Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

abaxter2

Members
  • Posts

    167
  • Joined

  • Last visited

Everything posted by abaxter2

  1. I am sure you would have already done this as part of the SSO, but I did have to turn on modern authentication in Exchange Online: https://support.office.com/en-us/article/enable-or-disable-modern-authentication-in-exchange-online-58018196-f918-49cd-8238-56f57f38d662?ui=en-US&rs=en-US&ad=US
  2. Yep - no email address or password prompts and the fist thing you see is the site - as long as you have permission to view that site ;-)
  3. Is SSO working? IE: a user goes to outlook.office.com/owa and is signed in without entering a password etc? also in the office client such as Word is the user still signed in? and is just missing the connected services? Also in your last post you mentioned that the "Belongs to:" is missing - I can confirm this is the same with my clients and at this stage putting that bit down to an update.
  4. I can see that device is activated with a: onmicrosoft.com account - do your users sign in with a onmicrosoft.com account? or a custom domain? if a custom domain is this setup in azure ad connect? You can also check that the hybrid join has worked by going to the azure portal > Azure active directory > devices and search for the device - you should then see the device listed under JOIN TYPE as "Hybrid Azure AD joined"
  5. Of course I do not know your setup and what services you use, but with mine I have no ADFS and use Azure AD connect for SSO + hybrid join - on my local lan no user is asked for a username or password when opening Office clients / accessing outlook on the web / Onedrive / Sharepoint / Windows store etc. You also have high availability by installing the Azure ad connect sync client on a second server: https://docs.microsoft.com/en-us/azure/active-directory/hybrid/how-to-connect-pta-quick-start#step-4-ensure-high-availability I do of course understand that you if are not currently using Azure AD connect then there is a lot to consider, and I am sorry that I cannot be more help with your current setup.
  6. Nope - Azure AD connect is a free product, and I can confirm you do not need Azure AD premium to use this feature.
  7. As you mention you have not tried Hybrid Domain Join yet - I have Azure Ad connect SSO + Hybrid Domain Join and can confirm that using the Hybrid Domain Join feature in Azure AD connect does sign the users in and does not give any warnings or messages about allowing my organisation to manage my device. Also with the Hybrid Domain Join feature in Azure AD connect you can also set a GPO to only allow apps from Windows Store for Education.
  8. In my setup this has changed to the: "Security and Compliance Center" > expand Threat Management > > Review and then choose Restricted Users. More info here: https://docs.microsoft.com/en-us/office365/securitycompliance/removing-a-user-domain-or-ip-address-from-a-block-list-after-sending-spam-email
  9. Yes Hybrid join is free - part of Azure AD connect. Before I used Hybrid join I did have Azure AD connect setup with SSO, but found that even tho my users was signed into the Office clients they were not signed in to "connected services" such as OneDrive etc, after setting up Azure AD connect with SSO and hybrid join all works as it should (on my setup anyway) if you are already using Azure AD connect for SSO I would say give hybrid join a go to see if this helps.
  10. We are using Azure AD connet and over the summer added hybrid join: https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-managed-domains And since doing this users are signed into office clients / Microsoft store etc - if you are only using Azure AD connect it might be worth checking this feature out.
  11. Depends if you are using intune for education and used the setup schools pc app to enrol the devices - if so letting the devices upgrade will break the package used to enrol the device, meaning that the settings that you configured via the app / package will no longer apply. For me I still prefer to do my upgrades in summer break, gives me the time to test and make sure all is working as I intended.
  12. We went down the route of: Azure AD connect pass through last year - works great for browser SSO but did find that local AD devices did not sign the users into office clients (word etc) did the hybrid join this summer with my annual windows 10 upgrade and now SSO works for all Microsoft services, so far very happy with the outcome.
  13. You can do this via azure AD connect, but you need to hybrid join you local AD devices: https://docs.microsoft.com/en-us/azure/active-directory/devices/hybrid-azuread-join-manual-steps And after syncing your devices check the following: https://docs.microsoft.com/en-us/azure/active-directory/connect/active-directory-azure-ad-connect-hybrid-azure-ad-join-post-config-tasks
  14. +1 for DNA, moved from impero a year ago and have not looked back. I have also heard that impero has improved over the last 6 months, but again was to late for me. Very happy with Netsupport and would easily recommend.
  15. Depends on how you licence, we have an OVS-ES and ordered enough to cover our staff and added the student benefit Office 365 ATP, the ratio is 1:15 (1 staff licence = entitled to 15 student benefit licences) Do not get me wrong as it has taken me a number of months to get my reseller to find the correct part numbers ( in the end I contacted another reseller who sorted the parts numbers within a day!) and it is possible via OVS-ES, in fact I now have the student benefit licences for: Azure AP P1 / Office 365 ATP and Intune for Education - all student licences are free. Ask your reseller about "Office 365 Advanced Threat Protection for students" / "OVS O365 AdvThreatProtect Stdnt Bnft 1Y Lic AP" this part number might not be the same from your reseller but if you have an OVS-ES then try this part number: W79-00002 O365ATPOpenStu ShrdSvr ALNG SubsVL OLV NL 1Mth Acdmc Stdnt STUUseBnft £0.00 per user You can also get the student benefit via CSP licensing.
  16. We use office 365 ATP and yes you can set policies at targeted users, so yes only licence the users you want office 365 ATP to apply to - but students get free licences anyway so would not cost you anything
  17. Hi All, I am having a hard time with my reseller at current trying to get quotes for Microsoft services, I currently have an OVS and my understanding is that with an OVS you can purchase on prem and cloud services (see attached), but my reseller keeps informing me that if I want cloud services I have to purchase via CSP. As I do have on prem and cloud services an OVS fits my needs and I would like to order services via my OVS. Over the last year we have been adding more cloud services such as Intune for education / Azure AD premium, and every time they provide a quote via CSP, and I have to keep saying I want the quote via OVS - after a lot of to and fro they do provide a quote via OVS, but they keeping telling me that the option via OVS will not be a option soon - but I cannot find this information anywhere nor have they proved that this is going to be the case. I am currently looking onto the following products: Office 365 ATP: https://products.office.com/en-gb/exchange/online-email-threat-protection They are working on an OVS quote but sent me the wrong product. As Office 365 ATP is included in Office 365 A5, I was also after a quote for Office 365 A5 - they will only provide a quote via CSP Windows defender ATP: https://www.microsoft.com/en-us/windowsforbusiness/windows-atp Microsoft have informed me that this is not an addon but included in Windows 10 education E5 - Windows 10 Education E3 is already included in my OVS, and Microsoft have confirmed that I can order Windows 10 education E5 keys via my OVS but my reseller is not supplying a quote. Microsoft 365 A5: https://www.microsoft.com/en-GB/education/buy-license/microsoft365/default.aspx# as this would include all the services that I require in one licence, but again they will only supply a quote via CSP. Has anyone heard that OVS is not going to be an option anymore? and is anyone having problems ordering services via their OVS? Many thanks for your time. transactional_licensing_comparison_chart.pdf
  18. In Windows 10 you can set the following: Computer Configuration\Administrative Templates\Windows Components\Search\Allow Cortana Setting "Allow Cortana" to "Disabled" will not search the internet and will just search the device
  19. PaperCut NG? https://www.papercut.com/products/ng/
  20. As everyone has already said you will not be able to stop taking a photo etc but if you use office 365 you could use the following: https://docs.microsoft.com/en-us/information-protection/deploy-use/configure-usage-rights#do-not-forward-option-for-emails This would not allow the user to forward / print or copy, it's also free for education.
  21. We do it here and needed azure ad premium 1, works a treat as can white list the school site so MFA is only required off site, you pay per user and we added to our OVS. https://docs.microsoft.com/en-us/azure/multi-factor-authentication/multi-factor-authentication-versions-plans
  22. Hi all, I have been finding when I try to import updates into my WSUS running windows server 2016 I was getting the following error: "This update cannot be imported into Windows Server Update Services, because it is not compatible with your version of WSUS" It now seems at long last that Microsoft have confirmed there is an issue: "We have confirmed that there is an issue with the import functionality on WSUS 10.0 and until it is fixed, we can use the following workaround" https://social.technet.microsoft.com/Forums/en-US/122b4681-3938-405e-83f8-a7cd59ad25c1/will-this-update-kb4057142-be-made-available-in-config-manager-wsus?forum=winserverwsus The work around is: when you click on "Import Updates..." from your wsus server you need to add a ? to the end and the change 1.20 to 1.8 IE: Microsoft Update Catalog This has to be done in internet explorer. before adding a ?: Microsoft Update Catalog After adding a ?: http://catalog.update.microsoft.com/v7/site/Home.aspx?SKU=WSUS&Version=10.0.14393.1914&ServerName={YOURSERVERNAME.YOURDOMAIN}&PortNumber=8531&Ssl=True&Protocol=1.20 After adding the ? just change 1.20 to 1.8 and you will be able to import updates again!
  23. Just to mention that the "Remove Run from the Start menu" does not stop the user using the Windows 10 search on the taskbar - if a user types a UNC into the windows 10 search / cortana that is on the task bar, the user will get access / promoted for a username and password. https://social.technet.microsoft.com/Forums/lync/en-US/10eb0df5-2a34-4ea0-a5b7-eeb551990d50/windows-10-gpo-to-lock-down-search-access-to-unc-and-c?forum=winserverGP https://community.spiceworks.com/topic/2001244-can-you-stop-windows-10-browsing-unc-from-search https://www.tenforums.com/tutorials/2854-hide-show-search-box-cortana-icon-taskbar-windows-10-a.html
  24. We do the same currently: disable the account but leave the account with a "A1" license. Also looking at other options moving forward.
  25. I am happy with RM broadband and safety net, but the transparent filtering is not perfect without manually installing the ssl certificate, without the certificate users get "Your connection is not secure" my wireless network points to RM dns servers so filtering does work, just not as clean for the user as I would like it to be
×
×
  • Create New...