SimonInOz
Members-
Posts
95 -
Joined
-
Last visited
Reputation
5 NeutralAbout SimonInOz

-
Hi, We have a traditional Microsoft Windows Server shares setup, and the Principal wants to investigate the use of Google so we can do the same in the 'cloud'. Has anyone got any experience with this, particularly thinking about shares security, providing access to authenticated Azure users etc. Can someone point me in the right direction here? Cheers
-
Hi, School looking to implement BYOD, just wondering if there are some reading resources on what to do, how to manage devices etc? What is everyone else doing? Cheers
-
Hi all, does anyone have an easy way to setup Spanish keyboards on a class of students via Group Policy, or via PDQ? Any assistance appreciated. Cheers
-
hmmm, ok. The issue was that I was missing startup-config before the tftp command, which was a typo as I had already had the command running on one switch. The correct command, in conf mode is: job Backup at 23:40 "copy startup-config tftp 10.x.x.x 10.x.x.x-aruba.cfg" exit/save This works. Not sure what the other chatter on this thread was about, but just point out the syntax error, and letting me know the right one would have been just fine. Have a good day.
-
Hi, I am trying to backup my switch configs, and want to do it with the 'job' command to run at a specific time. My command is: copy tftp startup-config 10.x.x.x 10.x.x.x-aruba.cfg (without the x's of course) Job is called 'Backup' Job Information Job Name : Backup Runs At : 23:00 Config Save : Yes Repeat Count : -- Job Status : Enabled Running Status : Active Run Count : 99 Error Count : 99 Skip Count : 0 Command : copy tftp startup-config 10.x.x.x 10.x.x.x-aruba.cfg Last Run Time : Tue May 25 23:00:00 2021 OK, if I run this command on the switch, it comes up with: Device may be rebooted, do you want to continue [y/n]? n So, I don't want to really reboot my switches on backup, so is there a way around this? Also, if I run this as a Job command, how would I pipe a 'N' as an answer? Many thanks, apols if this is the wrong group, just couldn't see a networking/switch one.
-
Thanks, so you create them as normal AD users, how is the shared Sharepoint area created, I am not a Sharepoint guru unfortunately.
-
Hi, I have been asked to set, or at least propose some options for board member access. My first thought was, accounts for all members, then a secure area on the server, VPN access then a drive mapping to that area. We also have O365 and Onedrive, but there would need to be some area which is generally accessible, plus a secure area for each member. I can do the first easily, but are there other options that people use for this purpose? Brain not operating well today, so any assist would be appreciated. BTW, we use Sonicwall VPN, and this is installed through the Microsoft store, would this still work for non domain computers, as all of their computers would be non-domain. cheers Simon
-
Hi, I want to use our custom domain (xxxxxxxx.wa.edu.au) for all new Microsoft Teams, instead of the xxxxxxxx.onmicrosoft.com domain My Email address policy is: PS C:\Users\ITManager> get-emailaddresspolicy | flRunspaceId : 94e2aa3d-e92b-4c88-9609-8d6241ce6bf5RecipientFilter : Alias -ne $nullLdapRecipientFilter : (mailNickname=*)LastUpdatedRecipientFilter :RecipientFilterApplied : FalseIncludedRecipients : AllRecipientsConditionalDepartment : {}ConditionalCompany : {}ConditionalStateOrProvince : {}ConditionalCustomAttribute1 : {}ConditionalCustomAttribute2 : {}ConditionalCustomAttribute3 : {}ConditionalCustomAttribute4 : {}ConditionalCustomAttribute5 : {}ConditionalCustomAttribute6 : {}ConditionalCustomAttribute7 : {}ConditionalCustomAttribute8 : {}ConditionalCustomAttribute9 : {}ConditionalCustomAttribute10 : {}ConditionalCustomAttribute11 : {}ConditionalCustomAttribute12 : {}ConditionalCustomAttribute13 : {}ConditionalCustomAttribute14 : {}ConditionalCustomAttribute15 : {}RecipientContainer :RecipientFilterType : PrecannedPriority : LowestEnabledPrimarySMTPAddressTemplate : @xxxxxxxx.onmicrosoft.comEnabledEmailAddressTemplates : {SMTP:@xxxxxxxx.onmicrosoft.com}DisabledEmailAddressTemplates : {}HasEmailAddressSetting : TrueHasMailboxManagerSetting : FalseNonAuthoritativeDomains : {}AdminDescription :ManagedByFilter :ManagedByLdapFilter :AdminDisplayName :ExchangeVersion : 0.1 (8.0.535.0)Name : Default PolicyDistinguishedName : CN=Default Policy,CN=Recipient Policies,CN=Configuration,CN=xxxxxxxx.onmicrosoft.com,CN=ConfigurationUnits,DC=AUSPR01A002,DC=PROD,DC=OUTLOOK,DC=COMIdentity : Default PolicyObjectCategory : AUSPR01A002.PROD.OUTLOOK.COM/Configuration/Schema/ms-Exch-Recipient-PolicyObjectClass : {top, msExchGenericPolicy, msExchRecipientPolicy}WhenChanged : 30/11/2016 2:17:24 AMWhenCreated : 13/07/2015 9:53:54 AMWhenChangedUTC : 29/11/2016 6:17:24 PMWhenCreatedUTC : 13/07/2015 1:53:54 AMExchangeObjectId : deaf13b5-0b62-4709-af4b-eca828f59942OrganizationId : AUSPR01A002.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/xxxxxxxx.onmicrosoft.com - AUSPR01A002.PROD.OUTLOOK.COM/ConfigurationUnits/xxxxxxxx.onmicrosoft.com/ConfigurationId : Default PolicyGuid : deaf13b5-0b62-4709-af4b-eca828f59942OriginatingServer : SYBPR01A002DC04.AUSPR01A002.PROD.OUTLOOK.COMIsValid : TrueObjectState : UnchangedRunspaceId : 94e2aa3d-e92b-4c88-9609-8d6241ce6bf5RecipientFilter : RecipientTypeDetails -eq 'GroupMailbox'LdapRecipientFilter : (&(|(&(!(!(objectClass=user)))(objectCategory=person)(mailNickname=*)(msExchHomeServerName=*))(&(objectCategory=group)(groupType:1.2.840.113556.1.4.804:=8)(!(groupType:1.2.840.113556.1. 4.804:=2147483648))(mailNickname=*)))(msExchRecipientTypeDetails=1099511627776))LastUpdatedRecipientFilter :RecipientFilterApplied : FalseIncludedRecipients :ConditionalDepartment : {}ConditionalCompany : {}ConditionalStateOrProvince : {}ConditionalCustomAttribute1 : {}ConditionalCustomAttribute2 : {}ConditionalCustomAttribute3 : {}ConditionalCustomAttribute4 : {}ConditionalCustomAttribute5 : {}ConditionalCustomAttribute6 : {}ConditionalCustomAttribute7 : {}ConditionalCustomAttribute8 : {}ConditionalCustomAttribute9 : {}ConditionalCustomAttribute10 : {}ConditionalCustomAttribute11 : {}ConditionalCustomAttribute12 : {}ConditionalCustomAttribute13 : {}ConditionalCustomAttribute14 : {}ConditionalCustomAttribute15 : {}RecipientContainer :RecipientFilterType : CustomPriority : 1EnabledPrimarySMTPAddressTemplate : @xxxx.wa.edu.auEnabledEmailAddressTemplates : {SMTP:@xxxx.wa.edu.au}DisabledEmailAddressTemplates : {}HasEmailAddressSetting : TrueHasMailboxManagerSetting : FalseNonAuthoritativeDomains : {}AdminDescription :ManagedByFilter :ManagedByLdapFilter :AdminDisplayName :ExchangeVersion : 0.1 (8.0.535.0)Name : GroupsDistinguishedName : CN=Groups,CN=Recipient Policies,CN=Configuration,CN=xxxxxxxx.onmicrosoft.com,CN=ConfigurationUnits,DC=AUSPR01A002,DC=PROD,DC=OUTLOOK,DC=COMIdentity : GroupsObjectCategory : AUSPR01A002.PROD.OUTLOOK.COM/Configuration/Schema/ms-Exch-Recipient-PolicyObjectClass : {top, msExchGenericPolicy, msExchRecipientPolicy}WhenChanged : 10/11/2020 9:16:15 AMWhenCreated : 10/11/2020 9:16:03 AMWhenChangedUTC : 10/11/2020 1:16:15 AMWhenCreatedUTC : 10/11/2020 1:16:03 AMExchangeObjectId : 2a3f732c-9e44-4759-8838-f01942866f60OrganizationId : AUSPR01A002.PROD.OUTLOOK.COM/Microsoft Exchange Hosted Organizations/xxxxxxxx.onmicrosoft.com - AUSPR01A002.PROD.OUTLOOK.COM/ConfigurationUnits/xxxxxxxx.onmicrosoft.com/ConfigurationId : GroupsGuid : 2a3f732c-9e44-4759-8838-f01942866f60OriginatingServer : SYBPR01A002DC04.AUSPR01A002.PROD.OUTLOOK.COMIsValid : TrueObjectState : Unchanged Short version: PS C:\Users\ITManager> get-emailaddresspolicyName Priority RecipientFilter---- -------- ---------------Default Policy Lowest Alias -ne $nullGroups 1 RecipientTypeDetails -eq 'GroupMailbox' If I type the following: New-EmailAddressPolicy -Name Groups -IncludeUnifiedGroupRecipients -EnabledEmailAddressTemplates "SMTP:@iswa.wa.edu.au" -Priority 1 I get this error: Active Directory operation failed on SYBPR01A002DC04.AUSPR01A002.PROD.OUTLOOK.COM. The object 'CN=Groups,CN=RecipientPolicies,CN=Configuration,CN=iswawaeduau.onmicrosoft.com,CN=ConfigurationUnits,DC=AUSPR01A002,DC=PROD,DC=OUTLOOK,DC=COM' already exists. + CategoryInfo : NotSpecified: ( [New-EmailAddressPolicy], ADObjectAlreadyExistsException + FullyQualifiedErrorId : [server=ME2PR01MB3668,RequestId=f176d112-7b20-484c-b912-6969dacc9252,TimeStamp=26/11/2020 12:33:47 AM] [FailureCategory=Cmdlet-ADObjectAlreadyExistsException] 3CFB6830,Microsoft.Exchange.Man agement.SystemConfigurationTasks.NewEmailAddressPolicy + PSComputerName : outlook.office365.com How do I do this, so that I get my xxxxxxxx.wa.edu.au domain to be the one used by Teams or Groups as a first priority? I am guessing it is to do with the priority number being reused is causing the error, but I want to do this without messing up my email system and so need some guidance. Any experts want to lend me a hand? Cheers
-
Office365, and desktop versions of Onenote, Outlook, Onedrive. Non UWP. Tell me more about seamless SSO!
-
Hi, We have Azure AD Connect, it all works fine basically, apart from two things: One When a user password is changed, we then have to direct them to change it in a load of areas on the W10 PC (pretty much latest updates): Onenote, Onedrive, Email (plus check the box to retain the password), etc, etc A basic question, is all of this not able to be automated? What is the point of Credential manager, if you cannot reuse a credential that has been changed? Surely there is a better way to do this, and my personal thanks to anyone that can solve this for me. I have googled for some time, never found anything that would help so far. Perhaps my searching is faulty, or it is just not possible, which would be amazing in its own right. Two How do you (correctly) setup a reverse pw sync between Azure and AD, so that a user can use the online password change feature? I need this stepped out, or a link to a process if possible. I am sure there was something to do with PKI last time I looked. Well, any takers here? Cheers all.
-
@HPlum78 thanks for the links mate, I think this is probably not going to happen anytime soon. I will have to do more research and find a way to do it right.
-
Hi, I guess I was really looking for an established process here, I was sure someone would be doing this right. I think I have the signed certificate done right, but I believe I need to set the execution policy to allsigned through GPO? I just need to know how this last few steps actually work from someone that has done it already.
-
I just checked the cert store on the student pc, and it is not in either personal/certificates or trusted root certificates. How is it pushed out by the CA server?
-
Hi, it was done on the Certificate Authority server, used the Code Signing template, then added to my pc. Just thinking, this probably needs to go out to all the pcs via Group Policy right? Or does that happen automagically with the CS server? I would like all the domain pcs to have the cert ideally if that is the case, so do I have to do this manually, or is it automatic? Cheers!
-
Hi all, I think I am about to lose my mind over this, so bear with me.. Trying to set up a Powershell script, that will run when a student logs in. This is what I have been through so far: Ok, so Powershell runs on the student account, when you try to run Powershell. (I actually had this disabled by software restriction policy, but have enabled it for testing) I have used Group Policy to run a script on login (restricted by scope to a single test user) on a user OU and user login script, not computer. The Powershell script is signed by me, and the signing is evident in the script and is ok when I actually sign it. $cert = (dir cert:currentuser\my\ -CodeSigningCert)Set-AuthentiCodeSignature .\testScript.ps1 $cert I have copied this script into the script folder (users\scripts\logon) in the policies folder script is basically: Get-AppxPackage *people* | Remove-AppxPackage # SIG # Begin signature block etc, etc signing block Ok, in relation to the logon script properties, I have the following: Script Name: %windir%\System32\WindowsPowerShell\v1.0\powershell.exe Script Parameters: -Noninteractive -ExecutionPolicy allsigned -scope userpolicy –Noprofile -file %~dp0Remove_MC.ps1 (I have tried just using the script actual name here "Remove_MC.ps1" this doesn't work either, I have also tried running it from a student accessible share) So, I am sure I have done something basically wrong here, but after a day of scratching my head, and trying to logically solve this, I am stumped. There must be people who have got this working, so would you be kind enough to share that knowledge with me? I would also like to write something to the computer, to see if it is actually running or not. I looked through event viewer, nothing was evident there, failure or otherwise. Any questions, just ask. Thank you all.
