New around here? Register your SA Forums Account here!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Thanks Ants
May 21, 2004

#essereFerrari


ihafarm posted:

This sounds like AADBroker BS to me. What does dsregcmd report? What happens if you attempt ‘dsregcmd /forcerecovery’?
That's all happy, my actual Entra account that I use worked fine, I had a couple of other accounts from different tenants that I had logged into things to do some proof of concept work on, and those ended up broken to the point where they wouldn't log in any more but also couldn't log out.

These accounts never showed in dsregcmd /listaccounts either

Adbot
ADBOT LOVES YOU

guppy
Sep 21, 2004

sting like a byob

tehinternet posted:

My first thoughts are a field in the form is set jankily. Are attachments mandatory on the form *or on any branch of the form*?

Double check the form top to bottom, check the outputs of the form again when an error is given just in case.

I checked this, because I did have some required fields, but only in the first section before any branching. I took it out as a test and I get the same result.

Cyks
Mar 17, 2008

The trenches of IT can scar a muppet for life
This is such a low priority question but it came up at work and I don’t have a good answer.

We have a pretty high turnover rate for entry level staff at our remote sites we manage. Our normal policy is to do a wipe on the machine, and have the manager on site just make sure the laptop is powered on connected to the Internet to receive the command. Then when the replacement starts, OOBE installs their apps. It’s not a big deal, but it does require some time pestering staff and checking to make sure it went through.

However, the person replacing them will be the same position with the same apps required. It’s also not a very file heavy job and the previous employee’ space usage would be like 2 gigs on a 120gig SSD. Is there a reason why we can’t just update the primary user in intune to the new employee and be done with it?

I know there’s a limit to the number Microsoft Hello pins you can store (10), but that’s all I got.

Thanks Ants
May 21, 2004

#essereFerrari


Do they have to be a laptop user or would Windows 365 Boot on a managed desktop be an option?

I would try and avoid account reuse just from an audit point of view, and if the previous user dumped something dodgy in their OneDrive or pinned browser tabs you don’t need the liability.

Wizard of the Deep
Sep 25, 2005

Another productive workday
I'm not reading that as account reuse, but just not nuking & paving between distinct users.

And it really depends on how often a departing employee leaves the machine in a lovely state (software wise). Personally I'd rather have a firm policy of "device always gets wiped and rebuilt when reassigned", because without it you're leaving it open to judgment calls and guesswork.

But surviving the day is always the highest priority. If cutting out some annoying work is what it takes, then either the bosses can cut other work, or hire more people.

Thanks Ants
May 21, 2004

#essereFerrari


An autopilot reset should be a lot quicker than a full wipe and OOBE if the apps that were getting removed and reinstalled are deployed from Intune

tehinternet
Feb 14, 2005

Semantically, "you" is both singular and plural, though syntactically it is always plural. It always takes a verb form that originally marked the word as plural.

Also, there is no plural when the context is an argument with an individual rather than a group. Somfin shouldn't put words in my mouth.

guppy posted:

I checked this, because I did have some required fields, but only in the first section before any branching. I took it out as a test and I get the same result.

At that point, if the form isn’t too large, I’d make a copy of the form and remove and rerun field by field until I found what was breaking it. PA errors can be real dumb and bury the lede all the time too.

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010

Thanks Ants posted:

An autopilot reset should be a lot quicker than a full wipe and OOBE if the apps that were getting removed and reinstalled are deployed from Intune

Good thing you asked question to a well timed update. Autopilot is getting rejiggered to be faster.

guppy
Sep 21, 2004

sting like a byob

tehinternet posted:

At that point, if the form isn’t too large, I’d make a copy of the form and remove and rerun field by field until I found what was breaking it. PA errors can be real dumb and bury the lede all the time too.

That's a great idea, thanks. I will give that a shot.

Silly Newbie
Jul 25, 2007
How do I?

Wizard of the Deep posted:

I'm not reading that as account reuse, but just not nuking & paving between distinct users.

And it really depends on how often a departing employee leaves the machine in a lovely state (software wise). Personally I'd rather have a firm policy of "device always gets wiped and rebuilt when reassigned", because without it you're leaving it open to judgment calls and guesswork.

But surviving the day is always the highest priority. If cutting out some annoying work is what it takes, then either the bosses can cut other work, or hire more people.

The way I handle that is tiered, and yes, does leave itself open to some judgement call issues, but we're small enough it doesn't matter. Software issues aren't much because I don't allow them to install anything without a business use case.

- The lowest level, generally field techs, just have the new person sign in as their own (new) user account and move on
- People with access to sensitive information, so generally project managers and similar, wipe the machine
- People with access to really sensitive stuff (finance and HR) I wipe and reissue to people in the same department with the same clearances
- C levels and people with access to scary sensitive information I replace the hard drive and archive/destroy the old one. This doesn't come up often

buffbus
Nov 19, 2012
We always wipe, lay a new os, and autopilot again. Kind of have to anyway unless someone else knows how to reassign the enrollment user (not primary user).

you ate my cat
Jul 1, 2007

What's the right way to do meetings on a shared mailbox calendar with Teams? We're currently having people create a meeting on their own calendar and copy/paste the link into the meeting on the shared mailbox's calendar, since a shared mailbox can't create its own Teams meetings. When the original creator leaves the firm, all those meetings become dead links. This all seems so terrible that I imagine there has to be a better way.

Our user mailboxes are mostly in EXO, and the shared mailboxes are still on prem. I think maybe we're supposed to use groups, but we're not rolling that out for a while yet. It also seems like SharePoint calendars used to be able to do something like this but now can't do recurring meetings?

Sorry if this is a dumb question.

Thanks Ants
May 21, 2004

#essereFerrari


Set the calendar as a resource and invite it to meetings

you ate my cat
Jul 1, 2007

I thought about that, but the mailbox is the organizer. Multiple people need to be able to manage the meetings, reschedule, etc, so it can't live on any one person's calendar. In the case of the recruiting teams, for example, this could be dozens of recurring meetings a month with varying internal and external parties.

death cob for cutie
Dec 30, 2006

dwarves won't delve no more
too much splatting down on Zot:4
Pulling this from the Windows 11 thread. (For context, I work at a non-profit org with basically no IT support where I need to set up a bunch of laptops for use by students; right now we just install everything manually, which takes hours. I am absolutely willing to learn some stuff to make this easier, but documentation on some things for Azure/Entra/AD/whatever admin seems kind of thin.).

death cob for cutie posted:

Would this be the appropriate thread to ask about enterprise-level stuff, specifically Windows Configuration Designer?

I have a bunch of laptops for incoming interns at my job that I want to get preinstalled with some software. This really isn't my wheelhouse but I'm trying to streamline this process a bit. Their accounts will ideally be the only ones on them (we want them to be fully responsible for these machines - there's no other local admin account on them), so I don't want to go through the OOBE experience, sign in with my Entra credentials, install poo poo and then have to remove my account and add theirs. I'm trying Windows Configuration Designer to see if I can streamline some of this, but it really wants me to set up either a local user account for the configurator to use or give it some kind of credentials to sign in with. Ideally this configuration package would be something I could just run on twenty laptops, rather than have to write a custom one for each user with their credentials.

If I go into the advanced configurator rather than the easy-mode wizard, will it let me rig it in such a way that I can install all this software and still have these people do the rest of the OOBE (doing the first sign-in, setting their PIN/Windows Hello, etc)? Is there another way I can get my desired outcome - maybe making an image with the software I want installed, then doing some kind of hack to remove any local user accounts and put it back into OOBE?

Some updates on this: it looks like the bulk Entra key option works for me, but the entire provisioning process is hanging on installing some of the software I've included in the package. I assume it's waiting for user input that's not showing up because I didn't pass a -silent flag or something, but I don't think those are universal for all the various Windows installers I'm using and some googling on some of the installers I'm trying to run didn't always come up with an appropriate command line option for "just install this system-wide with whatever defaults, quietly".

Have come up with the idea of doing a custom Windows ISO with the software we need built-in, but there's a potential wrinkle there I forsee - can I do a repair/restore with that ISO and still get whatever custom setup I made going? The only way for me to get the license keys for these laptops' Win11 installs, as far as I'm aware, is to actually get into them and copy the license key. If I have to wipe the drive before doing anything, well, that makes it trickier.

Alternatively,

death cob for cutie posted:

Is there another way I can get my desired outcome - maybe making an image with the software I want installed, then doing some kind of hack to remove any local user accounts and put it back into OOBE?

This sounds like it might be the best way - just slamming in a local admin account, installing software, and then purging that account to get back to the OOBE setup process. Is this an option?

dexter6
Sep 22, 2003
Probably off topic for this thread but I figured I’d post here to maybe get some help…

Do any of you work in the nonprofit space and have contact with the Microsoft sales team?

I am looking to get hired by Microsoft on the nonprofit sales team but I’m having a heck of a time making contacts and finding folks on that team to network with.

So if you know someone who works at MS on the NP team, I would be forever grateful for an introduction.

Thanks!

dexter6 fucked around with this message at 20:00 on Jun 6, 2024

klosterdev
Oct 10, 2006

Na na na na na na na na Batman!
Have you tried getting your nonprofit licenses through techsoup?

dexter6
Sep 22, 2003

klosterdev posted:

Have you tried getting your nonprofit licenses through techsoup?
Sorry, edited for clarity, I’m trying to get a job at Microsoft and but I’m having trouble connecting with folks on the nonprofit team.

sporkstand
Jun 15, 2021

death cob for cutie posted:

Pulling this from the Windows 11 thread. (For context, I work at a non-profit org with basically no IT support where I need to set up a bunch of laptops for use by students; right now we just install everything manually, which takes hours. I am absolutely willing to learn some stuff to make this easier, but documentation on some things for Azure/Entra/AD/whatever admin seems kind of thin.).

Some updates on this: it looks like the bulk Entra key option works for me, but the entire provisioning process is hanging on installing some of the software I've included in the package. I assume it's waiting for user input that's not showing up because I didn't pass a -silent flag or something, but I don't think those are universal for all the various Windows installers I'm using and some googling on some of the installers I'm trying to run didn't always come up with an appropriate command line option for "just install this system-wide with whatever defaults, quietly".

Have come up with the idea of doing a custom Windows ISO with the software we need built-in, but there's a potential wrinkle there I forsee - can I do a repair/restore with that ISO and still get whatever custom setup I made going? The only way for me to get the license keys for these laptops' Win11 installs, as far as I'm aware, is to actually get into them and copy the license key. If I have to wipe the drive before doing anything, well, that makes it trickier.

Alternatively,

This sounds like it might be the best way - just slamming in a local admin account, installing software, and then purging that account to get back to the OOBE setup process. Is this an option?

Maybe I'm missing something but is there a reason that you can't use either MDT or Autopilot to accomplish this? If you've already ruled both of those out, what was the reasoning?

buffbus
Nov 19, 2012
Probably just wasn't encountered yet. MDT is a proven classic and should work well for them if they have the time and expertise to create packages and put it all together.

I assume they don't have Intune licenses for Autopilot.

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010
If they have entitlements to A3 licensing then they get intune for education. Setting up intune w/ autopilot, apps from the microsoft store & winget is a gamechanger for onboarding. Hope deathcob has it.

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010
Hate to double post but microsoft finally did a good thing. Microsoft Entra PowerShell:

quote:

Backward compatibility with AzureAD module: Microsoft Entra PowerShell accelerates migration from the recently announced AzureAD module deprecation.

Compatible with both PS 5.1 & 7.

Potato Salad
Oct 23, 2014

nobody cares


incoherent posted:

Hate to double post but microsoft finally did a good thing. Microsoft Entra PowerShell:

Compatible with both PS 5.1 & 7.

it's really nice, jump in

(not that anyone has a choice in the matter eventually)

Thanks Ants
May 21, 2004

#essereFerrari


Thank christ, they were pitching the Graph API as the replacement for a while but it wasn't really.

Now they just need to fix the SharePoint module so it works in PowerShell and not only Windows PowerShell, and then make go and punch teams repeatedly in the face that create M365 PowerShell modules that can't be used with delegated permissions.

Potato Salad
Oct 23, 2014

nobody cares


frankly would have been fine with the graph API itself at my org, we already have to use it for so many goshdarned edge cases that never should have been edge cases

ms listened to feedback on this one

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


Ever since I learned the existence of Microsoft365DSC I started not caring about PowerShell but finally.

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


Potato Salad posted:

frankly would have been fine with the graph API itself at my org, we already have to use it for so many goshdarned edge cases that never should have been edge cases

ms listened to feedback on this one

What kind of gaps have you ran into?

tehinternet
Feb 14, 2005

Semantically, "you" is both singular and plural, though syntactically it is always plural. It always takes a verb form that originally marked the word as plural.

Also, there is no plural when the context is an argument with an individual rather than a group. Somfin shouldn't put words in my mouth.
I dig Graph API to manage SharePoint but there are some frustrating limitations for things like the term store (not seeing what is a child of another term, needing the id to find the term you need the… id for). It’s so close to great if they could just iron out that kind of crap.

bitterandtwisted
Sep 4, 2006




Has anyone done a cross-tenant 365 mail migration?
We've got a divestment coming up. I've used Migrationwiz before but as both sides will be on 365 I'm having a look at this method. Two questions for anyone who's done it

Is it a huge ballache compared with third party solutions?
How does licencing work? It's about £150/year and the user licences are "per migration". What does that mean, that each user in the tenant can be migrated once, not necessarily on the same migration job? That any migration costs the same fixed fee regardless of user quantity?

unknown
Nov 16, 2002
Ain't got no stinking title yet!



First figure out what needs to be migrated out. Email is the easiest part. It's all the other data that becomes the new hell for you to figure out. You're going to have to figure out the cases where both companies need access to the same data/files. Who owns it and where should it be stored (which company).

Good luck - this kind of thing is really shows how good the company is in its internal processes - and since they will be changing, everyone is going to blame IT because files aren't in the same place any more. Make sure you stay away from being involved in those process changes if you like your sanity.

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

unknown posted:

First figure out what needs to be migrated out. Email is the easiest part. It's all the other data that becomes the new hell for you to figure out.

This is the drat truth right here. Email migrations were easy, Active day 1 and full migration done no later than day 14. 2 years later we would still be migrating servers, data, sharepoint sites, etc.

Aunt Beth
Feb 24, 2006

Baby, you're ready!
Grimey Drawer
So who else had fun with Bitlocker keys and LAPS today?

incoherent
Apr 24, 2004

01010100011010000111001
00110100101101100011011
000110010101110010
So glad I dialed in my LAPS almost one month to the day. I was easy telling people where the bitlocker key was in their MS portal, but the LAPS is more of a pita to Enter.

mllaneza
Apr 28, 2007

Veteran, Bermuda Triangle Expeditionary Force, 1993-1952




guppy posted:

I checked this, because I did have some required fields, but only in the first section before any branching. I took it out as a test and I get the same result.

Is there an option to have the form just dump responses into an O365 spreadsheet? I use Google Forms that way a lot and it's quite nice.

tehinternet
Feb 14, 2005

Semantically, "you" is both singular and plural, though syntactically it is always plural. It always takes a verb form that originally marked the word as plural.

Also, there is no plural when the context is an argument with an individual rather than a group. Somfin shouldn't put words in my mouth.

mllaneza posted:

Is there an option to have the form just dump responses into an O365 spreadsheet? I use Google Forms that way a lot and it's quite nice.

Yeah, but you have to use Power Automate and Microsoft Forms or whatever that poo poo is called now. You can set a trigger in PA to populate a SharePoint list or Excel sheet. There’s a little manual work in matching poo poo up but it’s pretty straightforward. There’s probably a prebuilt template for it in Power Automate.

The Fool
Oct 16, 2003


I thought the default data storage for form results was a spreadsheet

Hughmoris
Apr 21, 2007
Let's go to the abyss!
Is anyone knee deep in Microsoft Sentinel and/or Microsoft Defender XDR? If so, how do you like the work and what are your thoughts on future career prospects in that stack?

There have been whispers of my work steering towards Defender in the future. I'd like to tackle some homelab projects to practice on but not quite sure where to start.

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


Is there really no way to :airquote: easily :airquote: dump out all of the Entra ID PIM Roles that are active and eligible? All I want to know is what are these users roles, pim roles, active or eligible and if it's a group assignment the name of the group. It looks like the earlier ADMS cmdlets worked but there's no 1:1 Powershell Graph SDK replacement.

I suppose I'll eventually figure it out if I keep hacking away at the MS Graph API but goddamn stuff like this should not be this hard.

Potato Salad
Oct 23, 2014

nobody cares


Hughmoris posted:

Is anyone knee deep in Microsoft Sentinel and/or Microsoft Defender XDR? If so, how do you like the work and what are your thoughts on future career prospects in that stack?

There have been whispers of my work steering towards Defender in the future. I'd like to tackle some homelab projects to practice on but not quite sure where to start.



I have been absolutely loving it in my my GCC High subscription. It's a perfectly competent EDR product.

it's a bit cumbersome to get events out of it for the purpose of analysis elsewhere, but honestly, if you are using the supremo Defender products, you should really just consider adapting your workflow to just sit in the first party tools.

Edit: I don't know how affordably you can get the analysis and retention bits in particular On a shoestring homelab budget. It's fairly common for businesses to have a test tenant and a production tenant. It's also fairly common for a business to procure that test tenant as part of the initial assessment process. Any chance you could just ask your organization for a small budget to get a test tenant? Or, if they already have one, to just let you in?

Potato Salad fucked around with this message at 19:13 on Jul 30, 2024

Adbot
ADBOT LOVES YOU

AlternateAccount
Apr 25, 2005
FYGM

Gucci Loafers posted:

Is there really no way to :airquote: easily :airquote: dump out all of the Entra ID PIM Roles that are active and eligible? All I want to know is what are these users roles, pim roles, active or eligible and if it's a group assignment the name of the group. It looks like the earlier ADMS cmdlets worked but there's no 1:1 Powershell Graph SDK replacement.

I suppose I'll eventually figure it out if I keep hacking away at the MS Graph API but goddamn stuff like this should not be this hard.

I tried for a bit a while back and couldn’t figure it out quickly. If you succeed, I’d love to know how.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply