonna be hard to leave this pod.

devmd01
Mar 7, 2006

Elektronik
Supersonik

DeathSandwich posted:

Welcome to working in IT. Collect your "remote bricking 1" merit badge.

Ask me about remote bricking an AD controller once. I was able to restore it from the hypervisor, but it was still like 30 minutes of dull raw panic.

I managed to hose our only physical DC doing windows updates.

We still were on ADFS 2012 at the time, and it only authenticated to the PDC for any external logins. Most of our workforce is remote. Oops.

Seized the roles to get things back in order, cleaned out all the old metadata then drove up to the datacenter and had it flattened and ready to be repromoted by mid afternoon.

devmd01
Mar 7, 2006

Elektronik
Supersonik
I’ve been here long enough that I’ve taken this place from 2008r2 (w/2003dfl) to 2022 for their DCs. Thankfully it’s a small footprint; I can rip and replace them all in a week.

Adbot
ADBOT LOVES YOU

devmd01
Mar 7, 2006

Elektronik
Supersonik
Well when you fire nearly all of your IT in place of contractors two+ years ago, you’re not going to get the same level of quality work. Good job there Ascension, chasing profit margins fucks over another company yet again!

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply