-
Posts
311 -
Joined
-
Last visited
Reputation
165 ExcellentAbout Manny-Tech

Personal Information
-
Occupation
Network Manager
-
Azure AD, Fortinet Filtering
Manny-Tech replied to Alawil's topic in Internet Related/Filtering/Firewall
I'm finding that once users are logged in they can use 'Open browser and connect' which probes the Microsoft captive portal check site and then proceeds to do the Azure auth. However, if staff do not click that link at the side of the WiFi properties and open a browser they get a 'Wifi may require you to go to its sign-in page' rather than directing me there. Having looked into it, I think it's when a https:// site is specified as a homepage. If I go to http://neverssl.com, it redirects to a captive portal through Azure, and they are signed in. Not sure there is a solution to this other than telling staff to either click 'Open browser and connect' or browse to a http site first. -
I don't think we're too far off then and thank you for suggestions. The other thing that bothers me is the syncing of folders to explorer and then if said user is removed from a Team they retain access to the explorer view, there doesn't appear to be a way to remove this automatically.
-
We're fairly far down the line in terms of shifting staff data to the 'cloud', we've essentially move home areas to OneDrive and each department has access to their own 'Team' alongside a generic staff area. We're a hybrid amongst each teacher having a laptop and a desktop in their classroom. Syncing files seems to be a problem as teachers move around various classrooms - not a problem if they use their laptop! I'm considering setting up a SharePoint Hub site to pull all relevant Teams document libraries into a central location. Has anyone else gone this route? I've tried to use the native tools available, but it does look like more and more people are going down the third party route. Second part to this is student data which is next on the list. Currently we have teachers that have access to student home areas on a network share, this isn't quite as fluent once that data is in OneDrive and I'm not sure how I get around that. Maybe we need to change the way we work and utilise student class teams for them to save their work in to make it accessible for relevant teachers? Likewise is the best way for students to access any teams / sharepoint data through a hub site rather than using Teams app or Office applications? I'm interested in others feedback on this and problems that have arisen and how you've circumvented it. Fairly sure we're all coming from a similar background of network home areas / shares and getting the best out of this in the cloud.
-
As a school we're well integrated into the O365 ecosystem, all personal data is in OneDrive, file shares have moved to a mix of teams/SharePoint (I know ultimately it's SharePoint for the storage), the one thing I have left to do is the masses and masses of iPad content that is sat on my server still. Teachers are recording content and using a 3rd party app to drop their content onto the server - I'd like to shift this data into the cloud, my initial thoughts are to just drop it all into a new document library, use the SharePoint app to upload and view content. My biggest question is usability, is it pretty on the eye for staff to view their content? How easy is it to upload content? I do like the idea of Stream for video but I'd like to incorporate photos/video all into one platform. What's everyone else doing around this?
-
My switch is a Aruba 2930M. I'm not trying to restrict between VLANs, I was just trying to understand how it was configured. My device gateway is 192.168.100.1 which is my router, though it does have a static route back for 172.100.0.0 to the switch for the other VLAN range. Maybe it's just my interpretation of what untagged/tagged is. I assume untagged means anything on that port is a member of that VLAN and tagged carries traffic over the ports that are tagged. Is that correct? So essentially the switch will do inter-vlan routing as long as it's all on the same switch, otherwise I need a static route to point it to my core switch where the VLANs are configured?
-
Would that be by just having 'routing' enabled on my switch on Aruba Central? I can't see anything in particular set on the VLANs
-
I have a networking question that I'm hoping someone can explain. On my Aruba switch I have the below configuration VMWareHostVLAN IP 172.100.200.1/26 Untagged 10-13 iLO-VLAN IP 172.100.200.65/26 Untagged 15-16 Default VLAN IP 192.168.100.100/16 Tagged 10-13 Untagged 1-9, 14, 17-24 Static routes: 0.0.0.0 - Gateway 192.168.100.1 192.168.0.0/16 - Gateway Default VLAN 172.100.200.0/26 - Gateway VMWareHostVLAN 172.100.200.64/26 - Gateway iLO-VLAN I also have the following devices with the below IPs Host1 - 172.100.200.10 Host2 - 172.100.200.11 iLo1 - 172.100.200.66 (host1) iLo2 - 172.100.200.67 (host2) If I have a client machine on 192.168.100.3 - it is able to communicate with both the host and the iLO. Looking at the switch config I can see the VMWareHost VLAN ports are tagged on the default VLAN which would make sense why I can communicate with the hosts. What I can't understand is how I can communicate with the iLO VLAN when the ports aren't tagged on the default VLAN. Anyone able to offer their knowledge on networking?
-
[ipad] Apple School Manager - Paying by credit card not working
Manny-Tech replied to Theldron's topic in Mobile Devices & Tablets
I was having same issues last week but tried again today and all working fine again now. -
Hi, With WPA3 becoming more common, and since Android 11+ removing the 'do not validate' on the certificate option when using RADIUS to connect to WiFi. How are you getting root CAs certificates onto devices, whether that is an internal CA or public CA such as GlobalSign? It also appears we need to specify the domain, or common name, on the certificate before a user can input their username and password to authenticate. I understand the reasons why it behaves like this, I just wondered what others approach is to a) getting the CA cert on their devices, especially BYOD and b) configuring WiFi connection settings for users or is it as simple as just pointing them to a guide? I guess, I'm almost wanting some form of SCEP setup for BYOD devices.
- 3 replies
-
- ca certificate
- do not validate
-
(and 1 more)
Tagged with:
-
I have computers sync'ing via AAD Connect, still no luck. I haven't hybrid joined any device as yet, so I'm not sure that is a contributing factor, especially based on having other machines working fine. I did flatten one of the devices today with a fresh install and it now does the silent config everytime. I was rather hoping that wouldn't solve it because that's not something I want to do on 200+ machines. Though if it's a necessity then so be it I guess.
-
Is that a requirement? I have a lot of computers that aren't, but they still silently sign in?
-
Hi, I'm having issues getting OneDrive automatically signing in on our domain joined Windows 10 clients on 21H2. I have AAD Connect configured with Passthrough Authentication enabled, I can verify this is working by signing into O365 seamlessly. I have also installed the latest OneDrive ADM files to Group Policy, configured my tenant ID, and other relevant settings to silently configure OneDrive. The problem I'm experiencing is that on some devices it works flawlessly, and on others it launches OneDrive, updates, but never actually signs in and prompts for users email address. Though on said machines where it doesn't work I can verify that SSO is working to O365 platform. There doesn't appear to be much in the way of log files. Has anyone else come across this or has any pointers on how to resolve? Thanks
-
Hi, We have a Windows 11 client that is Azure AD joined only, this particular device has a card printer attached to it and prior to going Azure AD joined was able to share this device with others to make use of. Now domain joined devices are unable to authenticate onto this device to add the card printer. Initially I couldn't even ping the device but soon realised this was related to firewall rules on the client, as well as the file and print sharing being enabled on a private profile. The thing I'm really struggling with is trying to add a printer by UNC \\clientname\printername and auth'ing, even if I allow everyone access through the share permission of the device. Has anyone else come up against this when going from domain joined to Azure AD joined?
-
I don't see how that is possible, or why you would do that for Google accounts. Are you sure it hasn't just been misinterpreted? Have you created a user in Adobe and then observed whether it gets sync'd to Google?
-
I use the Adobe User Sync Tool to populate all my users / groups into Adobe Admin Console from AD. I won't like, it was pain in the backside to get setup initially but once it's done it maintains itself. I then use ADFS to SSO straight to Adobe. From what I understand you want to do this: https://helpx.adobe.com/in/enterprise/using/add-google-sync.html to populate users into Adobe from Google and then https://helpx.adobe.com/in/enterprise/using/setup-sso-google.html to setup the federation with Google.
