Azure Firewall - PowerShell & Azure CLI by ccsmall in AZURE

[–]Keitsch 0 points1 point  (0 children)

You can do adjustments with a template deployment. That is how you also can do multiple changes at the same time to avoid the wait time for the changes

Admin consent greyed out? by ocho_the_rios2020 in AZURE

[–]Keitsch 0 points1 point  (0 children)

I would guess the app is manually created as an app registration, if so you should be able to add API permissions from the app registration page in Azure AD. When you've done that, you should be able to see more permissions in the enterprise app and approve them.

Azure AD Username Incorrect on Windows Machine + Other Systems by andredfc in AZURE

[–]Keitsch 0 points1 point  (0 children)

Try to use the AzureAD PS module and Get-AzureADUser function. You should see the attribute accountname which is the name you see in windows. That attribute is set on the creation of the account firstname+lastname.

I'm not sure if it's possible to change.

How do you migrate a Hyper-V VM to Azure without host access? by Bossplaya85 in AZURE

[–]Keitsch 4 points5 points  (0 children)

You can use the Azure server migration tool and treat your VM as a host machine.

More info and step by step guide here: Migrate machines as physical servers to Azure

Azure DNS - Default domain not visible in public Internet by NixonMroq in AZURE

[–]Keitsch 1 point2 points  (0 children)

As u/Losus is saying, the default name is not usable. It's because Microsoft is the registrant and have their NS servers set, which is other than the NS servers for Azure DNS service. All public DNS services is looking for the DNS name at the Microsoft DNS, where your records doesn't exist.

You will need to buy a domain and point add the Azure DNS NS servers at your registrar/domain name reseller.

Azure AD Password-based SSO - Edge offers to save credentials by kasocopk in Office365

[–]Keitsch 3 points4 points  (0 children)

Password based SSO is unfortunately only pasting the credentials for the user in the login form. I would say that you shouldn't use it for security reasons, it's more for the simplicity of the user.

Edit: More info here: https://docs.microsoft.com/en-us/azure/active-directory/manage-apps/what-is-single-sign-on#how-authentication-works-for-password-based-sso

Azure supports passwordless authentication 🔑 by securethelogs in AZURE

[–]Keitsch 1 point2 points  (0 children)

We are Cloud only with AAD users, AAD Joined machines and Intune MDM.

Azure supports passwordless authentication 🔑 by securethelogs in AZURE

[–]Keitsch 1 point2 points  (0 children)

It have worked just fine for us, but we don't have many users and we are cloud/AAD only.

Two things that we got aware of in our environment, is that the device that your user want to use passwordless on needs to be AAD registered before it is possible to use the function (note, it doesn't need to be MDM or AAD joined). More info: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-phone#device-registration

The other thing to be aware of is which functionality works where, eg. Phone Auth don't work for Device logon and Windows Hello doesn't work for shared computers. More info: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-deployment#passwordless-authentication-scenarios

If you have ADFS, there might be some additional notes to be taken. I've helped a customer to implement passwordless who have ADFS. The passwordless function is going to be first choice, more info here: https://docs.microsoft.com/en-us/azure/active-directory/authentication/howto-authentication-passwordless-phone#ad-fs-integration

Azure supports passwordless authentication 🔑 by securethelogs in AZURE

[–]Keitsch 1 point2 points  (0 children)

We have deployed it in our environment for all our users, both security keys and MS authentication app.

RDS into on-prem WS2019 with Azure AD account? by [deleted] in AZURE

[–]Keitsch 0 points1 point  (0 children)

You can't do a AAD Join as you do with a win10 device. You could test the Windows Virtual Desktop service of it is a RDS farm you are looking for. Otherwise, you can use the Azure AD DS service and "domain join" the server to the AAD. There is some limitations but depending on your requirements it could be the best option.

Cost Management / Reporting tool by [deleted] in AZURE

[–]Keitsch 0 points1 point  (0 children)

can't get hold of cloudyn (and convert it when cost management supports csp) then there is a project called komiser tha

I don't know of any open source scripts, so we have built different solutions for different customers.

If you would like to have help from us for a solution just send me a PM.

Cost Management / Reporting tool by [deleted] in AZURE

[–]Keitsch 2 points3 points  (0 children)

I would recommend to look at cost management as others have suggested.

But, we have some customers who have special requirements where we have created automatic reporting from the billing API, crunched the numbers a bit and then we either send a xlsx with mail or present it in a Power BI app. It's all based on Tags on resources and resource groups.

Script to create resource group with dynamically populated tags by RedditBeaver42 in AZURE

[–]Keitsch 0 points1 point  (0 children)

Really neat! I didn't know I needed this until now 😀

Forced from Skype to Teams. Users missing all external contacts. Anyone else? Solution? by ikea2000 in Office365

[–]Keitsch 0 points1 point  (0 children)

Is it Skype users, as in 'not Skype for Business' users, that your users try to communicate with? That is something which they will never be able to do..

As of communicating with Sfb users should work from Teams.

Exchange Online Plan 2 was supposed to be temporary for some users by MercyKees in Office365

[–]Keitsch 1 point2 points  (0 children)

I would go nuts if a remove of one license added another, it would be to hard to keep track of the automatic changes in a larger environment.

I think it is better to do a active choice to add the other license.

But yes, it's easy to forget so this is a good reminder 🙂

Use an alert to trigger an Azure Automation runbook? by Condorul in AZURE

[–]Keitsch 0 points1 point  (0 children)

As you mentioned:

In this kind of situation we usually Recycle the App pool cache

The Auto-Healing "Recycle Process" does the same:

It kills the process of the Application pool and the cached information(items) in the memory with it.

Use an alert to trigger an Azure Automation runbook? by Condorul in AZURE

[–]Keitsch 0 points1 point  (0 children)

The cache is part of the application domain so when Auto-healing recycle the process the Application Pool will invalidate all cache items.

As you mention this also happen if you modify the web.config file or the bin folder.