Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Thanks Ants
May 21, 2004

#essereFerrari


Azure AD is hosed :yaycloud:

https://azure.microsoft.com/en-gb/status/

Adbot
ADBOT LOVES YOU

Dans Macabre
Apr 24, 2004



how much would this be affecting my office 365 users who use on prem AD with dirsync/azure ad connect. The link talks about going to online portals - how about accessing email though

Dans Macabre
Apr 24, 2004


I only have experience with single box Exchange servers (when it comes to on prem) so I have some questions, starting with this one: small environments (under 100 mailbox) is it worth the time to set up multiple exchange servers so you have OWA in a DMZ for example? Do you do this?

mayodreams
Jul 4, 2003


Hello darkness,
my old friend

NevergirlsOFFICIAL posted:

I only have experience with single box Exchange servers (when it comes to on prem) so I have some questions, starting with this one: small environments (under 100 mailbox) is it worth the time to set up multiple exchange servers so you have OWA in a DMZ for example? Do you do this?

You almost certainly want a box in the DMZ as a proxy to your mail server, so yes. And the firewall rules should only allow the bare minimum ports for functionality and administration.

Dans Macabre
Apr 24, 2004


mayodreams posted:

You almost certainly want a box in the DMZ as a proxy to your mail server, so yes. And the firewall rules should only allow the bare minimum ports for functionality and administration.
Do I need an edge transport server as well? Or can I just have (1) CAS server (owa/outlook anywhere) in the DMZ, and then have everything else on the LAN?

wyoak
Feb 14, 2005

a glass case of emotion

Fallen Rib
MS doesn't support CAS servers in the DMZ, just FYI. The Edge Transport role is the only one they support in a perimeter network.

In your situation I'd look at getting a reverse proxy or WAF (for OWA) and putting that in the DMZ. If you want to build a second exchange server, use it for redundancy purposes.

wyoak fucked around with this message at 21:01 on Dec 3, 2015

Dans Macabre
Apr 24, 2004


wyoak posted:

MS doesn't support CAS servers in the DMZ, just FYI. The Edge Transport role is the only one they support in a perimeter network.

OK so does this mean MS recommends putting OWA on the LAN and exposing it to the web?

wyoak
Feb 14, 2005

a glass case of emotion

Fallen Rib

NevergirlsOFFICIAL posted:

OK so does this mean MS recommends putting OWA on the LAN and exposing it to the web?
I don't know if they have officially recommended deployments anymore since they stopped selling their ISA product (or whatever it was called in its later iterations), but you should probably have a reverse proxy of some sort sitting in your perimeter network. Load balancers, IIS with AAR, "next-gen" firewalls, SSL offloaders all do that.

KS
Jun 10, 2003
Outrageous Lumpwad
There are really cheap VM-based load balancers that do the job nicely and have about a 4-click setup to reverse proxy CAS.

KS fucked around with this message at 08:10 on Dec 4, 2015

Dans Macabre
Apr 24, 2004


nice thank you

I have a "next gen" firewall that can probably do this thing

Calidus
Oct 31, 2011

Stand back I'm going to try science!
I guess this is best place to talk about Office 365 and Exchange online. I need to start doing some very basic device management. This is what I would like to accomplish:

• White list or use a cert to allow company cell phones/tablets connect to Office 365 using ActiveSync.
• White list or use a cert to company laptops both on and off site to connect to Office 365 with outlook, one drive, etc
• Allow on site workstations to use Outlook, possibly white list static IP of the office?
• Block personal cell phones and computers from accessing Office 365

Is this doable with Office 365, Office 365 AD sync and possibly Azure AD?

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

Calidus posted:

I guess this is best place to talk about Office 365 and Exchange online. I need to start doing some very basic device management. This is what I would like to accomplish:

• White list or use a cert to allow company cell phones/tablets connect to Office 365 using ActiveSync.
• White list or use a cert to company laptops both on and off site to connect to Office 365 with outlook, one drive, etc
• Allow on site workstations to use Outlook, possibly white list static IP of the office?
• Block personal cell phones and computers from accessing Office 365

Is this doable with Office 365, Office 365 AD sync and possibly Azure AD?

No, not with your conditions. Some of that is possible if you bring ADFS into the mix, some of it would require 3rd party software or additional features from Microsoft, specifically Intune for MDM.

Dyscrasia
Jun 23, 2003
Give Me Hamms Premium Draft or Give Me DEATH!!!!
You may be able to do Cert based authentication for active sync, but I do know that outlook does not support it. I wanted to use it to prevent non corporate pc outlook clients, but no go.

vanity slug
Jul 20, 2010

Dyscrasia posted:

You may be able to do Cert based authentication for active sync, but I do know that outlook does not support it. I wanted to use it to prevent non corporate pc outlook clients, but no go.

Can't you disable Outlook Anywhere as an alternative? That's what they did at a former employer.

Swink
Apr 18, 2006
Left Side <--- Many Whelps

KS posted:

There are really cheap VM-based load balancers that do the job nicely and have about a 4-click setup to reverse proxy CAS.

Anyone have some recommendations in this area? I have a small deployment but I'm overdue getting it behind a load balancer. Ideally i need something I can trial for a while to get my head around it.

wyoak
Feb 14, 2005

a glass case of emotion

Fallen Rib

Swink posted:

Anyone have some recommendations in this area? I have a small deployment but I'm overdue getting it behind a load balancer. Ideally i need something I can trial for a while to get my head around it.
A couple years ago I deployed some low-end AX series A10 load balancers to frontend a smallish Exchange deployment - at the time they were pretty affordable (much cheaper than F5's and such with similar feature sets) and could do stuff like URL rewriting, SSL offloading, virtual chassis, etc. I haven't paid much attention to the space recently though so I don't know how they stack up these days, but they might be worth a look (they have virtual appliances as well).

Dyscrasia
Jun 23, 2003
Give Me Hamms Premium Draft or Give Me DEATH!!!!

Jeoh posted:

Can't you disable Outlook Anywhere as an alternative? That's what they did at a former employer.

Yea, we are working on it. We need to get the ssl VPN in place first, so we don't screw over users at clients with locked down networks.

KS
Jun 10, 2003
Outrageous Lumpwad

Swink posted:

Anyone have some recommendations in this area? I have a small deployment but I'm overdue getting it behind a load balancer. Ideally i need something I can trial for a while to get my head around it.

Kemp Technologies is the one I was thinking of with the dead simple setup for Exchange.

Matt Zerella
Oct 7, 2002

Norris'es are back baby. It's good again. Awoouu (fox Howl)
So what's a good backup solution for Exchange nowadays?

I have one server with ~40 mailboxes and we're using BE2012 and it really really sucks. Been having issues lately with backups taking forever. I just need D2D.

I'm hesitant to upgrade BE because 2012 has been so bad.

Internet Explorer
Jun 1, 2005





If it is virtual and the rest of your environment is virtual, have you tried Veeam?

Matt Zerella
Oct 7, 2002

Norris'es are back baby. It's good again. Awoouu (fox Howl)

Internet Explorer posted:

If it is virtual and the rest of your environment is virtual, have you tried Veeam?

It's physical (both servers are). We have some very minor virtualization going on and it's nowhere near our Exchange server/Backup machine.

Internet Explorer
Jun 1, 2005





That's unfortunate. I have not used it but maybe add Unitrends Enterprise Backup to your list? It does both physical and virtual, so it may be useful during the transition.

Dans Macabre
Apr 24, 2004


LmaoTheKid posted:

So what's a good backup solution for Exchange nowadays?

I have one server with ~40 mailboxes and we're using BE2012 and it really really sucks. Been having issues lately with backups taking forever. I just need D2D.

I'm hesitant to upgrade BE because 2012 has been so bad.

how about datto

KennyTheFish
Jan 13, 2004

LmaoTheKid posted:

So what's a good backup solution for Exchange nowadays?

I have one server with ~40 mailboxes and we're using BE2012 and it really really sucks. Been having issues lately with backups taking forever. I just need D2D.

I'm hesitant to upgrade BE because 2012 has been so bad.

I have been using MS DPM for the last 4 years because it came "Free" as part of our MS licensing. It works.

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

Anyone have Hosted Exchange with Rackspace? We're upgrading from 2013 to 2016 and they're only migrating over like 2 users an hour (one users mailbox was 3GB the other was 5GB)

Kind hoping they would have it done today. 2008-2013 didn't take long for them to do at all.

ilkhan
Oct 7, 2004

I LOVE Musk and his pro-first-amendment ways. X is the future.
Office 365 / Outlook 13

Is there a way to flag/high-priority/notification/something an email sent to a shared mailbox with no other users in the to field?

Dans Macabre
Apr 24, 2004


ilkhan posted:

Office 365 / Outlook 13

Is there a way to flag/high-priority/notification/something an email sent to a shared mailbox with no other users in the to field?

you mean like rules and alerts?

Dans Macabre
Apr 24, 2004


Bob Morales posted:

Anyone have Hosted Exchange with Rackspace? We're upgrading from 2013 to 2016 and they're only migrating over like 2 users an hour (one users mailbox was 3GB the other was 5GB)

Kind hoping they would have it done today. 2008-2013 didn't take long for them to do at all.

why not migrate to exchange online with migrationwiz

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Whats the proper way to run powershell commands from my workstation?

Currently I do an add-PSSnapin Microsoft.Exchange.Management.PowerShell.E2010 and then just run the commands.

Should I be making a remoting session instead?

KS
Jun 10, 2003
Outrageous Lumpwad

NevergirlsOFFICIAL posted:

why not migrate to exchange online with migrationwiz

Rackspace will actually provide phone support for O365 for like $3pepm and do the migration for free using migrationwiz, which is kinda cool. You can transfer an existing tenant to them and buy licenses through them. No contracts required.

We're migrating off Rackspace hosted exchange at the moment. Why? User's mailbox was inadvertently deleted and Rackspace's restore was corrupt. Ugh.

If you can't trust a cloud service's backups, you're in serious trouble.

Dans Macabre
Apr 24, 2004


KS posted:

Rackspace will actually provide phone support for O365 for like $3pepm and do the migration for free using migrationwiz, which is kinda cool. You can transfer an existing tenant to them and buy licenses through them. No contracts required.
oh nice

quote:

We're migrating off Rackspace hosted exchange at the moment. Why? User's mailbox was inadvertently deleted and Rackspace's restore was corrupt. Ugh.

If you can't trust a cloud service's backups, you're in serious trouble.

I use cloudfinder.com for backups.

Dans Macabre
Apr 24, 2004


anyone using MDM through Exchange Online? What is the difference between MDM and the mobile device policies that have been around for a while? Also apparently if someone has an O365 account and a personal MS account it doesn't work?

Bob Morales
Aug 18, 2006


Just wear the fucking mask, Bob

I don't care how many people I probably infected with COVID-19 while refusing to wear a mask, my comfort is far more important than the health and safety of everyone around me!

KS posted:

Rackspace will actually provide phone support for O365 for like $3pepm and do the migration for free using migrationwiz, which is kinda cool. You can transfer an existing tenant to them and buy licenses through them. No contracts required.

We're migrating off Rackspace hosted exchange at the moment. Why? User's mailbox was inadvertently deleted and Rackspace's restore was corrupt. Ugh.

If you can't trust a cloud service's backups, you're in serious trouble.

Rackspace hosed one users account up migrating us from 2013 to 2016. It was not one I would have chosen for them to gently caress up.

#thanksrackspace

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Re MDM: the difference is compliance and reporting. It's a basic step up from Activesync where you're either connected or quarantined or whatever. You actually enroll the device and can see its basic status of compliant/non compliant.

The next step after that is intune which is a fully fledged MDM where you can mandate apps, settings etc like all the big MDMers.

Worth having if you have nothing else in place to inventory your phones. Extremely basic feature set.

It has been several months since j last looked at the product though.

Meraki system manager is free for 100 devices and does everything.

Dans Macabre
Apr 24, 2004


cool thank you

I'm going to go on a limb and say MDM isn't a great idea if environmenit s BYOD

Swink
Apr 18, 2006
Left Side <--- Many Whelps
As far as knowing who and what is accessing company email/data, it might be an improvement over a bunch of Activesync connections for each user as the sole log of who is connected.

We're planning on adding our byod phones to a basic MDM policy. Pushes down email and Corp wifi settings but nothing else.

It was really new when I looked at it and in the style of o365, nothing worked out of the box. I'm sure they've improved by now.

Matt Zerella
Oct 7, 2002

Norris'es are back baby. It's good again. Awoouu (fox Howl)
We've been using Meraki for the last year and it's worked well for a free product.

Android support sucks rear end but my boss banned those devices anywAy so not a problem there.

Swink
Apr 18, 2006
Left Side <--- Many Whelps
Do you use it for laptops at all? Boss wants to enroll our Surfaces.


Edit: also does anyone use GPS tracking in a regular environment? It's creeping me out. I want it disabled.

Swink fucked around with this message at 23:39 on Dec 23, 2015

Matt Zerella
Oct 7, 2002

Norris'es are back baby. It's good again. Awoouu (fox Howl)

Swink posted:

Do you use it for laptops at all? Boss wants to enroll our Surfaces.


Edit: also does anyone use GPS tracking in a regular environment? It's creeping me out. I want it disabled.

I added one laptop but it doesn't seem to do anything.

Adbot
ADBOT LOVES YOU

Tigern
Sep 6, 2012

possibly tiger
Grimey Drawer
Does anyone know if there is a way to create a rule in Outlook 2013 that looks at all incoming mails and check if it was sent to more than 30 people(TO or CC field)? I want to delete all emails like this.

I tried looking at some scripts but it's all pretty foreign to me, so I don't want to gamble on copy-pasting them from google.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply