Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
mewse
May 2, 2006

Thanks Ants posted:

Unless you've got a good reason why it won't work then how ever many licenses of MS365 Business Premium as there are users, with Azure AD logins on the PCs, user folders copied to their personal OneDrive space, and some Intune policies to keep some sort of consistency between the PCs in terms of naming, update rings, software installs etc. Files in SharePoint.

This assumes the types of files are suitable for SharePoint, the internet connection is acceptable, etc.

Yeah a small company like that shouldn't have the maintenance hassle of on-site servers.

Adbot
ADBOT LOVES YOU

mewse
May 2, 2006

Anyone using M365 MFA with azure ad/windows virtual desktop? Vendor wants to set us up with a third party mfa / app but I suspect the built in M365 offering would be good enough

mewse
May 2, 2006

Internet Explorer posted:

Yes, but only on the first time the you log in via the client app or the first time you log in on that device via the browser. Azure Conditional Access, but yeah, similar thing.

What's the use case that the vendor is saying it won't satisfy?

I haven't gotten into it with them yet, we're just starting to look at mfa because of an insurance questionnaire for cyber coverage.

The same vendor supports my former employer and the solution they're using is duo mfa. It looks like it supports hardware tokens which would appease* my staff that don't have employer-provided smartphones.

*not really appease just counter "i'm not putting that app on my personal device"

mewse
May 2, 2006

Rick posted:

Yeah it sucks. We actually have a site where we get 20 up from the same provider but the main office is reliant on fixed wireless.

Radio wireless is capable of way more bandwidth than that, maybe they've got bad distance to the tower or something

mewse
May 2, 2006

You guys are adverse to cox but maybe you could sign up for the bandwidth and use a modern router like a meraki for redundant uplinks when cox goes down

mewse
May 2, 2006

bolind posted:

So CentOS is dead. I was looking at Oracle Linux and it looks had decent. Anyone got any experience with it?

I'd stay way the gently caress away from anything Oracle. I don't use centos personally so I googled what you're talking about and found this article that says centos isn't as dead as the community is assuming.

If you're looking for a distro with commercial support, SUSE is apparently decent.

mewse
May 2, 2006

Our xerox photocopier seems to be screwing up the dns resolution of the office 365 smtp server about like 5-10% when doing scan to email. We have it set to use google dns (8.8.8.8/8.8.4.4) but when I ping smtp.office365.com on my desktop, it seems to lag to resolve the address. The dns records also seem screwy to me (via dig in google toolbox):

code:
;QUESTION
smtp.office365.com. IN A
;ANSWER
smtp.office365.com. 300 IN CNAME outlook.office365.com.
outlook.office365.com. 300 IN CNAME outlook.ms-acdc.office.com.
outlook.ms-acdc.office.com. 57 IN CNAME LYH-efz.ms-acdc.office.com.
LYH-efz.ms-acdc.office.com. 7 IN A 52.96.119.82
LYH-efz.ms-acdc.office.com. 7 IN A 52.96.97.130
LYH-efz.ms-acdc.office.com. 7 IN A 52.96.183.226
LYH-efz.ms-acdc.office.com. 7 IN A 52.96.182.2
Three CNAMEs and four A records??

Anyway the vendor has suggested to replace smtp.office365.com with a direct IP address - it seems to be working for now - but I hate that solution because the hostname can resolve to several different server IPs and is constantly being updated by MS.

Any of you guys dealt with something like this?

mewse
May 2, 2006

Yeah I figured out after I posted that it's a 3 level CNAME chain that ends with four A records, I still don't really know what to do with this photocopier because I've plugged one of those IPs into it instead of the hostname (working fine for now)

mewse
May 2, 2006

That's probably worth a shot, just entered that into the photocopier, thanks

e: 2 successful scans so far, gonna have to watch it tomorrow to make sure it's corrected

mewse fucked around with this message at 23:26 on Nov 24, 2021

mewse
May 2, 2006

unknown posted:

It's the size of the DNS packet and the crap resolver in the scanner that bombs out if it's too big a packet. (Often happens when there's additional info tossed into the response). Usually happens when there's authority info added to the packet - which will increase the packet size to >256bytes.

Holy poo poo I just installed wireshark and pinged smtp.office365.com a bunch of times and triggered a dns response that is 257 bytes

mewse
May 2, 2006

Silly Newbie posted:

You could just stop doing authenticated SMTP for your scanners unless they need to scan outside your tenant.
You can just use domain-tld.mail.protection.outlook.com for your SMTP server over 25, and it goes through just fine so long as it stays in org.

Is there any documentation on how this setup works / what this setup is supposed to be used for? I did find the xxx.mail.protection.outlook.com hostname for our o365 tenant and it only resolves to a single IP address with no CNAMEs, I'm just wondering about why it would accept smtp submissions on port 25 with no authentication.

e: hmm this looks like it has the details

mewse fucked around with this message at 19:36 on Dec 3, 2021

mewse
May 2, 2006

mewse
May 2, 2006

bolind posted:

Watch your electricians as a hawk as they will ignore any instructions, no matter how detailed, and just wing it.

I use a dedicated data cabling guy because I don't trust electricians to run ethernet

Adbot
ADBOT LOVES YOU

mewse
May 2, 2006

MF_James posted:

I'm less than pleased, we had to have them re-punch like 30% of the jacks they did so they can gently caress off for not testing.

Like every electrician doing "low voltage" cabling because it's super easy with no risk of being electrocuted then loving it up because they don't understand data cabling

e: also I don't know why electricians are allergic to port numbering on patch panels

mewse fucked around with this message at 16:22 on Oct 5, 2023

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply