Jump to content

bb12489

Members
  • Posts

    10
  • Joined

  • Last visited

Reputation

45 Excellent

About bb12489

  1. Sorry to hijack your thread, but I'm running into the same issue with folder redirects to AD home locations. Ever since 10.13.5 dropped over the weekend, our Ad joined Mac's won't automount their AD home locations to /Volumes/Users anymore. thus our script we had in place to redirect the Desktop and Documents folders no longer work. I'd appreciate any assistance that anyone can give!
  2. I'll be checking this out here for sure. I honestly can't believe that we as an educational institution can't get AAD P1 for better than $6 per user per month.... 20c sounds a lot more reasonable!
  3. See, this is what's been confusing me on this. If it's this easy to enable with a single license, and they specifically stated that they don't enforce per-user licensing for the password reset experience, then why also include that part about providing a license for each user? This really needs clarification I guess. Why is MS licensing this difficult to decipher :/
  4. Glad it works for you as well! And glad I could help.
  5. I just thought I would reply to this thread, since I saw you guys making mention of the AAD Premium prices for password reset. I too found this to be completely ridiculous, so I did some digging and found their licensing page for SSPR here.... https://docs.microsoft.com/en-us/azure/active-directory/active-directory-passwords-licensing In the first paragraph is states "We do not enforce per-user licensing on the password reset experience" . this seemed to completely contradict everything I've heard and read about setting up the password reset(writeback) using AAD Premium. To my knowledge I thought you needed an AAD P1 license for each user in the tenant. At over 2000 users here, that would of gotten expense real fast, and just doesn't make sense. So I decided to buy a single AAD Premium license ($70 for the year), assign it to myself(global admin) and see if it would magically enable SSPR for everyone. Sadly this was not the case, and SSPR was complaining about not having enough licenses, but I soon figured out why. It seems that when you buy an AAD Premium license, you don't need to assign the license to anyone. Just having the license in the tenant enables certain premium features that aren't user specific. So I removed the license from myself, and all of a sudden the SSPR works correctly! I honestly couldn't believe it at first, so I tested it with multiple synchronized AD accounts, and test student accounts. Changing the password online through 365 does successfully write back changes to our on-prem AD! Now we have a fully working password reset solution, and way happier end-users! Long story short..... Purchase 1 AAD P1 license Do NOT assign the license to anyone in the tenant Open the Azure AD Connect application in your on-prem AD and configure password writeback Go to the Azure AD management online portal to enable password reset Profit! I hope this helps you guys out!
  6. It might be because of KB3159706. This patch for WSUS enables it to decrypt ESD files for deployment of Windows 10 upgrades. Here is the post install instructions via reddit....
  7. These are the collection of scripts that I found in my searches.... https://github.com/W4RH4WK/Debloat-Windows-10 The only one I'm using at the moment is the one to remove modern apps. In the script you can comment out the apps that you want to keep. I've basically only kept Mail, Calendar, Calc, Weather, and maybe a couple others. Most bing apps have been removed.
  8. The only other thing I have in our Task Sequence is a powershell script to remove specific modern apps from the system. Make for a a much cleaner start menu. Otherwise there is a lot that can be controlled by GPO. Recently found the GPO to disable automatic installing of Candy crush and twitter!
  9. I've been thinking about using OneDrive for Business as a replacement for Staff/Student home drives as well, but it seems that the service just isn't designed for it. Easiest would be to have the staff upload the files that they want off campus access to. Otherwise you can look at setting up Work Folders on a Windows Server to point at individual home drives for staff.
  10. I'm glad I've come across this topic. I'm also researching the use of Azure AD SSO for Google Apps. Currently we have few existing users in Google Apps that have been synchronized using GADS. We use very few Google services at the moment since our main focus is now Office 365. My question is, can I enable Azure AD SSO to Google Apps, even though I have existing users in Google Apps? Will I have to delete the exiting users and re-sync them from Azure AD? Or can I just roll with SSO from Azure AD and continue to use GADS for account syncing? Any help would be greatly appreciated!
×
×
  • Create New...