Jump to content

KK20

Members
  • Posts

    969
  • Joined

Everything posted by KK20

  1. KK20

    Updating to 20H2

    personally I update the ADMX immediately, they are backwards compatible and covers you in case someone takes a laptop home and ends up coming in with an out of sequence update. We dont have the time to update every 6 mons so we tend to skip at least a full year (in terms of updating)
  2. KK20

    Updating to 20H2

    We used WSUS, the same way we went from 1709->1909 ->20H2 Test a few samples in each room, then do it over a holiday. Dont forget to update your GPO admx!
  3. we got round it by swapping our up to date modern kyocera drivers with a 15 year old XP driver (papercut went a bit mad with the v4 driver). That worked just fine. I say XP driver, it had a folder for "legacy OS" as well as the XP driver....
  4. ADUC does not have a mail attribute attached to it, this is used by other applications querying ADUC. Are you saying your sync writes back remote mailbox details to ADUC? If so then I have a configuration issue as mine definitely does not.
  5. fine here. ive been testing a lot of exchange online scripts today so I have been in and out of admin consoles. Ive always found the exchange console to be slow (a lot slower than onsite ECP at any rate)
  6. OK so I just tested it. The following happens for me: 1) create user onsite in an appropriate OU 2) at this point I would normally create an exchange mailbox - I actually have a script on scheduled task that has a combination of Get-ADUser -searchBase on my OUs and Enable-Mailbox (plus some set-mailbox with differences if necessary). I did not manually kick off this script therefore an onsite mailbox was NOT created 3) waited about 10 minutes so that AD azure connect synced to azure AD 4) licence was added in azureAD, user shows synced. Online mailbox with correct school.co.uk domain created. 5) tested mailflow - onsite and offsite email went happily to and from the user. 6) GAL does not list this user in the usual groups. ADUC does not think this user has an email address - mail property not populated. so I set about thinking - what if I create an onsite mailbox? So i ran my script with did create an onsite mailbox. However, the onsite and remote mailbox had different GUIDs so whilst it was a kludgy fix for GAL and ADUC, (mail still flowed to the remote mailbox), it wasnt neat. The solution was to edit my script slightly- after creating the mailbox onsite for the user, do a bit of decision making - if there is an offsite GUID for this user, then disable the onsite mailbox, create a remote mailbox using the tenant name, copy the offsite GUID onto this record. If there isnt an offsite GUID then create a batch remote migration with auto completion. This worked fine for my test user - ADSI shows the correct proxy addresses, correct mail and exchange local is happy with the correct offsite GUID (and no hint of local). Local ECP shows the user as having an office 365 mailbox. This means I will simply carry of as normal letting ADUC add a new user, wait for my scheduled task to create the onsite mailbox and re-forge the o365 mailbox GUID. Why do I do it this way? If I was creating a single user then I could probably get away with create in ADUC and add remote-mailbox BEFORE azure syncs. However since I auto assign licences this is a run the gauntlet. so I could stop the auto assign exchange license or do the script. At least this way the accounts work as soon as sync is up and running, it is simply ADUC and GAL that will take time to update.
  7. as an addition, how do people-who-hybrid go about creating new users? Do you still create and assign mailboxes onsite THEN migrate? I assumed that the sync was "one way", I didnt want to have two mailboxes created for new users as I suspected that if I created a new user (which would be synced online), if they were exchange licensed (as our OUs are) this would automatically provision an exchange online mailbox. Im guessing this exchange online GUID is not synced backwards?
  8. Looks like I will simply keep our exchange server. "migration" wont be an issue as there will be no mailboxes on it, external input will be locked down to o365 so that should cut the attack vector down a little (firewall wont pass OWA as there wont be a need to). We have no intention of moving our AD totally offsite yet and I dont fancy ADSI editing every account we create!
  9. We migrated our mailboxes from onsite exchange to office 365 some time ago along with our MX, our mailflow is internet > office365 > (if necessary fro mailbox) onsite exchange. There were some diehard applications and hardware that wouldnt communicate with office 365 properly and so we still had our onsite exchange server running with a few service accounts and connector to offsite - we do not run centralized email. After running through the weekend rigmarole of installing the hotfix patch, it has been decided to shelf those apps and hardware so we can finally look at retiring our exchange onsite completely. However, we still have onsite AD and are running federated - azure AD connect synchronisation. This means that in the past we have created a new user in AD onsite, added email account in onsite exchange then migrated the mailbox, this ensured that the onsite AD was populated with email addresses, the GAL updated nicely and the exchange online mailbox functioned fine with outlook online etc. Im struggling to see how I would do this with no exchange server. If I (now) create a new user and leave things alone (i.e. I do not create a mailbox in local exchange), I do still get the offsite exchange online mailbox when azure AD connect syncs, it is the correct federated domain, UPN is the same form as everyone else. Licences are correct just as they would be for anyone else - except my onsite AD in not populated with email address, GAL is not updated with the user email either. What am I missing or more correctly what have I probably not done? Im better fixing these issues before I remove exchange completely....
  10. This is an interesting one. MPLC licenses you to screen one of their rightsholders films - this could be DVD or streamed. Disney+ is the media conduit and Disney+ can impose whatever restrictions they want, so in this case whilst you might have the necessary licence to show a movie to a class, you don't have the permission to use Disney+ to do so. So in this case it wouldnt be the film maker chasing you for breaking licences (since MPLC has you covered there), it would be Disney+ for using their service against their ToC. I would imagine the same applies to Netflix and an illumination film. Illumination is covered by MPLC (good for you) but Netlfix do not cover the use of their system by schools. So you can show the film but not via Netflix. As someone said earlier - the Cinema may show a film that you are legally allowed to see but that doesnt mean the cinema needs to let you in.
  11. "cost of hardware" for pfsense, snort and pfblockerNG. Just get something like an old Rx20 or Rx10 with a few network cards then run it in a virtual machine so you can easily backup the VM or move it to new hardware without much downtime (just remap the network connections). £300 each refurb - you could buy two and put them in a HA setup if you have enough IPs etc. We use a cold spare instead. If you are still running "onsite services" then combine with something like DNSMadeEasy to switch over your public side to your backup internet line.
  12. It isnt used by many, some bacs software needs an IE security cert/plugin in our finance office. The digital signs are LTSC so they have it. Servers are a mix of 2016 and 2019 (so effectively LTSC). Once thing I havent checked in "new edge" is the enterprise mode. Previously you had to wait 60 seconds for the scheme to apply, was wondering if that had changed with the vs schema xml.
  13. Try plugging in a simple usb soundcard (you know what I mean) and see if that works, if so then it could be a driver thing, windows updates seems to love adding drivers for surface pro (we have drivers disabled in WSUS but I have still seen drivers updated on surfaces!). We have a plantronics headset that refuses to work in "gotomeeting" (comes out sounding like a robot) but works perfectly in zoom, teams, "parent booking" and other recording software - it is purely gotomeeting. A cheap £3 USB soundcard works just fine in all the above.
  14. We use IAMCloud mapper, this maps onedrive to the H: on user logon (plus a couple of sharepoint libraries to other drive letters). Initially we used IAMCloud mapper as a crutch for teachers who couldnt get used to losing their data drive letter (these were sanitised and pushed to a sharepoint library). This might be why we havent had as many "blue cloud sync" issues - people use the H: drive to save online.
  15. funnily enough ive just posted this on another thread: I use the QNAP backup- boxafe. It is a little rough around the edges but it works. Initial sync was slow and the scheduling is non existent (you backup nightly at 12AM, thats it). However, it does work and does restore. It will backup sharepoint (and teams since it pulls the teams through sharepoint). You can backup onedrive and office365 mail. Its free so im doing that until I get a better option - plus the QNAP nas was sitting doing nothing (since it was one of the OLD backup stores when we had libraries onsite!) QNAP is a 1273-rp populated with ironwolf pros. It uses a pair of domestic SSDs as write cache. It used to be an iscsi target but is pretty much just standalone office365 backup now. This particular box also worked as a stretch cluster "other side" at one point in its life and performed that duty very well (we were migrating one of our SANs at the time, then we restructured).
  16. Onedrive and teams are little monkeys for caching files BTW, depending on how you sort your profiles/appdata redirection etc you will run into this. Typically our teams caches hit 500mb easily. We havent found internet speed to be an issue at all, latency perhaps but not speed.
  17. I use the QNAP one - boxafe. It is a little rough around the edges but it works. Initial sync was slow and the scheduling is non existant (you backup nightly at 12AM, thats it). However, it does work and does restore. It will backup sharepoint (and teams since it pulls the teams through sharepoint). You can backup onedrive and office365 mail. Its free so im doing that until I get a better option - plus the QNAP nas was sitting doing nothing (since it was one of the OLD backup stores when we had libraries onsite!) QNAP is a 1273-rp populated with ironwolf pros. It uses a pair of domestic SSDs as write cache. It used to be an iscsi target but is pretty much just standalone office365 backup now. This particular box also worked as a stretch cluster "other side" at one point in its life and performed that duty very well (we were migrating one of our SANs at the time, then we restructured).
  18. I did my own in the end. The isams API pulls back XML. I simply parsed the XML from the feed into CSV formatted in the way microsoft likes them, then I use Send-CsvFiles with the profile name to upload them. I do this as a daily scheduled task. It has worked perfectly before and after the rollover. The beauty of doing it this way is that I can tack "other jobs" onto the scheduled tasks such as keeping non-class teams up to date with AD groups accordingly (we dont have azure premium so I cant use dynamic groups)
  19. I can only comment on what we have observed. Like I say, this occurs when someone isnt actively using the document, only when a person who is using it goes into hibernation/reboots/loses connectivity. Once that "locked for shared us" pops up then you can no longer co author the document or spreadsheet. Google "locked for shared use", its not a new phenomenon. The closest to a "fix" I could find was https://dev.to/okms/office-online-the-file-is-locked-for-shared-use-error-15mh however, this is only useful for internal machines rather than external ones where you have no control.
  20. If someone opens a file in the desktop app from SharePoint online (this is using teams app, SharePoint online web page, IamCloudMapper - its irrelevant), you can no longer co author. That file is "locked". There are no tools in SharePoint online to force unlock. Pupils soon work this out in teams, they can simply open a file in desktop app and the teacher can no longer edit it - give it a try. If the machine is hibernated (or force powered off) when a desktop app has opened a file, that file is locked for between 10 mins and an hour (SharePoint online will decide when it wants to unlock it, it is listed as 10 minutes in Microsoft docs but I've had files that have stayed locked for an hour) . Remember that this can be done inside school on a controlled machine or on a phone, or a desktop at home. I'm not talking about "check out", im talking about "edit this in desktop app" facility. Teams is Ok though, once you get staff into a teams "thinking" rather than "everything on a shared drive" then it does release a few headaches. Access requests are easier for one- you have an entire section for the search, it doesn't make redactions any easier of course! Ownership of items is substantially easier to track. Data cleaning will be easier - we archived previous year teams in sept, I will delete those archive sets "this" September (archiving the current sets - if that all makes sense!) The behemoth SharePoint file libraries still exist but teachers are putting more in the "class team" rather than the SharePoint file library we have disabled external link sharing for SharePoint and teams. This forces any "external links to parents" to come from OneDrive - this puts a large brake on "accidentally sharing the root with parents" - this still needs training though! slowly weaning people off zoom (im talking "free zoom" - I cannot comment on the policies available to paid zoom). For example, we can set a policy to stop pupils using webcams and set some constraints. Zoom still does a few things easier - sharing of desktops, whiteboards, ease of "personal rooms" (there are pro's and con's to this of course) etc Recently we have a fairly large breakthrough on backups. I was retiring an old QNAP 12 bay NAS that was used as an offline "we have malware onsite and need an offline backup to restore from" box (we use a faster SAN for this now as we dont store as much onsite any longer!). This QNAP has an app called boxafe on it, boxafe connects to your tenant and can backup sharepoint in its entirety! User level onedrive backups, office 365 the lot! So we now have an onsite backup for our office 365. It is a little clumsy to setup, you cant set a schedule other than midnight (which is a bit silly) and the first backup is torturous but it works for us and is a last line of recovery if your versioning and recycle bin lets you down. Ive run a couple of restores for giggles and it seemed to restore just fine. Best of all, its free!
  21. I looked at using a group but since the admin screen said "groups are not supported" I didnt continue. In the end I used module pnp.powershell, this works well but is slow. A combination of get-msolgroup for my group members then set-pnptenantsite with a list of -owners what you WILL run into is 429 throttling errors if you dont have a handler for throttling. This is a lot of individual calls so you are better artificially slowing it down. Ideally I would like a graph solution (and automate it) but havent yet found one. I have adapted my script to also update static teams from group membership (we dont have premium azure so I cant use dynamic groups).
  22. we use iamcloud cloud drive mapper to backup our major sharepoint libraries to onsite, I backup weekly. Why? Because I was told to by our SMT. We have retention policies in place for day to day recovery. I use our previous pair of arrays that we had left over when we migrated offsite. When the arrays die I do not plan on continuing the backup. We have never needed to use them and we dont back up office 365 email.
  23. 250/250 for 600 users. We rarely hit the peaks looking at logs. Burst when logging on but rarely sustained. There is still a lag though, if you want speed then you need to use the web version not the drive version. The drive version does not play well with collaboration, think "old school excel workbook sharing". File locking is a pain if someone opens a file and hibernates - you cannot force unlock a file via sharepoint, not like the old days of looking at open file shares on the file server.
  24. you will also need to configure gmail for return paths and you dont want forwarding loops. In this case you will need to set gmail as a validated primary domain also and set that as your outbound address (SPF etc updated so that your exchange and gmail are allowed to send on your behalf). Again, this is done with various other companies, we used to use "oliver" as a library software, this did NOT interface with our exchange server and would send emails to our pupils via its own mail server - we needed to add their mail servers to our SPF and pray they didnt spam on our behalf (as we would be blacklisted for their spam). So 1) exchange accounts (or contacts, your choice) forward (and not keep) @schooldomain.co.uk to @gmail.schooldomain.co.uk 2) gmail has both @schooldomain.co.uk and @gmail.schooldomain.co.uk validated 3) gmail has @schooldomain.co.uk set as the send 4) leave your MX alone but update your SPF DKIM should be fun I dont have any knowledge of gmail - point 3 should be fine. Our exchange has school.sch.uk and school.co.uk for every account but we only send on our school.co.uk this would be no different for gmail As for actually DOING this, I have no idea on how to bulk edit gmail but for exchange powershell could sort this out.
  25. I dont understand. what do you mean "is it possible"? Currently you have your MX pointing to Exchange. an email arrives and exchange decides what to do with it. You want teacher email to "stay where they are" but you want pupil emails to "go to gmail". This means you need a mechanism for moving emails from your pupils to gmail. You dont want pupil emails to remain on exhcange. Now, you CAN leave a full fat mail account enabled on exchange, this might be useful for your teams. In this case you can forward ALL emails (and not leave a copy) to "another address somewhere else". This will work, we do this all the time for school staff who work for other companies (such as our catering manager) - she has a catering manager email address elsewhere and doesnt care about using her school domain to check emails, but she can still access the teams using her school logon details but all the emails get forwarded outside the school. Now the caveat. Make sure your school antispam system is good. if not ALL SPAM going to those forwarders will be forwarding. GMail will see that the spam is being forwarded by YOUR DOMAIN and will blacklist you.
×
×
  • Create New...