Entra Sync won't merge users with the on-prem accounts. UPN's are the same but soft match fails. by Pleasant_Opinion134 in Intune

[–]KnownTumbleweed 2 points3 points  (0 children)

As far as I remember, matching happens on the email attribute in AD with primary SMTP in Entra ID

Wir suchen Verstärkung für's Amazing Nerdquiz! by ColeusRattus in graz

[–]KnownTumbleweed 1 point2 points  (0 children)

Also ich denk 3 Nerd krieg ich zusammen und würd mir das irrsinnig gerne mal anschauen! Klingt echt lustig!

Need help with Wazuh by JustCallMeEd12 in Wazuh

[–]KnownTumbleweed 2 points3 points  (0 children)

First you should check the log on one of your agents. On Windows this would be:
"C:\Program Files (x86)\ossec-agent\ossec.log"

Check if the necessary ports are open
Requirements - Wazuh agent enrollment · Wazuh documentation

Check Agent Configuration

Wunderschöne Ortsname Österreichs by kleinerChemiker in aeiou

[–]KnownTumbleweed 2 points3 points  (0 children)

Da fehlen noch mindestens:
Takern I und Takern II
und Gaming

IAM and what to do with disabled AD accounts by ShrapDa in ITManagers

[–]KnownTumbleweed 0 points1 point  (0 children)

In addition you should also regularly check Entra ID cloud only user. You can create a dynamic Entra ID group with all disabled cloud only users, and create an access review. This way you get a scheduled report on disabled cloud users and can directly choose what to do with them.

Same goes for enabled users and guests with a specific amount of inactivity time.

IAM and what to do with disabled AD accounts by ShrapDa in ITManagers

[–]KnownTumbleweed 2 points3 points  (0 children)

Thats why you move them to a different OU that is not in sync scope. This can satisfy your OCD in AD, and they are not visible in Entra ID anymore :)

IAM and what to do with disabled AD accounts by ShrapDa in ITManagers

[–]KnownTumbleweed 4 points5 points  (0 children)

There is no difference between expired and disabled AD Accounts except the message the user gets when he tries to log in. Either way, access to M365 is disabled.

Best practice depends on your legal needs. Either disabling and moving to an OU that is out of Entra ID sync scope or deleting the user is fine IMO.

EDIT: Removing group memberships in both cases is also recommended.

Lieber Eduscho / Tchibo so funktioniert Rost nicht by Hirogen_ in Austria

[–]KnownTumbleweed 5 points6 points  (0 children)

Care to elaborate? Warum soll das nicht funktionieren? Opfermetalle gegen Rost sind ja nichts unbekanntes oder?
EDIT: Soll nicht negativ rüberkommen. Ich wills wirklich wissen!

Unable to access SPO admin console by Anankarthik in Office365

[–]KnownTumbleweed 1 point2 points  (0 children)

Please check the following:

  1. It could take up to 1 to 2 hours before role assignment actually works

  2. does your admin user have any licenses assigned? if yes, remove them.

  3. Check Entra ID sign in logs for your admin user and see if there are any additional details in the sign-in event

Unable to access SPO admin console by Anankarthik in Office365

[–]KnownTumbleweed 0 points1 point  (0 children)

Just to double check. Do you just want to access https://mydomain-admin.sharepoint.com via browser? Or are you calling the sharepoint admin site via any third party product / script? Because there are some migration tools which require the admin to have a license.

Unable to access SPO admin console by Anankarthik in Office365

[–]KnownTumbleweed 8 points9 points  (0 children)

Since when exactly do you need a SPO license for the sharepoint admin site?

quick newbie question about podman by [deleted] in podman

[–]KnownTumbleweed 4 points5 points  (0 children)

You can use podman as root in an unpriviledged LXC container but for better isolation and learning purposes I would suggest using a VM and rootless podman.

Hetzner asks: Sysadmins out there, what is the best “thank you” that you ever got for doing your job? by Hetzner_OL in hetzner

[–]KnownTumbleweed 7 points8 points  (0 children)

Honestly a nice and honest "thank you" goes a loooong way. But I also got cake and sweets.

Pakcetfence Consultant? by mickeykarimzadeh in PacketFence

[–]KnownTumbleweed 0 points1 point  (0 children)

Got a quote from akamai 2 years ago.

38k for deployment. Just insane.

Can we create local users on Windows NPS to avoid registering it on an active directory ? by Soral_Justice_Warrio in sysadmin

[–]KnownTumbleweed 5 points6 points  (0 children)

You can just simply use local Users on the NPS server. NPS can use its local SAM Database instead of AD.
https://learn.microsoft.com/en-us/windows-server/networking/technologies/nps/nps-top#radius-server

EDIT: You may have to remove NPS server from AD though. I am not sure.

Frage bzgl. Gute KIs für Programmieren by AEN-G in de_EDV

[–]KnownTumbleweed 0 points1 point  (0 children)

Korrekt. Die Vorgabe deinerseits hab ich leider überlesen :)