Jump to content

Aaron

Members
  • Posts

    308
  • Joined

  • Last visited

Everything posted by Aaron

  1. Hi FN-GM thank you yes the servers are setup correctly within Active Directory Sites & Services, no the Domain controllers are on the same site Single domain different OU's. Replication was actually very quick during the initial DC replication and also time sync between both servers is grand. It appears that the 2016 server doesn't seem to be accepting NTLM authentication for some reason
  2. Hi everyone I just thought I would chance this and ask if anyone has had any issues with server 2016 and NTLM authentication at all? I have setup a new server running 2016 and set this as a second domain controller (primary based at another site) both sites are connected via site-to-site and appear to be working fine. I have the users using the local dc as authentication but it appears that this isn't actually working. I tried to setup a radius server on my firewall again based at site B but authentication always fails. Also when the site to site failed (One morning) no one could authenticate with the local DC. I honestly cant seem to see any errors on the DC around authentication but this could be because its running auth through the site-to-site back to primary DC. With the raidus once it was changed to for users to authenticate with the primary domain controller (Site A) the radius server worked perfect. As soon as I switch back to Site B domain controller it fails but again I cant see any errors to state that this has failed other than bring the site to site down and test again. has anyone had any authentication issues at all running both a server 2012 and 2016 domain controllers? Thank you.
  3. if that was only for ourselves that could work fine but its for others who will not be accessing through a web page only the use of PDF
  4. Anyone have any idea on software which could possibly do this?
  5. Hi everyone hoping someone could help me with this one, i have been asked to see if we could find sofware that would allow us to created editable pdf documents but will also allow expandable text boxes without losing the formatting. I had looked at livecycle but from what i can this has been discontinued and i would need something that would work on windows 10 professional. Has anyone any experience with any software that could do this?
  6. Thank you i did take a look at this which would work perfect if all devices had been located within the one location but because i have laptops and tablets being used out and about it wouldnt work for me without the users using a VPN to remote back into the office and out through our firewall. I also looked at the onedrive admin centre and seen that i can restrict to a set of IPs which is helpful for multiple sites but again its restricted access to within the site which works perfect for desktop computers but not for any mobile devices.
  7. Thank you i will take a look at this now but thats very handy to know.
  8. Hi everyone I just wanted to ask if anyone has limited access to office 365 to only approved devices (mobiles/Tablets/computers) if so what did you use to do this. I know i can use the basic MDM functions to limit access to exchange for mobile devices but what about onedrive and sharepoint login? Is it possible to lock everything down so that its only accessable via an approved device or company owned device? Thank you.
  9. for anyone else that maybe gets this I just followed the below steps: First make sure your bios has secure boot turned on. Next, build your USB stick with Fat32 Then install normally. The 11 steps for manually preparing / building a USB Disk to be a bootable Win 10 Install. This bootable USB stick will work for both older BIOS installs as well as the newer UEFI installs. 1. Diskpart (Run from a CMD prompt) 2. List Disk 3. Select Disk # (Where # is the number of your USB disk) 4. Clean (removes any partitions on the USB disk, including any hidden sectors) 5. Create Partition Primary (Creates a new primary partition with default parameters) 6. Select Partition 1 (Focus on the newly created partition) 7. Active (Sets the selected partition to an active valid system partition state) 8. Format FS=fat32 quick (Formats the partition with the FAT32 file system. FAT32 is needed instead of NTFS so that it can load under the secure boot UEFI BIOS.) 9. Assign (Assigns the USB drive a drive letter) 10. Exit 11. Copy all the files from the Windows 10 isO to the USB Stick. that's the exact process that's worked for me
  10. yes it boots straight into installing windows as soon as I setup the usb with DIskpart and formatted as Fat32 so that looks to be it working now with secure boot and TPM now. again thank you for suggestions
  11. thank you yes I have made sure TPM was enabled but it comes through as TPM ready with reduced functionality. I am trying now by setting up the USB as Fat32 so that I can install with secure boot switched on and hopefully that will do the job. I had used the windows USB creation tool to make a bootable usb and added the ISO so I am hoping that setting the USB with diskpart will solve the issue I will repost if this works. Thank you for the suggestions
  12. I am really hoping someone can help me with this one. I just recently purchased an HP laptop (HP Pavilion X360) which can preloaded with windows 10 home edition and I needed to install windows 10 enterprise. I went through the steps to enable legacy boot which allows me to boot off USB and I installed a fresh windows 10 enterprise edition on the laptop. Right now everything was going great the OS installed with no issues activated and I started to install the software and its from here I noticed a problem. As soon as I tried to install the encryption software the laptop would restart but not encrypt the only difference I could see was over the legacy support which must have disabled TPM which I need for encryption. When I disable the legacy support and enable/disable secure boot and restart the laptop comes on to say no OS has been installed, although if I enable legacy support and restart the laptop boots into windows 10 enterprise. The only thing I can think of is that the TPM is setup with the pre loaded windows 10 Home edition and what I wanted to know was is it possible now that I have windows 10 enterprise installed on the laptop that I can enable the TPM and secure boot with this OS? Has anyone had this problem before?
  13. Thank you TSEARS I did try the cookies as a possibility but no it doesn't allow the SSO, at the moment it look like I am going to have to direct the page to the sharepoint link and have people click the email address before it will load. I am hoping that at some point this will change for domain machines because although the SSO works its still requires the end user to click the email account before the page will automatically load for them.
  14. Hi everyone just wanted to ask if anyone has been able to find the branded pages urls for office 365? I have added the branding to the pages but can only seem to see these on specific pages - Outlook online page and the main Microsoft login page will appear branded when using the correct url but for some reason when I try to use the sharepoint online link it appears as a standard Microsoft until you login (then briefly) the branded page appears. Anyone been able to see if a specific url is available for people to see the company branded page?
  15. Thank you TSEARS I will clear the cookies and try again I was on with Microsoft for a while but although the SSO is working correctly its just trying to fine tune to suit ourselves or at least make it as simple as possible without the need to keep clicking email from domain computers - as I say from laptops outside the office I have no problem with this as an extra layer of security but from domain computers I was hoping that with SSO I could configure something which would allow automatic login to the services
  16. I was in the process of setting up an ADFS server until I seen Microsoft released a new version of the Azure AD Connect which allows single sign on and so I am only using that not my own ADFS server.
  17. Thank you Michael I have tried that but it keeps prompting the user to click their email address before logging into the site which I am trying to bypass completely. - - - Updated - - - Thank you Jonah I will take a look at that now.
  18. Hi everyone so I have SSO working with office 365 and for the most part its very good although even though this is working I am still asked to either click my email address to login or click email address and then select work created account before it will allow me to login. This is the same with SharePoint online I need to do the above. Has anyone managed to get a way around this so that from domain computers the domain user does not need to click anything but it seamlessly login to SharePoint/office? I understand outside of the office the need for the login which is fine but from within the domain while azure ad connect and single sign-on is working anyone managed to work around this? I have tried adding the site to local intranet and also trusted sites testing both times but once I navigate to the site it still asks me to click on the email address and then click on work/school account (in which case SSO kicks in) and the user is logged in. The only issue with this is if I move to SharePoint 365 and direct this as the first loading page every morning all users will need to click their email and then click work/school account to access the SharePoint site (I know its not a massive issue) but trying to make it as seamless as possible.
  19. I have tried adding the site to local intranet and also trusted sites testing both times but once I navigate to the site it still asks me to click on the email address and then click on work/school account (in which case SSO kicks in) and the user is logged in. The only issue with this is if I move to sharepoint 365 and direct this as the first loading page every morning all users will need to click their email and then click work/school account to access the sharepoint site (I know its not a massive issue) but trying to make it as seamless as possible.
  20. Hi everyone so I have SSO working with office 365 and for the most part its very good although even though this is working I am still asked to either click my email address to login or click email address and then select work created account before it will allow me to login. This is the same with SharePoint online I need to do the above. Has anyone managed to get a way around this so that from domain computers the domain user does not need to click anything but it seamlessly login to SharePoint/office? I understand outside of the office the need for the login which is fine but from within the domain while azure ad connect and single sign-on is working anyone managed to work around this?
  21. thank you ricki oh I understand this will mean allot more additional work for setups but i am hoping that it will also improve reliability especially on the IP phones. At the moment because it’s all covered under a single large subnet and the phones are not vlan off the QoS is not great so this is also another reason why i would like to get this working as well as the new wifi network I am installing.
  22. thought I had this and everything was working great but then noticed this morning that the policy is set to "not configured" and the logs are only collecting 5145 event id
  23. I think i have this solved. if a folder is deleted it logs an event with 4660 but i have to compare the handle ID in event 4660 with event 4663 this will tell you what object was deleted. ID 4663 is generated just before ID 4660 so easy to find and compare. if a file is removed it looks like it generates an event ID 4659: object was requested with intent to delete (this one tells you the object name) following on from this id it seems to generate a 4658(handle to an object was closed) then 4656(handle to object was requested) and 4658(handle to an object was closed) again. event ID 4659 is only generated when the file is deleted tried this a few times by clicking delete and then selecting NO this only generates the 4658, 4656 and 4658 again. but as soon as you click delete and click yes the event log generates the 4659 followed by 4658, 4656, 4658. hopefully this will be of some help to others.
  24. i have just double checked and the event view is recording IT 4663, 4658 and 4656 but again these logs are only telling me an attempt was made to access the file they dont actually tell me if the file was deleted, i have just checked on a user and the logs are written but the user was only accessing the file not deleting the file.
  25. Hi everyone i was wondering if anyone had setup auditing on a server to find out who has delete a file/folder and could shed some light on if i have gone wrong: I setup the local security setting: local policies - audit policy- aduit object access - Success I have also set on the folder: Properties - security - advanced - auditing - added groups/users - type (success) - this folder, subfolders and files - permissions (delete subfolders and files, delete) & replace all child object auditing entries with inheritable auditing entries from this object. Straight away my event viewer, security logs have started showing allot of events (Mainly ID 5145 detailed file share) and if i try to say no auditing for this all events seem to stop. I am only interested in the success logs for a file/folder deletion and was wondering have i done something wrong that anyone can see. I have been adding files and deleting under my own account which is also under the folder auditing but its not showing me that i have deleted the file/folder. I am running server 2012 and 2012R2 and from what i could find the logs i should be interested in are 4660, 4663 and 4656 can anyone shed light have i missed a step to get these logs because the ones it seems to be showing me more is that if somone has made an attempt to access an object (not showing me that they have actually deleted the object)
×
×
  • Create New...