Jump to content

Recommended Posts

Posted

We joined up with Locker Connect this last Summer to get ourselves on the automatic account creation bandwagon. We chose them over Salamander as we liked the look of what we saw. However, I'm not getting the functionality that I was expecting.

 

Now I'll say right now, I'm not saying the software doesn't work, but I do think that somewhere along the way our configuration hasn't been set how we want it.

 

We use Bromcom as our MIS (don't get me started about that right now) and Microsoft 365 as our email system. We are also using Azure AD Connect (or Entra) to link up our onsite AD with Azure so we can enable single sign-on. Accounts are creating in both AD and 365, and they are adding to correct groups in AD... but not in 365? Even though the named groups are proper "Microsoft 365 Groups".

 

Locker say that our 365 accounts are getting created by Azure Connect rather than Locker, and so they are having to handle accounts after the fact. But because of this, they can't handle group management? Does that sound correct?

 

Does anybody else out there use Locker with 365 and have a SSO system? Do you have any issues with group allocation? Are you making use of Azure/Entra Connect? Basically, what is your working setup that we seem to not have?!

 

Driving me potty as I'm sure we can achieve what we want without having to switch to Salamander, but I just can't get my head around it. And right now it's hindering our next step in our big project of shifting a lot of data into SharePoint and Teams.

Posted (edited)

We use Locker. Excellent product. I looked at Salamander and wanted it but their lead time was too long (shows how popular it is), whereas Locker had availability right away.

 

Locker is great that you can see what it's doing and make tweaks yourself and always found their support to be spot on.

 

Essentially, for us it does the following.....

 

1. Task that runs and looks at Arbor and sees if there are any new students or staff that don't have an e-mail address set in their profile. Creates an entry based on our formatting.

2. Next task run that creates AD accounts on new staff or students - account is put into a number of AD Groups based on the type - uses Wildcards for these and specifying which OU to place the account in. They have to have the e-mail set in Arbor for it to be created in the previous step.

3. Azure AD Connect is humming away in the background and when it next does a sync, it'll create the accounts in M365 - we use Group Based Licensing - so a license gets assigned in M365 based on a specific AD Group that locker put the account in the previous step (A3 for Faculty for staff, and A3 Student use benefit for students).

4. Later on, Locker will do another task which is to create/update all the Distribution groups in M365, ie. Cloud Groups and put all the AD Sync'd users in those groups

5. Another task is then doing the Teams creation/migration looking at the timetables in Arbor and sorting those AD Sync'd users into the Teams - Teachers are Owners, Students are members.

6. Yet another task, updating/creating timetables from Arbor into Outlook Calendars - this we only do weekly for students as it's a lot of data to extract and throw at M365.

7. And then another task goes through and disables any leavers, again both staff and students. Disables the account, you can then get it to remove from certain AD groups. The other tasks that run above will remove membership of teams, lists, etc next time it runs.

 

As for SSO, we have that working, and that's just really looked after by GPOs and agents from M365 running on the DCs, etc.

 

We have no issues with it overall - we've just migrated from SIMS to Arbor and Locker happily spent the day remoting in and doing the migration. It's a well trodden path for them and they have a number of PS Scripts that have to do all the renaming, etc to get stuff moved over.

 

HTH

 

Pete

Edited by FragglePete
Spelling & Grammar
  • Thanks 1
Posted

That sounds exactly like what I would expect it to be doing. But the groups memberships and adjustments aren't working as intended. We'll go back to Locker support and get them to look into our config, something clearly is set up wrong.

 

Do you mind if I ask how your SSO part is working? We have a GPO that sets a site-to-zone setting and one to allow status bar updates via a script. But that's seems to be pretty much it. I'm wondering if we have a setting wrong with the Azure AD Connect program?

Posted
Do you mind if I ask how your SSO part is working? We have a GPO that sets a site-to-zone setting and one to allow status bar updates via a script. But that's seems to be pretty much it. I'm wondering if we have a setting wrong with the Azure AD Connect program?

Yes, I believe that is all we have in place as well - did it so long ago, can't quite remember now. Azure AD Connect and it's DC agents help facilitate the password checking and write back if setup.

 

Pete

  • Thanks 1

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...