Jump to content

Roberto

Members
  • Posts

    2,735
  • Joined

  • Last visited

Everything posted by Roberto

  1. If your filtering solution is blocking enough 'good' websites for this to be massively useful then I would suggest that the root cause is a poor filtering solution or overly zealous settings and the fix is probably not giving the students (or even just teachers, who are often not focussed on whether something will present a DPA or safeguarding issue) a tool to find ways to bypass the filtering.
  2. We do this continuously at my employer. You’ve had good advice and good products already so I will try to add to that rather than repeat it. So… domain names. Do you need to migrate these also? Perfectly possible but you will need to remove the domain from the old tenant before you can update it to be part of the new one. This will mean wanting to have DNS ready to update, and also that you will need to find and remove all references to the domain name in the old tenant’s objects before you can remove it there, and that you need to consider that the migrated users will need their upn updating twice (1st is old tenancy to new tenancy prior to domain name being moved, 2nd is updating them once you’ve properly added their ‘old’ domain name). Have you determined if there will be any clashes between mailbox names or sharepoint site names, whatever? You will need a plan to migrate these. Have you captured permissions? Who has access to what mailbox, Team or sharepoint site? Have you looked at O365 groups, distribution groups, etc to determine if these should be migrated/recreated? Checked if users are using parts of O365 you might not have counted on? E.g. planner or flow or suchlike? Are users issued with devices or provided with byod functionality that is connected to the AAD tenant? E.g. Intune or MFA? How will you update this? If they have AAD-joined devices how will you migrate these? How will you minimise disruption in the meantime? How is spam filtering done? How are they using Conditional Access? 3rd party enterprise app registrations? Do they have anything that relies on, for example, legacy auth access to a mailbox that won’t work on your tenant because you disabled legacy auth?
  3. If you're really worried, can you do a test restore somewhere?
  4. When I’ve used Aruba in the past, both switches and Wireless APs, it’s been absolutely rock solid.
  5. Just ordered a 13 Pro today as an upgrade from my 11. My 11 will almost certainly be going to my partner as an upgrade to her iPhone 8, which we’ll probably trade in. I do tend to upgrade every 2 years.
  6. I blogged about implementing Azure AD/O365 passwordless here if that’s of any use. I don’t think it’s going to be easy to ‘standardise’ this as such, much like MFA push, it’s vendor specific unlike TOTP. However, the two identity providers I’ve got in-depth experience with personally, MS/Azure AD and Okta, both can already be a standard login provider for thousands of applications from hundreds of vendors, including some you’d possibly be surprised at due to rivalries.
  7. You say you’re “not IT” - who is and can they look into things? SQL backups should happen regularly and the SQL management tools can be set to clean up old backups automatically, and whoever is managing this server should set this up. This folder screenshot is a worry - lots of old orphaned backups and from what I can see, no up-to-date backups. Whichever end of the telescope you look through, this is still the wrong amount of backups. Backups can also be set to go to a new drive that won’t interfere with the c:\ drive or your data storage. This would be better for everyone’s peace of mind.
  8. I would probably destroy and re-create the mailbox at this point. The Microsoft.Mapi.MapiExceptionMailboxInTransit error is an internal exchange error and makes it pretty clear something has fallen between the cracks. You can probably remove it via o365/exchange online powershell by removing the o365 licence (or at least the mailbox component) from the user .with something like Disable-mailbox -IgnoreLegalHold -PermanentlyDisable Obviously don’t do this if you’re not comfortable with powershell.
  9. Check account is correctly licenced in the O365 admin console. If you sign in as the user, do other O365 functions work? Go to the Exchange Online admin console and search for the mailbox. Look for obvious differences with a working student account. Can you open account properties once you’ve found the account?
  10. That’s true, if the OP has actually blocked legacy authentication. Merely enabling MFA with the kind of rules an (with all due respect to the OP, based on their post and answers) inexperienced admin has set up won’t do that.
  11. Again, this depends on the specifics of your conditional access policies as to when and if they get challenged at all, but your users will just be asked to complete a MFA challenge (and also may have to sign in generally again). I’m assuming that as you’ve not mentioned it, you have not blocked apps at all, just required MFA.
  12. That rather depends on what, exactly, you’ve set in conditional access. But in broad terms, if they are required to have a valid MFA token to log in via that app then they will have to register for MFA and then complete the MFA challenge the next time their credentials are checked.
  13. That’s very true. You can’t pick a solution for your employer based on how much it rounds out your own CV. Having said that, @Norphy and I did save our then employer nearly 90k by refusing to go to CC4, so probably fair to say it was also in my employer’s interest to go vanilla at the time.
  14. Try removing the device from AAD, autopilot, and Intune. Could it be have been added previously with an old name? Or equally, could the device name be a duplicate of another? The error you post does suggest an identity error of some kind, if other devices are building ok. MENROLL_E_PROV_SSLCERTNOTFOUND 0x80180024 When attempting to bind the public cert/private key, the public cert was not found either: when attempting to bind the public cert/private key, or when looking into provisioning payload (perhaps targeting the wrong store).
  15. Any particular error? Reading this thread feels like pulling teeth.
  16. Im sure Intel are certainly praying that it does.
  17. I’m an ITP sufferer at the best of times and I’ve had no complications from the AZ vaccine. It’s somewhat counterintuitive that ITP would cause clots, it’s normally associated with low platelet counts and an inability of blood to clot.
  18. As a bare minimum, I would keep user settings and computer settings apart. Aside from that, have a philosophy / design that you feel will work for you and then stick with that. For example, you might decide to have all your settings related to end user experience - e.g. changes that affect what the user can see and will do, all in one GPO and all settings related to back-end security that they wouldn't see in another. Not too sure about this one myself, but its a suggestion. I would probably break stuff down into a different pattern based on things I thought would make sense to deliver together, e.g. browser/internet settings in one GPO, settings related to Office software in another, etc. Whatever you choose, breaking things down has the advantage of allowing you to target different settings to different groups of people quite surgically, as well as being able to test and stage a rollout of new settings, whereas if you have fewer, more monolithic GPOs, you're making it harder to troubleshoot and stage rollouts of settings.
  19. We’re quite worried at work I think. Been asked to be extra careful, take a test at least twice a week when going into the office, and I’ve been asked to avoid the tube and instead take a taxi to/from the train station.
  20. I remember that. I came up with a (relatively) safe method of moving from the single processor to multiprocessor kernel for NT4 that pretty much got me my first MVP award by itself when I shared it.
  21. I assumed they meant they had changed from the pattern you suggest (the default, so how do you change to the default!) to the one in their post somehow. In any case, my advice stands; use their phone support service.
  22. Why would you do that? Surely you know you don’t own the AppleID.com domain? Not sure about this specific issue but apple business do provide support for apple business manager on their telephone service. https://support.apple.com/en-gb/business
  23. I think it's a fantastic opportunity in business where companies might currently have a huge investment in on-prem terminal services or Citrix. It should also be a good thing for education if the price is right. Think about the pain of having to spin up special environments for exams? Just use this instead. Working in an environment where all the talk is BYOD but you're worried about licences or a standardised environment to run, e.g. Photoshop? Here you go. Staff or students needing to work from home because lockdown again and your current campus IP over Potato connection won't take it? Hello!
  24. If you own schooldomain.org.uk then you also own appleid.schooldomain.org.uk. You should be able to speak to whoever provides your public DNS for schooldomain.org.uk and ask them to set up a zone for appleid.schooldomain.org.uk and whatever verification entries you need for Apple. This should be an absolutely trivial task for them.
  25. Is it consistent? E.g. if Amanda Huggenkiss and Seymour Butts are both members of group A and are missing from group A in Exchange, are they consistently missing from other DL groups? In Exchange Properties for a problem user, is the box checked for "Hide from address lists"?
×
×
  • Create New...