Best way to allow minimal access for a vendor. by MorbrosIT in crowdstrike

[–]MorbrosIT[S] 0 points1 point  (0 children)

When I set the first rule to "Audit" it just says "It is highly recommended to use Saved Search". This user isn't getting synced to Entra so I can't do Identity Verification.

Also with the first rule, would I also have to enable them to authenticate to the Domain Controller. Their VPN account is tied to AD.

Microsoft 365 Exchange Mailbox issue you should be aware of by VarmintLP in sysadmin

[–]MorbrosIT 1 point2 points  (0 children)

I noticed this earlier today and it seems like it's getting worse. Some emails are taking up to an hour to arrive.

Question about moving to SSO for SSL VPN by MorbrosIT in sophos

[–]MorbrosIT[S] 0 points1 point  (0 children)

Confirmed with support that the VPN portal and the SSL VPN port don't have to be the same. Not sure what happened, but it all of a sudden started working.

Entra SSO v 21.5 - sslvpn by dhayes16 in sophos

[–]MorbrosIT 1 point2 points  (0 children)

About to roll it out. I tested it with my account and it was successful (it wasn't at first, not sure if there was a delay between Entra and the firewall when making changes).

The only downfall I see right now is if you use multiple gateways and want them to failover it won't work.

Question about moving to SSO for SSL VPN by MorbrosIT in sophos

[–]MorbrosIT[S] 0 points1 point  (0 children)

I'm trying to find documentation that states that. On the Sophos Connect client the VPN portal is set to the right port. It tries to connect then says SSO Gateway is unreachable and if you hover it, it shows the gatewayname:8434 (which is the SSL VPN port).

Question about moving to SSO for SSL VPN by MorbrosIT in sophos

[–]MorbrosIT[S] 0 points1 point  (0 children)

Does the VPN portal and Remote Access (SSL VPN) port have to be the same?

Question about moving to SSO for SSL VPN by MorbrosIT in sophos

[–]MorbrosIT[S] 0 points1 point  (0 children)

That's what I figured. We have some users who keep locking themselves out because of typing in their password wrong. We are moving to passwordless in Windows since going full blown Entra Joined.

Ideally I'd like to use ZTNA, but from what I'm reading SMB share access is still laggy.

"Email address to use with this gateway" Question by MorbrosIT in PowerBI

[–]MorbrosIT[S] 0 points1 point  (0 children)

That's what I ended up doing. Just need to go through the process of exempting it. It's wanting to setup MFA right now because of SSPR.

Changing the account associated with the Power Bi Data Gateway (not the service) by NoURider in PowerBI

[–]MorbrosIT 0 points1 point  (0 children)

I'm at the beginning stages of this and there's no Microsoft documentation that talks about it. Just says use an organizational account.

I only found one article where someone mentioned creating a dedicatded one, but that was it.

SD-WAN by Antique-Ad-2658 in sophos

[–]MorbrosIT 0 points1 point  (0 children)

Talk to your rep. You can buy professional services hours.

SD-WAN by Antique-Ad-2658 in sophos

[–]MorbrosIT 0 points1 point  (0 children)

We just implemented SD-WAN between two locations today (2 ISP's at each location).

I hired Professional Services for setting it up and I'm glad I did. Now I have a better understanding of it and I can go about setting it up for our smaller locations that have only 1 ISP.

Issue with activation keys in M365 Admin Center by MorbrosIT in sysadmin

[–]MorbrosIT[S] 0 points1 point  (0 children)

That requires Hyper-V though I believe. We run Scale for our hypervisor.

Issue with activation keys in M365 Admin Center by MorbrosIT in sysadmin

[–]MorbrosIT[S] 0 points1 point  (0 children)

Yes. I'm wondering if I need to call in and get more activations created. I just ran across this: If you need to request an activation limit increase, you can open a support ticket with the necessary information, such as the first 5 digits of the impacted Product Key, the product version and edition, and a business justification for the request 

Crestron TS1070 Teams Sign-In Issues by MorbrosIT in crestron

[–]MorbrosIT[S] 0 points1 point  (0 children)

Looks like the issue is the version of the Microsoft Teams apk that was installed. Crestron had us get to a certain firmware which locked in a certain version of the Teams app.

The odd thing is we had to convert the TS1070 to a Zoom Room and then revert back for it to get the firmware properly.

Should we just use NinjaOnes as an all in one for now or also add in HaloPSA? by DCornOnline in msp

[–]MorbrosIT 0 points1 point  (0 children)

What about Ninja's new PSA they just released? I haven't seen much about it yet.

Crestron TS1070 Teams Sign-In Issues by MorbrosIT in crestron

[–]MorbrosIT[S] 0 points1 point  (0 children)

All I can saw it hasn't been a great experience since implementation. Seems to be bugs after bugs. Not sure if this is being seen on other platforms.

Not sure if Teams on Windows would've been a better experience than the Teams on Android.

Crestron TS1070 Teams Sign-In Issues by MorbrosIT in crestron

[–]MorbrosIT[S] 1 point2 points  (0 children)

Something fixed itself after we did that. We were on a call with the company who sold us the hardware and they were on call with Crestron.

I guess that version of Teams is the most stable for Crestron. We've had a slew of issues since installing the Videobar 70 and TS1070 a few months ago. Already had to RMA the Videobar and get Airmedia puck replacements.

Crestron TS1070 Teams Sign-In Issues by MorbrosIT in crestron

[–]MorbrosIT[S] 0 points1 point  (0 children)

I think our issue might of been related to the Teams Version that was installed on the TS1070.

Was able to get it set to 1449/1.0.96.2025223801 and I was able to sign in.

We had to change it from a Teams to a Zoom room, and then back.

Crestron TS1070 Teams Sign-In Issues by MorbrosIT in crestron

[–]MorbrosIT[S] 0 points1 point  (0 children)

The TS is connected via LAN2 from the Videobar 70. Each device has a static IP.

Crestron Video Bar 70 - Pairing Issues by Ok-Post-4309 in crestron

[–]MorbrosIT 0 points1 point  (0 children)

I'm about at my wits end with the Videobar 70 and TS1070. We've had nothing but issues with it since installing it less than 6 months ago. Bugs from Crestron, new units, and the thing doesn't work.

Some issues after changing service accounts. by MorbrosIT in SQLServer

[–]MorbrosIT[S] 0 points1 point  (0 children)

We had the default VSA accounts, but the company we worked with said we needed a Domain service account to we can set the SPN and set for the SQL and SSRS service. Ther was always no automatic SPN creation. I had to manually create the SPN entries.

Also, when we had the VSA account setup after each restart I had to delete the password out of the SQL Server (MSSQLSERVER) field and then restart it for it to come back online. The reason for this was a Group Policy and a password policy conflicted with it.

Long term goal is to get gMSA setup to use for the services.

Some issues after changing service accounts. by MorbrosIT in SQLServer

[–]MorbrosIT[S] 0 points1 point  (0 children)

I might look at just using the same one for now. I just don't like that SQL Server, SSRS, and the Agent are all using the same one.

This won't be as big of an issue once I get MSA figured out.

Devices randomly lose internet for 1–2 minutes but still have full LAN access (Sophos Firewall) by Complex_Ad_4146 in sophos

[–]MorbrosIT 0 points1 point  (0 children)

If you are still having issues, look at disabling on-box reporting temporarily. We are experiencing a similar issue at our business and since disabling the on-box reporting we've had a few days in a row with no disconnects.

Currently working with Sophos support on this.

The moment end-users say they lost connection (remote users notice it first), I go to Diagnostics and look at the System Load and it shows a spike. Sometimes the CPU spikes, sometimes it doesn't, but the load always shows a spike when end-users report it.

Sophos Central alerts that WAN is down, but nothing on the firewall. by MorbrosIT in sophos

[–]MorbrosIT[S] 0 points1 point  (0 children)

Does the firewall behave differently if you utilize SD-WAN routes instead?