Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
TheFace
Oct 4, 2004

Fuck anyone that doesn't wanna be this beautiful

Internet Explorer posted:

Does anyone use Azure Microsoft Backup Server (MABS?) and if so, why do you hate yourself this much?

At my last job yes. And I did a lot back then. So glad to be out of Operational IT!

Adbot
ADBOT LOVES YOU

MF_James
May 8, 2008
I CANNOT HANDLE BEING CALLED OUT ON MY DUMBASS OPINIONS ABOUT ANTI-VIRUS AND SECURITY. I REALLY LIKE TO THINK THAT I KNOW THINGS HERE

INSTEAD I AM GOING TO WHINE ABOUT IT IN OTHER THREADS SO MY OPINION CAN FEEL VALIDATED IN AN ECHO CHAMBER I LIKE

Zero VGS posted:

Azure AD also has something called Azure Active Directory Domain Services, which counter-intuitively would not allow public-facing DC services or LDAP for years and years. They actually expected you to make a site-to-site VPN which wouldn't have worked for us and all the work-from-home people (and no we're not paying for Win 10 Enterprise). But very recently they improved it to allow a public IP that can have domain services and Secure LDAP. Check it out here: https://azure.microsoft.com/en-us/services/active-directory-ds/#overview

I have a client with this, it's pretty slick except the fact that it can't be moved between subscriptions so I'm going to be stuck deleting it and rebuilding it so we can takeover billing/management.

jaegerx
Sep 10, 2012

Maybe this post will get me on your ignore list!


LochNessMonster posted:

How are you dealing with not running docker on it, just use a VM?

Yup. There’s some struggles with emulated software right now but it’s so loving fast.

Most of my poo poo is in the cloud anyway so I don’t run a lot locally anymore.

Vargatron
Apr 19, 2008

MRAZZLE DAZZLE


How's y'all's change freeze week going so far?

CLAM DOWN
Feb 13, 2007




Vargatron posted:

How's y'all's change freeze week going so far?

What's this???

22 Eargesplitten
Oct 10, 2010



It's a US thing, if changes froze in Canada you wouldn't be able to get anything done 9 months out of the year.

Woof Blitzer
Dec 29, 2012

[-]

Vargatron posted:

How's y'all's change freeze week going so far?

Not till Dec 15 dude... duh

Vargatron
Apr 19, 2008

MRAZZLE DAZZLE


CLAM DOWN posted:

What's this???

Ah you know, the time where somebody rolls "a quick fix" into prod and it causes everybody to work over the holiday.

Methanar
Sep 26, 2013

by the sex ghost

Vargatron posted:

How's y'all's change freeze week going so far?

I was thinking about getting some particular thing done so I can discuss it on friday in one of the meetings.

Then I remembered, oh wait, US holiday. That’s awesome:

I’ll be able to just get through some of my backlog work without anybody being around to assign me more.

I wish all the americans would gently caress off more often.

devmd01
Mar 7, 2006

Elektronik
Supersonik
As an American I concur!

The Fool
Oct 16, 2003


devmd01 posted:

As an American I concur!

Not emptyquoting

Bonzo
Mar 11, 2004

Just like Mama used to make it!

Vargatron posted:

Ah you know, the time where somebody rolls "a quick fix" into prod and it causes everybody to work over the holiday.

I run content/document repository systems and we have lots of people doing end of year reporting. In most cases I can't even restart a service unless I get approval 2 levels up AND it's during a contractually bound maintenance window.

George H.W. Cunt
Oct 6, 2010





Been on vacation and just got word that the company is insolvent and is being liquidated. Happy Thanksgiving!

I knew it was coming and have been looking for a new job but ugh the pressure is really on now.

LochNessMonster
Feb 3, 2005

I need about three fitty


George H.W. oval office posted:

Been on vacation and just got word that the company is insolvent and is being liquidated. Happy Thanksgiving!

I knew it was coming and have been looking for a new job but ugh the pressure is really on now.

That sucks, especiallly just before thanksgiving. Hope you find a new job quickly.

Olpainless
Jun 30, 2003
... Insert something brilliantly witty here.
Going to ask a nebulous question here, hopefully there's some wider insight here.

Our director has asked me/our infrastructure team to look at making a reporting server (PowerBI on-premises) externally facing, whereas I'd suggest it's much safer to limit access to this to behind the VPN - is this something that many places tend to do? My experience is that reporting stuff should generally not be something available to the outside world.

Dick Trauma
Nov 30, 2007

God damn it, you've got to be kind.
I hope that if you ask for an explanation they will provide one. If they don't, or if they don't seem to understand, the phrasing I use is "Do you have a compelling business reason for exposing this server to the outside world? If not I will put it behind the VPN."

At the very least sometimes it prods people into examining their reasoning, or lack of it.

GreenNight
Feb 19, 2006
Turning the light on the darkest places, you and I know we got to face this now. We got to face this now.

My guess is he wants to access it and can't be rear end'ed to VPN in first.

Olpainless
Jun 30, 2003
... Insert something brilliantly witty here.

Dick Trauma posted:

I hope that if you ask for an explanation they will provide one. If they don't, or if they don't seem to understand, the phrasing I use is "Do you have a compelling business reason for exposing this server to the outside world? If not I will put it behind the VPN."

At the very least sometimes it prods people into examining their reasoning, or lack of it.

So the governing body can access a report(s).

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:

Olpainless posted:

Going to ask a nebulous question here, hopefully there's some wider insight here.

Our director has asked me/our infrastructure team to look at making a reporting server (PowerBI on-premises) externally facing, whereas I'd suggest it's much safer to limit access to this to behind the VPN - is this something that many places tend to do? My experience is that reporting stuff should generally not be something available to the outside world.

I don’t particularly think VPNs are a good security model as a general practice - the network is to say the least an unreliable security boundary.

Since this is on prem there may not be much you can do to avoid it, but identity based security models > network based security models.


Could you replicate the data to bigquery or something similar and stick it behind SSO?

Butter Activities
May 4, 2018

I’m taking my Core 2 test Monday, mostly just watching all of Messer’s videos plus his free study group live-streams. Probably a little underprepared since most people recommend studying two months before but I this is all the time I have so gently caress it.

i am a moron
Nov 12, 2020

"I think if there’s one thing we can all agree on it’s that Penn State and Michigan both suck and are garbage and it’s hilarious Michigan fans are freaking out thinking this is their natty window when they can’t even beat a B12 team in the playoffs lmao"

Olpainless posted:

Going to ask a nebulous question here, hopefully there's some wider insight here.

Our director has asked me/our infrastructure team to look at making a reporting server (PowerBI on-premises) externally facing, whereas I'd suggest it's much safer to limit access to this to behind the VPN - is this something that many places tend to do? My experience is that reporting stuff should generally not be something available to the outside world.

How does Power BI handle auth on prem? Is it AD or can it use SSO?

The Fool
Oct 16, 2003


Olpainless posted:

Going to ask a nebulous question here, hopefully there's some wider insight here.

Our director has asked me/our infrastructure team to look at making a reporting server (PowerBI on-premises) externally facing, whereas I'd suggest it's much safer to limit access to this to behind the VPN - is this something that many places tend to do? My experience is that reporting stuff should generally not be something available to the outside world.

We make reports available to our board by rendering them to pdf and putting them on Sharepoint.

Olpainless
Jun 30, 2003
... Insert something brilliantly witty here.

i am a moron posted:

How does Power BI handle auth on prem? Is it AD or can it use SSO?

AD. Some vague information out there that it's capable of SSO using ADFS but we're not set up for it.

Vulture Culture
Jul 14, 2003

I was never enjoying it. I only eat it for the nutrients.

George H.W. oval office posted:

Been on vacation and just got word that the company is insolvent and is being liquidated. Happy Thanksgiving!

I knew it was coming and have been looking for a new job but ugh the pressure is really on now.
This was me and Methanar a year and a half ago. Job hunting was stressful but I think we both ended up in really good places!

i am a moron
Nov 12, 2020

"I think if there’s one thing we can all agree on it’s that Penn State and Michigan both suck and are garbage and it’s hilarious Michigan fans are freaking out thinking this is their natty window when they can’t even beat a B12 team in the playoffs lmao"

Olpainless posted:

AD. Some vague information out there that it's capable of SSO using ADFS but we're not set up for it.

I would use an Azure AD app proxy in that case assuming Power BI can do the IWA stuff (conditional access + other security features you get with Azure AD are good enough imo), but if that isn’t possible I wouldn’t like it either but I don’t like things using AD being externally facing at all.

Dick Trauma
Nov 30, 2007

God damn it, you've got to be kind.
Two jobs ago the management answer to the problem would've been to print out the reports and messenger them to whomever needed to see them. They spent at least $20k per year on messenger services instead of just emailing stuff.

The Iron Rose
May 12, 2012

:minnie: Cat Army :minnie:
I’m not overly familiar with PowerBI but if your management doesn’t need to run analyses themselves I’d say the simplest option would be to automate the creation of a PDF and use a scheduled task + script to export it somewhere easily accessible over the internet.


I probably wouldn’t expose the whole server to the internet either tbh.

Or use Azure AD if your org has it.

Methanar
Sep 26, 2013

by the sex ghost

Vulture Culture posted:

This was me and Methanar a year and a half ago. Job hunting was stressful but I think we both ended up in really good places!

The rabbit, it turns out, was not healthy.

Olpainless
Jun 30, 2003
... Insert something brilliantly witty here.
Cheers, this has been valuable feedback. Much appreciated.

Impotence
Nov 8, 2010
Lipstick Apathy
as a general rule, even if it's behind vpn you don't drop all your sso requirements or ad requirements

otherwise you end up with the crunchy outer shell, soft creamy centre issue. user-controlled devices on vpn are still hostile.

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


i am a moron posted:

How does Power BI handle auth on prem? Is it AD or can it use SSO?

Isn't PowerBI just another Microsoft Office 365 Application that uses Azure AD?

i am a moron
Nov 12, 2020

"I think if there’s one thing we can all agree on it’s that Penn State and Michigan both suck and are garbage and it’s hilarious Michigan fans are freaking out thinking this is their natty window when they can’t even beat a B12 team in the playoffs lmao"
https://powerbi.microsoft.com/en-us/report-server/

For some reason this exists. I have never actually seen it in action cause the data gateways seem to be fine for getting on prem data onto the SaaS version of Power BI.

Olpainless
Jun 30, 2003
... Insert something brilliantly witty here.

Biowarfare posted:

as a general rule, even if it's behind vpn you don't drop all your sso requirements or ad requirements

otherwise you end up with the crunchy outer shell, soft creamy centre issue. user-controlled devices on vpn are still hostile.

Oh yeah, it's still managed by AD, but i feel having something like this running operational stuff able to be causally probed by the world seems like a terrible idea.


i am a moron posted:

https://powerbi.microsoft.com/en-us/report-server/

For some reason this exists. I have never actually seen it in action cause the data gateways seem to be fine for getting on prem data onto the SaaS version of Power BI.

Yep, it's this we're using. Basically everything we have is on premuse stuff and we have a hell of a lot of SSRS stuff on it as well.

And powerbi saas has vicious pricing.

Thanks Ants
May 21, 2004

#essereFerrari


George H.W. oval office posted:

Been on vacation and just got word that the company is insolvent and is being liquidated. Happy Thanksgiving!

I knew it was coming and have been looking for a new job but ugh the pressure is really on now.

Did they wait until people were taking time off so they couldn't strip every valuable item out the office on their way out the door?

George H.W. Cunt
Oct 6, 2010





Thanks Ants posted:

Did they wait until people were taking time off so they couldn't strip every valuable item out the office on their way out the door?

They dropped it a hour before sending the email that said “good news early release at noon on Wednesday!” Lol

I can’t imagine what’s going on in the office now. I’ll have to run in and grab my poo poo and headset on Monday. Supposedly we have a buyer and IT will be needed for a bit longer but for the rest? Yea they’re gone.

Dick Trauma
Nov 30, 2007

God damn it, you've got to be kind.
I'm reading job postings at LinkedIn and just saw one for a company called GOAT Group. :goatsecx:

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

There’s few products where the gap between what a name promises and the product does is greater than Power Bi.

Gucci Loafers
May 20, 2006

Ask yourself, do you really want to talk to pair of really nice gaudy shoes?


Does anyone have any recommended training courses or reading on Terraform for Azure outside of their website? That's my next thing to do for my job...

This PluralSight one is interesting Implementing Terraform on Microsoft Azure but I'm kind of surprised it's only about three hours of content.

It can't be that simple... can it?

Vulture Culture
Jul 14, 2003

I was never enjoying it. I only eat it for the nutrients.

Gabriel S. posted:

Does anyone have any recommended training courses or reading on Terraform for Azure outside of their website? That's my next thing to do for my job...

This PluralSight one is interesting Implementing Terraform on Microsoft Azure but I'm kind of surprised it's only about three hours of content.

It can't be that simple... can it?
Terraform is about ten minutes of learning, followed by memorizing a lifetime of idiosyncratic details about your cloud provider

Adbot
ADBOT LOVES YOU

Matt Zerella
Oct 7, 2002

Norris'es are back baby. It's good again. Awoouu (fox Howl)
You're better served learning the overall functions of terraform rather than Azure specifics. Things like count, workspaces, modules, state, etc.

The certification is not hard to get and a very good way to learn TF for beginners. Even if you don't take the test.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply