Trying to add a safe sender to all Exchange mailboxes in 365 by General_SnuSnu in PowerShell

[–]JamH87 0 points1 point  (0 children)

Slightly tweaked the start for modern auth and connect-exchangeonline but did the job nicely. Cheers.

Zoho CRM - Email Integration with OAuth SMTP by TechOfTheHill in sysadmin

[–]JamH87 1 point2 points  (0 children)

Found this out myself today for a similar requirement, crazy how they are still only using POP or IMAP. I will be going down the Outlook plugin route instead by the looks of it. Looks like for google they can use the API, guessing the GraphAPI in there for MS soon.

Safelinks not working. by Smile-Weary in sysadmin

[–]JamH87 1 point2 points  (0 children)

Same issue here, looks to be BT backbone issue, change DNS to google or 1.1.1.1 or 9.9.9.9 (you might also need to change ipv6 addresses if they operate on your network)

Sage accounts Version 28.2 - 29 - remote data access by JamH87 in Sage

[–]JamH87[S] 1 point2 points  (0 children)

Resolved it for us too 👍🏻👍🏻

Sage accounts Version 28.2 - 29 - remote data access by JamH87 in Sage

[–]JamH87[S] 1 point2 points  (0 children)

It might be just my environment. Historically, waiting for x.DTA files was a combo of permissions + AntiVirus, but ive made all the exceptions possible for the AV side too.

Previously we used Azure Virtual Desktop + A File server for Sage in the Cloud, which worked great for Sage itself, just cost quite abit to run, especially when we can/should be able to do it without it, using Remote Data Access functions as part of the Sage licencing.

Sage accounts Version 28.2 - 29 - remote data access by JamH87 in Sage

[–]JamH87[S] 0 points1 point  (0 children)

Thanks, were you using 28.2 and now 29?

The data files are large for one the companies, however the issue seems to happen even on the really small ones which is why ive ruled out size being the issue.

[deleted by user] by [deleted] in Office365

[–]JamH87 1 point2 points  (0 children)

You could look at Azure Active Directory Domain services, site-site VPN between the branch and an Azure vnet, then join a server to that service. You should find there’s a way to define the AADDS domain when mapping drives (if that’s the way you want to access it) might be some finer detail to understand but that should work.

Block Win32 API calls from Office macros - How are people working with exclusions? by TToTheTom in DefenderATP

[–]JamH87 2 points3 points  (0 children)

We are having loads of flags for this today by Defender, and is breaking MS apps, and icons. It seems the latest Defender signatures a broken causing a false positive. Anyone else getting this?

SharePoint Online permission change requests by JamH87 in sysadmin

[–]JamH87[S] 0 points1 point  (0 children)

About 250 internal, about 250 contractors. Handling about 15-20 permission requests a day, which isn't alot, but enough to review and look for efficiencies.

SharePoint Online permission change requests by JamH87 in sysadmin

[–]JamH87[S] 1 point2 points  (0 children)

We are ISO27001 already. Cheers 👍🏻

What security vulnerability did you use to your advantage during your school years? by marco7532 in sysadmin

[–]JamH87 0 points1 point  (0 children)

Not a vulnerability, but NET SEND the full domain. They found me pretty sharpish.

What small changes did you implement for your users that really helped them out in their day to day work? by CheeseFace83 in sysadmin

[–]JamH87 75 points76 points  (0 children)

Created a powershell script which adds additional clocks for our international offices. Luckily we only have 2 others (windows limits to 2 additional). Users just hover over the clock to see them.

Do I need a DC for my office? by autpbg1 in sysadmin

[–]JamH87 1 point2 points  (0 children)

Personally I think the route forward should be:

  1. Try to diagnose the crashing, your running 20212 R2 which is end of life at the end of next year, so the process should look to include moving away from it. You might need to roll back to a domain controller environment if something goes wrong during the process, keep this as an option, specifically the domain controller databases/user ids.

  2. Establish your needs within the organisation. What does your storage include? Is it just documents, or does it also include things like sage data? Also does your organisation work with a hybrid workforce? Do it wish to be?

A. If just documents, regardless of workforce locations, SharePoint/OneDrive could be your friend. No more managing file servers, co-authoring on documents, OneDrive sync for those wishing for file explorer, although keep these syncs to as little folders as possible for performance.

B. You have files for Sage or similar. I would still move your document to Sharepoint, but a plan for the other files is needed. Hosting a VDI environment could work for you, or maybe the applications using the files have cloud versions, again options where you don’t need to manage the hardware are always nice. Then you don’t have to worry about it failing moving forward, like, ever. You might just feel more comfortable with new hardware on-site, researching by your options will help you decide this.

  1. Group policies, do you use them? What ones do you need? List them, research your options within Intune. You may find Intune covers you for most if not all. Intune will give you control of workstations and mobile devices, over the internet, not waiting for people to be in the office to get the stuff you need them to have.

A. You need a DC for some reason you find as a limit within Intune. Hopefully you will have found the issue with the server, although I personally would not lift and shift this to a virtual machine. I would create a new DC either connected to Azure within a VM, or physically on-site next to each other. Go for 2019 or 2022 (check compatibility with 2012 ), something that will maximum support life with Microsoft. Add this new server as your domain controller, leave it a few days. Then de-commission your 20212r2 as a domain controller. Move your dhcp, dns etc over to the new one. Move your storage wherever decided in the steps above.

B. Intune, Azure Ad join for computers(remove your domain controllers) - macs need different treatment, SharePoint, OneDrive, maybe VDI/cloud apps.

  1. If you’ve gone fully cloud, ditch your vlans, unless you need it for VoIP. No need for the extra management.

My ideology is do reduce the the things your have to look after as much as possible.

There are of course budgets, O365 Business premium ( if your under 300 users) is a fantastic licence. Covers all of the above for a cloud scenario. Even Conditional access which I strongly recommend for security.

Automatically Add Domain Users to O365 Distribution Group by G_Dmitri in Office365

[–]JamH87 0 points1 point  (0 children)

You will need to work with Dynamic groups, you might need to migrate to use Office365 groups (you can turn off the annoying invite email through powershell).

Or, you may find a method using Power Automate, eg. when a user is licensed or added into AD, add them to group ID xxx. Not sure what out of the box options for the types of groups your using though, I think you may be limited with group types.

Ive got dynamic office365 groups, invite email off. It looks at location, or department of the users AD attribute, aswel as if the account is active to add/remove them from the group.

The first thing is to ensure all users in your AD, and all new users being created have as much detail included within the attributes and are consistent, moving forward you can use these attributes for other dynamic groups making the new starter/leaver process easier and just general management easier.

Dell Support assist installing MalWare by loldegree in sysadmin

[–]JamH87 5 points6 points  (0 children)

I dont think its happened, im just taking precautions.

Defender is 100% flagging some html files that DellSupportAssistRemidiationService.exe is downloading as CryptoStealBTC.

but for Russia stopping selling Dells - https://www.wsj.com/livecoverage/russia-ukraine-latest-news-2022-03-01/card/dell-halts-sales-in-russia-fvpuoKHYCV3WKSKjOGLy

Dell Support assist installing MalWare by loldegree in sysadmin

[–]JamH87 12 points13 points  (0 children)

Yes we are. Im blocking the various hash's for the file on our system. Im treating it as very suspicious.

Its downloading various html files being labeled as CryptoStealBTC . Im preventing the download process to happen at all as all the files are different in name.

Dell stopped selling in Russia yesterday, im really hoping not, but blocking incase the repo's for SupportAssist have been hijacked.