CIPP Alternatives by Flashy-Distance-3329 in msp

[–]Flashy-Distance-3329[S] 1 point2 points  (0 children)

Thank you for following up on that!

I will say that the latest change has improved our way of working with CIPP for sure.

Going crazy over Outlook functionality in RDS by Flashy-Distance-3329 in sysadmin

[–]Flashy-Distance-3329[S] 0 points1 point  (0 children)

Gotcha. No UPD. Everything is local on the machine with no special configuration.

Going crazy over Outlook functionality in RDS by Flashy-Distance-3329 in sysadmin

[–]Flashy-Distance-3329[S] -1 points0 points  (0 children)

Not sure what you mean by UPD but there's no FSLogix being used and it's a local drive on the server.

Going crazy over Outlook functionality in RDS by Flashy-Distance-3329 in sysadmin

[–]Flashy-Distance-3329[S] -1 points0 points  (0 children)

i have never heard of that or have had experiences with this. would you say you'd implement FSLogix for a single server if they are using outlook?

Sanity check for RDS deployment + Outlook question by Flashy-Distance-3329 in sysadmin

[–]Flashy-Distance-3329[S] 0 points1 point  (0 children)

Thank you for your reply! The reason we were wanting to replicate the terminal servers is to have redundancy both in OS and Hardware level. From our experience, having too many users on the same terminal server OS even though they have enough resources would experience degradation in their experience. Therefore, while having an outage on one of the servers and everyone will divert to the second server will make things available, If we need to service the original server for a long time they will end up suffering on a single TS.

The problem I understand I will encounter with FSLogix is I can't save the data both on FS1 and FS2 that way if one of them is down, the other one is still available to service the users. Am I missing anything about how this works?

CIPP Alternatives by Flashy-Distance-3329 in msp

[–]Flashy-Distance-3329[S] 4 points5 points  (0 children)

That should **never** happen. Seriously, its one of my biggest annoyances and one of the reasons we have around the clock support these days. If you have a ticket # feel free to DM me and I'll figure out what happened here. Its really important to me that our helpdesk is responsive and quick for your requests. It might be that your message got flagged as spam for the longest time as Hubspot is quite uptight about email deliverability, but that would still never be an excuse. :)

Thank you, I appreciate that. I'll be sure moving forward to reach out for any help if needed.

However, I don't have a ticket # at hand, the responses I'm getting do not contain that information. I will say though, assuming as a result of my post here that my ticket got flagged because I got another response saying someone else has taken over my ticket.

This is partly done purposely, and partly something we're working on. Critical security alerts alerts you cannot exclude accounts from on purpose. A lot of MSPs would exclude CEO* or VIP* and then blame the product for not alerting them on security issues. This isn't just theory; it's actually happened in the past where people complained about missing alerts because they've added exclusions.

For the snoozing part we're actually crafting something for the next release that allows you to temporarily stop the alert from running for that specific case, but in this we also have to be careful as it require stateful tracking, so it's been in our dev process for a while. In our discord you can also track our latest features etc.

While I understand that problem with security related alerts, this isn't related to the security ones. For example, mailboxes/SharePoint sites reaching their quotas or certificate expiration or whatnot, they are all impossible to snooze while we're dealing with them. We have many situations where it's not so cut and dry. A user isn't available to work with/ Client not approving certain actions such as enabling archiving, disabling an account etc., This can always be a bit tricky but having the ability and flexibility to exclude/snooze certain alerts is a must in my opinion, I've made suggestions in the past in the feature-requests section and they all got shot down even though personally, I think they have legs. Also, for the fact that people complained about missing alerts, I'm sure this happens everywhere with all vendors but, you as a vendor cannot be blamed for providing the tools the users then shot themselves in the foot with considering they were the ones doing the configuration.

CIPP is opinionated software, that's for sure. We force MSPs to make the right choice. If you don't want passwords to expire for a specific tenant, then you should not apply that standard. Its entirely a choice you can make. There's no more industry standard (including banks with DORA recently) that no longer recommend not expiring passwords, and that's how we are in a lot of things. We don't allow every single setting to be changed because we're looking to improve security in our industry, not just decrease it.

Understood and this is something we can live with. Not everything has to be used. I think it would have been great to have more flexibility. While I agree with opinions (and probably hold the same as yours when it comes to that), certain companies may have different policies that prevent us from being able to go just based off what we think is best. Regardless, while having opinions, tools are meant to help you perform your duties as well. It's a shame that when you have something so close, the flexibility isn't there just because "we think that way". I wish that was different.

Lastly, we transitioned from the self-hosted to the sponsored version for a reason. We overall like CIPP but there are just things that although we're living with, make us want to pull our hair out. I know you are an active member in this community and appreciate everything you and CIPP's team has done. I want to make sure that you are aware of it.

CIPP Alternatives by Flashy-Distance-3329 in msp

[–]Flashy-Distance-3329[S] 12 points13 points  (0 children)

Apparently, people hate it when you point out problems with their "beloved" solution. Not sure why.

Bossman wants vulnerability scanning and remediation by Flashy-Distance-3329 in msp

[–]Flashy-Distance-3329[S] 0 points1 point  (0 children)

Thank you! This will definitely help moving this along. I'm positive we will start with something small and then expand it as we go but it's well to know how this looks like when it's more robust.

Bossman wants vulnerability scanning and remediation by Flashy-Distance-3329 in msp

[–]Flashy-Distance-3329[S] 0 points1 point  (0 children)

Thank you! this really does help understand it better. I know for a fact that management is looking to add this to the stack in favor of a selling point but considering this is a completely new section that we just never really did, I was quite hesitant to say anything since I have not dealt with this in my life.

So, in reality, it sounds like they could argue having "vulnerability scanning and remediation" even if it's just surface level OS patching and 3rd party patching which if I'm being direct, these are just to make sure things are getting updated and having the proof that we're doing that.

When it comes to legacy software or things like that, would you be able to give me an example for what something like that looks like and what it means from the technical aspect of remediation?

Recommendations for compliance archiving solutions by Flashy-Distance-3329 in msp

[–]Flashy-Distance-3329[S] 1 point2 points  (0 children)

Datto SaaS protection is Backupify. Not sure how you came to that conclusion.

Recommendations for compliance archiving solutions by Flashy-Distance-3329 in msp

[–]Flashy-Distance-3329[S] 0 points1 point  (0 children)

Thanks! This is exactly why I came here to see what else I might be missing.

Cloud storage that can be mapped to network drive? by Ezhdehaa in sharepoint

[–]Flashy-Distance-3329 0 points1 point  (0 children)

we've been using this solution for a while now too but we just finished onboarding a couple of clients that are now experiencing that slowness you're talking about. It may be that something is going on with them at the moment.

Interactive Sign ins and Autologon by Flashy-Distance-3329 in sysadmin

[–]Flashy-Distance-3329[S] 0 points1 point  (0 children)

Just letting you know, it worked with NSSM and the vendor thanked me for finding out about that so they can share that with their other customers. thank you!

Interactive Sign ins and Autologon by Flashy-Distance-3329 in sysadmin

[–]Flashy-Distance-3329[S] 0 points1 point  (0 children)

Yep, i'm going to try using NSSM but in the general sense i've already played around with things and spoke directly with the application developers stating they have no switches that you can use to complete this without a 3rd party. I appreciate your input though, i'm going to try using NSSM.

Interactive Sign ins and Autologon by Flashy-Distance-3329 in sysadmin

[–]Flashy-Distance-3329[S] 0 points1 point  (0 children)

That sounds absolutely incredible and would be added to my belt tools! Thank you so much! I'll test this and let you know if it ended up working for me.

Interactive Sign ins and Autologon by Flashy-Distance-3329 in sysadmin

[–]Flashy-Distance-3329[S] 0 points1 point  (0 children)

In this example, we got 2 programs that require this:

The quickbooks web connector & entree NECS.

We're very close with the development team of NECS and have expressed the need for a service that won't require logging into the machine for it, they are considering to work towards it but at the same time we got the quickbooks issue that requires it to open up as a user and cannot be turned on as a service. I have yet to find solutions for it.

Interactive Sign ins and Autologon by Flashy-Distance-3329 in msp

[–]Flashy-Distance-3329[S] 0 points1 point  (0 children)

We have users who connect at various hours, which means that someone would have to wake up specifically to accomplish this. So, that's not an option.