-
Posts
686 -
Joined
-
Last visited
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Bankesy
-
@mjhardisty I can't remember how we got around this in the end but thanks for the suggestion
-
@Rob_D that makes sense now thank you. @howart_p when you say internal you mean the proper internet\external IPs as @Rob_D and @chaplic have suggested? @chaplic I did read about that setting and ADFS which we aren't using so figured it might not be relevant or there would be an updated way to achieve the desired outcome. In the settings for my named locations I have what was left by my predecessor, 'Name of My School' (with a single IP address that looks like it could be external), this is marked as Trusted and I've added it to the excluded locations on the Conditional Access policy. Maybe that IP address isn't right or has changed. In the Conditional Access policy I also have an exclusion for 'Multifactor authentication trusted IPs', I don't know where this has come from unless it's generated by me having the "Skip multi-factor authentication for requests from federated users on my intranet" box ticked? Thanks again
-
@Rob_D So if I'm following that correctly you've set it up so your users don't get prompted for MFA outside of the network? I'm coming at this from the angle of exclusion = place you don't want users to be prompted for MFA So I'm trying to exclude MFA prompts internally but include them externally
-
Good morning all, I'm in the process of setting up MFA for Office 365 for our staff, I'm using conditional access policies to do this and the testing has gone well. I used the Combined Security Registration Info method to get a test user to register (this worked and SSPR is fully working). Then set a conditional access policy to require MFA for Office 365, this is also working except it asks at every login even inside the network despite me thinking I have set it to not ask inside the network by ticking 'Skip multi-factor authentication for requests from federated users on my intranet' Something I'm missing? Thanks
-
Good afternoon all, Just wondering if anybody knows why I might be getting the following behaviour on one account and not others given the config below: I've setup 2FA via a conditional access policy in Azure and added a user group, users in that group get prompted to setup 1 authentication method for 2FA and it works thereafter no issues. Except my account (which is in said group) gets prompted to create 2 x authentication methods...because I'm a global admin maybe? Thanks
-
@dmj @Frodo_Baggins Thanks for your replies, I was able to see my predecessor yesterday who set all of this up in the first place and it seems like I'm getting that error because the administrator account isn't authorised to set one of the permissions from the list produced during the GAM setup. If I select just a few at random I no longer get the error so hopefully I can work out which ones I am allowed to set and which ones I actually need to be able to manage groups via GAM.
-
@Mako Thanks for this, I read through all the Microsoft discussion stuff on this yesterday.
-
Good afternoon, Has anybody seen this behaviour before? A 'Connecting' dialogue box that appears and hangs there the first time users try to open or save anything in Office applications for the first time every day, once connected everything is fine but the box will come back on restart. I've attached an image and I'm wondering if maybe it's DFS\DNS related? Thank you
-
@dmj The administrator account I'm using is on the project as an owner? Thanks
-
@fiza @jthompson I've got a bit further with this: I can now get as far as the part where the browser loads and is supposed to give a verification code but all I get is this: Authorization Error Error 400: admin_policy_enforced Account restricted Learn more Request Details The content in this section has been provided by the app developer. This content has not been reviewed or verified by Google. If you’re the app developer, make sure that these request details comply with Google policies. Anything obvious that I'm missing? I'm using the main super admin account for the organisation and have temporarily set the one OU we have to 18+. Thanks
-
Good afternoon, Hoping somebody can explain to me or walk me through how certificates should be applied or renewed for Workfolders on server 2016, in this environment I've inherited it would appear a certificate that was making all of this work has expired and subsequently client devices no longer sync documents. I can see the server has Lets Encrypt installed and to me it looks like the certificate has auto renewed but I'm very confused now about what that means, am I supposed to find\export the certificate from somewhere and then import it\deploy it to clients? Thanks
-
@fiza Yes I see that setting now, my assumption is that my predecessor marked it as everybody over 18 to setup GAM and then switched it back or did something clever to mark the one account he was using for setup as 18+ maybe. I really don't think there is any differentiation, I've just inherited this the way it is.
-
@fiza When I look at the Organizational Units it appears there is only one, named after the domain. I can't seem to do much with it or set age limits and the administrator account is in that OU. Thanks
-
Good morning, Hoping somebody here can help me as I am new to Google Classroom and GAM and keep getting stuck when trying to configure it. I'm still quite new to my current environment but as I understand it the last IT Network Manager had GAM setup on his PC but this installation was lost. I also gather that Azure is syncing any distribution group from our Active Directory to Google. All I'm trying to do is configure GAM so I can mass delete duplicate groups on the Google side but every time I try to setup GAM I get as far as being asked to visit this site: https://console.cloud.google.com/apis/credentials/... Only to be redirected to families.google.com and told that I cannot access the service as it is "unavailable for Google Workspace for Education users marked as under the age of 18 by their administrator" And I get this even when using the administrator account so something isn't right somewhere I suspect. If anybody has any ideas I would appreciate it. Kind regards
-
@chaplic Seems like it might have been my doing actually, I think where I enabled the licenses for Exchange Online but was running Powershell commands to create mailbox on prem. Seems to be fine now that I am running the correct commands to only create the mailbox in the cloud. Also, I haven't worked with Exchange a lot but I think I've got my head around how the Lets Encrypt certificate expires every three months and then needs adding to ISS, enabling for SMTP and then selecting in the Hybrid Config Wizard. Thanks
-
Hiya, I don't exactly know what was or wasn't setup, I just inherited it a few months back. I don't have many duplicate mailboxes in O365 but would be nice to clear them up and know that communications work both ways so we can migrate.
-
Good afternoon, Could somebody help me with where I'm going wrong please? I'm trying to create a migration endpoint in Exchange 2019 (because I think I need to in order to move some mailboxes from on prem) but I just can't seem to figure out what the wizard is asking for when setting it up. I think there was previously a migration endpoint configured but seems like maybe updates\restart wiped it out. The wizard seems to want an example e-mail to migrate, then some domain\administrator credentials, pretty sure I've got all of that correct but then I just get an error telling me that the migration point couldn't be created via AutoDiscover and that I need to enter the FQDN of the server where MRS is installed (which I presume is the Exchange server). This is followed by an error telling me that a connection couldn't be established. Basically I'm trying to fix the weird hybrid mess we've ended up in with some mailboxes on prem, some in cloud (some users appear to have on prem and cloud mailboxes) and only only one way communication between on prem and cloud (no communication between cloud mailboxes and on prem). ...rant over
-
@round2it I'm not trying to block it entirely, at this particular point I'm trying to make it so staff can download the SIMS CTF files they need (XML) but the way the current policies are setup for Chrome and Edge prevents this. Thanks
-
@tomviv I mean groups, staff are creating\deleting\archiving classes of their own accord. When they invite students to the classes they do so through the mail enabled groups that have been created in AD. I'll check out the links as deleting the groups on the Google side is exactly what I'm trying to do, I'll also take a look for the scheduled task. Thank you
-
@FN-GM My apologies, the query concerns client devices. I just posted here because because I'm using group policy on Server 2019 and couldn't see another sensible thread for the query. Thank you
-
Good afternoon, Wondering if somebody can help me with this please? I've noticed that in my new environment downloads from browsers are being blocked, things like .exe and .xml (for SIMS CTF files). I figured it was a GPO preventing this and indeed upon testing this appears to be the case and I have found an existing GPO which has 'Allow download restrictions - Enabled \ Download restrictions - Block dangerous downloads' for both Chrome and Edge. I haven't seen or used this policy before so I'm wondering if: A) that is set correctly because it seems super restrictive B) if it's set correctly is there a way I'm supposed to allow exceptions Thank you
-
Good afternoon, Hoping somebody will be able to help me with this as I have no Google Classroom experience but find myself in an environment where it is already setup. Essentially I've managed to understand how my predecessor was creating groups from SIMS in AD via PS script and these have synced themselves to Google Classroom without me doing anything else but they appear to have merged with last years groups. I gather from the vague instructions I was left that maybe I was supposed to delete\archive the existing groups in Google Classroom? Maybe using something called GAM? But this is where I'm lost... Thanks as always to anybody who reads\responds
-
Good morning, Does anybody have any experience with Bluerunner Cashless Solutions for their catering please? Thank you
-
Hiya @timbo343 Thanks for your input, just wondering if you would disable Sophos on a per PC basis on some of the affected clients or more centrally?
-
Good afternoon, Super vague issue I think but not really sure where to start, since returning from the summer break I'm seeing a widespread issue across our network with Windows 10 being much slower to boot up and very slow browsing when using Edge. I can't think of much that has changed other than restarting a few servers to install updates and the new cashless catering system that has gone in. Just wondering if anybody else has seen these behaviours with Windows 10 or Edge recently? Thanks
