Jump to content

Recommended Posts

Posted

We are but not direct with Netsweeper. We have it via Schools Broadband.

 

We just use the AzureAD agent so the sync happens to the Azure group and not AD groups

  • Thanks 2
Posted

What would be your main worry?

 

Don't even need to sync users these days, you can control it all via the agent, but that's a bit non standard.

 

Is it VPN based filtering so all tunneled to cloud, or client filter based which is just locally installed proxy on a machine

  • 2 weeks later...
Posted (edited)
Don't even need to sync users these days, you can control it all via the agent, but that's a bit non standard.

Was trying to get my head around that just yesterday. Is that where you can push via intune/gpo a magic string that then the agent uses to signal the platform which group to use for the traffic from that client? Does that allow for targeted polices that "could" be as granular as the AD/Entra group/user (because you are targeting using GPO/Intune), even when all users appear to share an IP? (it being a limitation, of our particular network/regional/netsweeper implementation of IP subnets, that 'traditional' per user filtering is not possible if many users are coming from the same IP)

 

edit:this is probably specific to my/Paddy's frame of reference, where for historical reasons many customer networks are more like remote offices to a centrally managed network, where as SBB's assumptions are that customers come with their own private administered IP ranges.

Edited by psydii
Posted
Was trying to get my head around that just yesterday. Is that where you can push via intune/gpo a magic string that then the agent uses to signal the platform which group to use for the traffic from that client? Does that allow for targeted polices that "could" be as granular as the AD/Entra group/user (because you are targeting using GPO/Intune), even when all users appear to share an IP? (it being a limitation, of our particular network/regional/netsweeper implementation of IP subnets, that 'traditional' per user filtering is not possible if many users are coming from the same IP)

edit:this is probably specific to my/Paddy's frame of reference, where for historical reasons many customer networks are more like remote offices to a centrally managed network, where as SBB's assumptions are that customers come with their own private administered IP ranges.

 

You could in theory do this anywhere, we are specific (but not the only ones) in that we run the network and we allocate you IPs as we control the routing and everything from on prem to breakout. If you are using NAT in our network the filter cannot be granular to a user level but if you aren't using NAT, typically you'd have a GPO per OU if you wanted real granularity, then each intake year/however your AD structure is set up, would be able to get a different policy. In the case of InTune/Entra, you can have a load of filtering policies and tie one of those to a user as they log in, most people group these as staff/student but you can go as granular as your skills allow.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...