Jump to content

Koldov

Members
  • Posts

    5,084
  • Joined

  • Last visited

Everything posted by Koldov

  1. Yes, very annoying as it doesn't actually even kick you out whilst the tab is open on screen, only when you go to do something else! Hence me sitting on a complicated (well, for me) GMail compliance setting for a while, then when happy and finally hitting 'save' it just kicks me out... sign back in and... no sign of the setting I was working on...
  2. Possibly, but the migration was set-up by a 3rd party consultant and I didn't have anything to do with it (only cleaning up the mess). Are you saying somehow adding a Microsoft O365 domain into Google Workspace and making all Google accounts with the O365 address as an alias would mean emails sent to O365 would then go to Google....? I'm sure I haven't even scratched the surface of what Google can do as I've only just started to look into it in any depth, but at the time the Head wanted it done yesterday (as we already had Google Workspace set-up in a basic form for distance learning over lockdown), so the consultant said just do a migration of emails and set-up forwarding for a month or so... Also, they were quite insistent that after that time the old O365 domain be into the ether, so maybe this was an easier way than adding domains and aliases and then, removing domains and aliases from all the accounts...? Or they didn't even know it was a possibility...
  3. Haha I have no idea, that's why I'm asking! Yes, sent to the old O365 domain and then 'sent' from that domain/forwarded to the new GMail account. It's not a transparent thing, the old domain actually receives the email and sends it. On a test email in GMail, clicking on the drop down next to the To: shows amongst other things... from: [email protected] - via - olddomainco.onmicrosoft.com to: [email protected] and mailed-by: olddomain.co.uk
  4. Thanks, that's great. So I'm on the right track at least! Anyone know what I'm looking at setting in terms of section 2? "2. Add expressions that describe the content that you want to search for in each message If ANY of the following match the message Expression Add expression" I'm looking at 'Advanced Content Match' then I need to add a location, possibly one of these choices out of that list... Full Header Sender Header Envelope Sender Then 'Content to look for' = oldemaildomain.co.uk Then Section 3. If the above expressions match, do the following 'Subject > Prepend the custom subject' = "THIS MESSAGE WAS FORWARDED FROM YOUR OLD EMAIL ACCOUNT!"
  5. Honestly I only skim read and got to the part that said: Understand dynamic group membership Membership in dynamic groups differs from other groups in that: You can’t add people to the group manually You have limited options for assigning permissions Only users can be members. and wrote it off as a solution (I've snipped the full explanations, the above are just the bullet points)...
  6. Thanks, yes the Google accounts in my original post were indeed used as Apple IDs (back before MDMs when you had to use one Apple ID to assign the app to 5 devices iirc). I'm hopeful we have left all that behind quite a few years ago now and that there aren't any apps that we use now linked to those as we use a singular VPP/ASM account now for app 'purchases' (always the free ones!). Volume Purchase Program originally for Macs I guess?
  7. Thanks, another reason for this being a good thing for me is that a few years ago our Headteacher decided (without any consultation of course) that he wanted a better 'electronic' calendar... He decided that he would create all staff a (personal) Google account... to make matters worse he decided that he would use our O365 Domain name to create these accounts and to top it all off ignored the fact that once we had created a school Google Workspace (for Classroom and distance learning over lockdown), we could have transferred it over. You can imagine the hilarity that ensued with staff having to sign-in to two separate Google accounts and the SLT deciding that they were going to use the 'personal' accounts for sharing 'SLT stuff' in their drives... Anyway, it's all sorted now and we are using the school Google Workspace exclusively, however... it has been suggested (by me) that all staff now sign-in to their old 'personal' Google accounts and delete them. Unfortunately as I'm sure you all know this is NEVER going to happen, so unless I force the issue and literally stand over the shoulder of each of the 60+ staff members and watch them do it (plus the agony of at least 90% of them not remembering their passwords - with no way to reset them - and a good percentage 'who aren't very good with computers') there isn't much I can do. Should I just drop it and hope Google will eventually delete these accounts..?
  8. I am quite often asked to re-input my password whilst using Google Workspace Admin console and it seems to happen very frequently. For instance this morning I had been working for a while after signing in this morning, used another tab in the browser to research something (for 10 minutes maybe) and then switched back to the Google Workspace tab, clicked on a Menu/Settings link and it asked me to sign in again... As I say it happens a lot and I figured there must be a session control policy, so I researched where that would be (Security > Google Session Control) and found it was set at 14 days! I'm guessing this is a default though and it doesn't explain what I'm experiencing... The other explanation could be that once signed-in that it asks me to 're-verify' my credentials if I select a 'security/sensitive' menu/setting but that's a bit overkill... and is it really that 'aware'?
  9. Not much to add here as it's all in the title, but basically once a user is created and added to an OU, is there anyway (through the 'Admin' console) to set something up that then adds them to a 'Group' for mailing list purposes? Examples: A user is created, added to the 'Teacher' OU and is automatically added to the 'Classroom Teacher' group and 'All Staff' group. A user is created, added to the 'Admin Staff' OU and is automatically added to the 'Admin Staff' group, Reception Staff' group and 'All Staff' group. I've seen things like 'Dynamic Groups' but it seems like overkill and I think removes some 'Group' management options and using the option when adding a user to go Advanced > Add all future users to... it's a bit nuclear, but something like this functionality only for a specific OU and a specific group? I've also seen it may be possible to use Google Cloud Directory or GAM, but I'm not anywhere near this level/ability yet, so if it's not possible to automate it through the admin console, I'll carry on doing it manually as it's not a massive issue but more of a nice to have automation and one less thing to think about...
  10. Any GOOGLE WORKSPACE/GMAIL gurus in here? As we've moved to GMAIL our old O365 tenant is forwarding emails from the old accounts for a period of time. It's been a while now but I've just looked at the stats and it's still a pretty impressive amount. I've sent emails to remind users they should be updating and contacts/suppliers/websites with their new email addresses, but you know how it is... Admittedly, a lot of it might be spam or phishing so it might not be actually getting though at the GMAIL end, or they are emails that the recipient just isn't bothered about. It could be that they've forgotten all about it already and aren't even looking to see where the email has actually been sent to, but I thought I could make a rule that would append a header to say that it has been forwarded. To save me floundering about in the GMail menus (if that's where it should go), if it's possible can anyone give me a step-by-step instruction please on the easiest way to do this? I though it would be GMAIL > Content Compliance: 1. Email messages to affect = Inbound 2. Add expressions that describe the content you want to match (If any of the following match) = oldemaildomain.com 3. If the above expressions match do the following = Add custom headers Bit lost here on 'X-Header Key : Header Value' or Prepend the custom subject? or 'Options'... Address lists Only apply this setting for specific addresses/domains... and create a list somewhere with just the old domain on??
  11. I didn't see anything... because I didn't bother to look... Pretty much ignore the "Oooooh, you might be able to see the Northern Lights tonight" because I live quite far down south (plus lots of light pollution around where I live). In my ignorance I've always thought it was for those lucky (?) enough to live in the Northern Isles of Scotland and sometimes those in the far North of England might even catch a glimpse (on the rare occasions when it isn't cloudy/raining). But then I see on the news about people in Essex and even Cornwall seeing them!
  12. Not sure if any of this will help as you don't say what you actually have in place at the moment in terms of mitigations, but there is a similar thread here: /forums/internet-related-filtering-firewall/232488-youtube-semi-obscene-advertising.html There haven't been any complaints here, so I haven't needed to look into it and therefore can't tell you if what we do actually stops those kind of adverts or not... Can't remember exactly as it was all set up so long ago, but we have an LGfL setting iirc (defaults non-signed in users to 'restricted' YouTube), a Chrome GPO setting safe/restricted mode (maybe deprecated now), all teachers need to be logged in to their Google Account (and the default YouTube setting is strict restricted and approved videos only), we also have uBlock Origin.
  13. Another issue has meant I need to look into our file server shares and permissions and I need to do some changes, but want to do it safely and with minimum downtime. It's a legacy server (in-place upgraded from 2012R2 and possibly 2008 before that), but the shares themselves have existed since the dawn of time. I haven't had to make many new shares for a very long time (maybe the odd folder here and there) and for the ones I have, I've normally needed them for special purposes, so blocked inheritance and set permissions explicitly. For some parts though I have just followed the settings on all the other folders (one of those is that the users get the NTFS Security permission - FULL CONTROL). Recent comments in other threads though suggest that these settings are at best, not good practise and at worst a security risk. We have a main data drive where the majority of shares reside, and this has the following settings: SHARING NOT SHARED SECURITY AUTHENTICATED USERS - MODIFY SYSTEM - FULL CONTROL ADMINISTRATORS (SERVER\ADMINISTRATORS) - FULL CONTROL USERS (SERVER\USERS) - READ & EXECUTE Creating a new folder (as I would to create a new 'root' share) on this drive gives the same default/inherited NTFS Security permissions. Sharing the folder gives the default sharing permission of: EVERYONE - READ So, question... When did that change? I seem to remember the default (and widely repeated best practise) being: EVERYONE - FULL CONTROL for the 'share' permission... However, on the drive I have looked at most of the TOP LEVEL (root?) shares and found the following permissions on the biggest two: STAFF (Inheritance Disabled) SHARING EVERYONE - FULL CONTROL SECURITY 'STAFF' (SECURITY GROUP) - FULL CONTROL DOMAIN ADMINISTRATOR - FULL CONTROL DOMAIN ADMINS (DOMAIN\DOMAIN ADMINS) - FULL CONTROL --------------------------------------------------------------------------- ADMIN (Inheritance Disabled) SHARING EVERYONE - FULL CONTROL SECURITY 'ADMIN' (SECURITY GROUP) - FULL CONTROL DOMAIN ADMINISTRATOR - FULL CONTROL DOMAIN ADMINS (DOMAIN\DOMAIN ADMINS) - FULL CONTROL I know this should be basic bread and butter of an IT admin and it's a pretty basic/obvious thing, but these were all created before my time and although I know I need to 'tidy them up' I'm just wary of making changes to hundreds of folders, thousands of files, with data totalling many 100s of GB. Also I think part of the issue is that for the 'special' shared folders I have created, I mostly just made a folder (although inheritance is blocked for them) within one of the other 2 main shares, rather than creating a new 'root' share to save having so many 'drive' letters for all the different shared folders... Anyway, in the first instance I've obviously been advised to 'nuke' the FULL CONTROL (NTFS/SECURITY) permission for any 'standard' user/group. To do this I would just untick it at the root share folder from the 'SECURITY' tab and wait for it to propagate down ignoring any errors when it hits any 'special' folder with inheritance blocked. This shouldn't actually break anything, I hope?
  14. It might be permissions for these particular folders, but it's a bit more complicated... the '\\servername\share' has full permissions for a security group (Staff) which they are explicitly part of and so does the folder '\\servername\share\myfolder' (inherited), but the subfolders in that '\\servername\share\myfolder\folder1' have inheritance disabled (sensitive data) and are not 'shared' specifically (purely because it is a sub-sub-folder of a shared folder), only certain users (of which they are one) are given access with 'Full Control' NTFS permissions granted and 'Authenticated Users' (again they should be in this group) have read. 'Change' is a share permission, do you mean 'Modify' in the NTFS security permissions? Yes, thanks. So I've got another chance to look at this again for a few minutes... I tried a test folder and it hit a security permission it couldn't change (file in a non-inherited sub-folder I think) and when I quit it left the permissions in an inconsistent state, does it just ignore it if you continue instead of quit...? I would just remove it from the root folder, but the trouble has traditionally been that all folders inherit from the 'root' and this folder has the NTFS Security permission of 'Staff' (security group) having full control, so unfortunately it has always propagated to every sub folder ('Share permission is Everyone = Full Control) so it means a change to the NTFS security permissions on the root and then propagate through 100s of GB and thousands of files: This PC > Data Drive (F:\) > Staff Folder (shared as Q:\)> 70+ subfolders > 300+ GB of data = 'Staff' (security group) NTFS permission = Full control There is another similar folder I'd like to tackle, but for some reason the Headteacher has never complained about files creating the issues in my OP... This PC > Data Drive (F:\) > Admin Folder (shared as M:\) > 100+ subfolders > 100+ GB of data = 'Admin' (security group) NTFS permission = Full Control They are a member of both security groups... Is there anything special permission that I need to give a Mac, application on a Mac (or Mac user) to be able to work with Windows shares? I've seen a couple of things on the server: One being an 'Apple Mac SMB Share Access' security group. The other being on the DC - Primary Group - There is no need to change Primary Group unless you have Macintosh or POSIX-compliant applications... It's so annoying... I just can't get them onto a Window laptop... Even though every application he uses is Microsoft (Office etc.) or OS agnostic like the Chrome browser.... and now Windows 11 looks more like MacOS than ever... it can't just be the position of the @ symbol on the keyboard can it? EDIT: Added to that, I don't have a Mac (obviously) that I can test and I can never get theirs as it's pretty much 'in use' all day... everyday!
  15. Ok, so it's not a big deal really... sorry for the dramatic thread title! However, I just received an email from Google telling me that an account I have is to be deleted... "You're receiving this message because your Google Account has not been used in at least 8 months. If you want to keep your Google Account, sign in to it before June 29, 2024. Take a moment now to sign in to your Google Account. If you do not sign in to your Google Account before June 29, 2024, Google will delete your Google Account and its activity and data." The thing is I do seem to remember this Google account, it was set-up over 7 years ago and is one of at least 10 accounts we created to assign licenses to our iPads. I think this was back in the day before ASM and even before VPP, iirc you had to create an account that you could assign the apps to and then sign in to 5 or so iPads with it to get the apps on each of them. Not sure why we made Google accounts instead of Apple accounts, but we had a 3rd-party consultant back then as we'd never had iPads before and that's what they told us to do... Seems ridiculous now so I'm not even sure if I've got it right, but the main questions are: Do Google delete inactive accounts? Why now, is it a recent thing? Does this mean that all such old, abandoned accounts will eventually be purged?
  16. *Grabs the popcorn and waits for the WUfB lot to arrive*
  17. This is a tricky one, so I'm watching this thread with interest... because I have never fully worked out how to have this set exactly as I want it. I don't let anything install an update automatically, so I give it a couple of weeks and release as I see fit. Some of our VMs run Defender due to needing to keep them quite slim and low on resource use (the hosts run Sophos). I have tried different settings and had disastrous results with servers randomly rebooting (and sometimes the odd VM not restarting), but with other settings they won't even install the Defender definitions even when 'Approved for Install'... As for the OP I would say if you have 'complete control' over releasing updates in WSUS, then you could set the servers to 'check, download and install' automatically and set a small check for updates time. The only way you might fine grain it any further and have servers installing updates and restarting, could be to have different servers in different OUs with different times set in the update GPOs. Also if you could separate them in WSUS release the updates with different deadlines...? I have looked at it many times and ended up going round in circles with all the possibilities!
  18. Just for completeness - I found out this had absolutely nothing to do with being a remote user, firewall or the VPN... It was just FMS (and SIMS) doing a job of installing/configuring/updating its own files! /forums/mis-systems/234012-fms-sql-connection-general-sql-error.html#post2014585
  19. Just wanted to say thanks again to @Steve21 - I spent a few hours a while ago trying to figure out why a remote user couldn't get on to FMS... /forums/mis-systems/235171-fms-remote-access-via-cisco-vpn.html Obviously being a remote user on a VPN added some extra potential issues, but as I couldn't work it out I eventually did a different quick and dirty workaround (which I'm not going to admit to on this forum). Anyway... the user brought their laptop in today but logged in to the domain directly it gave the same error! However, it worked signed on as admin but not as the user (which I couldn't have checked before as I didn't have the laptop) so after another 15-20 minutes of testing why and checking all the FMS/CONNECT/SIMS ini files etc. I thought I'd check for anything that might be a user setting... couldn't find anything, so I thought I'd re-check for posts on EDUGEEK for 'FMS'... BINGO! But why the is this file even there and why doesn't it get updated when all the other 'normal' .ini files do! Good job this place is here and full of awesome (if sometimes a bit random and niche) technical knowledge , it's so much easier than having to write up my own notes...
  20. Yeah that top one in the screenshot is what I get for all of mine, but at least it's not just me doing something stupid because I have no idea what I'm doing!
  21. Yeah, I mean it's definitely a 'different' experience, I'm not used to having the management/admin equivalent of AD, Exchange/Outlook/O365, Office, Teams, and all the other app settings, browser settings, in one web based platform console... and the settings for one part affecting the use of another! Our 3rd-party consultant changed around our OUs and suddenly half the staff didn't have permission or access to most of the Workspace... Ha ha! Well it has been remarked that we are getting noticeably less spam mail, but I reminded them that these are new email accounts and haven't had years of signing up to dodgy resource, 'educational' supplier/sales websites (let alone the amount of 'personal' things that I've seen signed up to with the school email accounts in the past), so we'll see....
  22. Well, I guess most things aren't that complicated once you know how to do them... Just that I've never used groups for anything and coming from an exclusively Microsoft/O365/Outlook (and a little bit of Exchange) background and suddenly having Google Workspace to manage this is all new to me! I guess I'm used to having distribution lists in a place for distribution lists (even though it's under 'Groups' in Exchange), not 'well this is actually part of something else that is actually used for another function but you can use it for a different thing it just needs x, y & z, settings changing'... As I said, just a different way of doing things and doesn't seem very intuitive to me, but I suppose I'll get used to it. Thanks for your help!
  23. Thanks for that, but well... that's a bit weird and not very intuitive... Is there no way to have a centralised GMail distribution list any other way than having to use a work around, or changing some behaviour in another part of Google Workspace? Of course, I'm not used to the 'Google' way of doing things, but it seems a very convoluted way of doing something so basic.
  24. Great, but where are the settings to do that? I've looked a few times now and can't find anywhere to set any rules... Thanks, I will look into that. EDIT: Just tried in an incognito window and still no rule description...
×
×
  • Create New...