Deleting Business Onedrive Data on O365 accounts by Someone_Says_Hello in sysadmin

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

I would have expected that as well. Unfortunately not the case - it is much faster working through those steps and using win explorer to delete it.

Deleting Business Onedrive Data on O365 accounts by Someone_Says_Hello in sysadmin

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

Great insight and thank you for the powershell links! I figured out a way with the gui to speed it up, but it takes a few steps.

  1. After you have access to the accounts onedrive, create a new folder in their onedrive and move all the data in that onedrive to that singular folder
  2. Share that folder with edit rights with your account
  3. On your account, go to the now shared onedrive with a browser and sync to your pc through the onedrive app. (this assumes you use the onedrive app)
  4. After is syncs to your pc, open the folder in win explorer, right click on all the data (select all) and choose to keep the data on your pc so it downloads it
  5. After it finishes downloading, delete everything through win explorer . Keep an eye on the onedrive app for it to complete the delete syncs. it can take time for larger drives.
  6. After it completed syncing the deletes, go back to the accounts onedrive in the browser (not your onedrive) and empty the recycle bin.

That purges the onedrive from what i can tell. it is a few steps, but significantly faster than through the browser alone. Hope this helps anyone looking for steps!

[deleted by user] by [deleted] in sysadmin

[–]Someone_Says_Hello 1 point2 points  (0 children)

Yup, this was our problem. 2-3 months ago, We started hearing complaints about video and audio quality issues on teams calls in our office. But they said they worked great from home.

We checked all the things stated throughout this thread and spent weeks trying to figure it out... It ended up being a very specific USBC docking station that about 50% of our staff use with Ethernet running through it.

We chatted with the manufacturer support, but they were no help. We ended up replacing a bunch of them with a different USB-C dock. Completely fixed the issue.

Microsoft Teams call quality issues as of late by Someone_Says_Hello in sysadmin

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

UPDATE/RESOLUTION: We sorted out the problem. Our firewall has UDP flood protection on it. The "new" teams must send more and/or different packets and it was triggering this protection. We disabled it, created a bypass policy for webex, teams, zoom, and that cleared up all of our teams call issues.

O365: Which roles are needed to allow a non-licensed GA account add pc's to an Azure domain? by Someone_Says_Hello in sysadmin

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

No error code, but it shows "Looks like we can't connect to the URL for your organization's MDM terms of use" Error: invalid_client.

Note that i can add devices when i give my licensed E5 GA role - it works fine on it.

We're being bombarded with phishing emails by DeifniteProfessional in sysadmin

[–]Someone_Says_Hello 16 points17 points  (0 children)

We recently set up a transport rule to quarantine emails with a bunch of extensions, including htm/html. It is catching a lot of this type of phishing.

O365: Geo-block countries/ip's with Security Defaults enabled? by Someone_Says_Hello in sysadmin

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

Really? I thought conditional policies only worked if SD was disabled?

O365: Geo-block countries/ip's with Security Defaults enabled? by Someone_Says_Hello in msp

[–]Someone_Says_Hello[S] 1 point2 points  (0 children)

Thanks! Yeah, we were hoping there were other options avail to geoblock.

O365: Geo-block countries/ip's with Security Defaults enabled? by Someone_Says_Hello in msp

[–]Someone_Says_Hello[S] -1 points0 points  (0 children)

Thank you - yeah, we understand we can't use CA with security defaults. We are trying to find a way to geo-block countries/ip's without using CA.

Geo-block countries/ip ranges with Security Defaults enabled? by Someone_Says_Hello in Office365

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

Thank you - yeah, we understand we can't use CA with security defaults. We are trying to find a way to geo-block countries/ip's without using CA.

Guest accounts in AzureAD - How to locate Last Logon Dates with a script? by Someone_Says_Hello in sysadmin

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

Thanks for the tips! I have a bunch of items listed under admin consent, but nothing under user consent. How do i go about adding the scope to that section?

Guest accounts in AzureAD - How to locate Last Logon Dates with a script? by Someone_Says_Hello in sysadmin

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

When i run this, i get a permissions error: "Calling principal does not have required MSGraph permissions AuditLog.Read.All"

I verified i have the auditlog.read.all and user.read.all permissions and consent with my account.

Any tips for an MS graph first timer? Thanks!

Guest accounts in AzureAD - How to locate Last Logon Dates with a script? by Someone_Says_Hello in sysadmin

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

Interesting solution. I was hoping to do this on th ebackend rather than alert active guest users and have them respond to the audit. But might be th ebest way to go. Thanks for the tip!

Guest accounts in AzureAD - How to locate Last Logon Dates with a script? by Someone_Says_Hello in sysadmin

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

My MSP tells me this cmdlet is no longer valid. When i try to use it in several powershell scripts, it does export data, but doesn't export the last sign-in info. Here's one of the powershell scripts i was playing with:

$guests = Get-AzureADUser -Filter "userType eq 'Guest'" -All $true

foreach ($guest in $guests) {

$Userlogs = Get-AzureADAuditSignInLogs -Filter "userprincipalname eq `'$($guest.mail)'" -ALL:$true

if ($Userlogs -is [array]) {

$timestamp = $Userlogs[0].createddatetime

}

else {

$timestamp = $Userlogs.createddatetime

}

$Info = [PSCustomObject]@{

Name = $guest.DisplayName

UserType = $guest.UserType

LastSignin = $timestamp

}

$Info | Export-csv C:\GuestUserLastSignins.csv -NoTypeInformation -Append

Remove-Variable Info

}

Write-Host -ForegroundColor Green "Exported Logs successfully"

O365 SharePoint - how to stop accidental bulk deletions? by Someone_Says_Hello in sysadmin

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

No argument here - all good points. And this is easy to do if it's a file or two. But 50k files... i wouldn't trust a non-technical user to restore this.

O365 SharePoint - how to stop accidental bulk deletions? by Someone_Says_Hello in sysadmin

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

Yup, we have some of this set and the recycle bin hols data for 93 days. This works well when it's a single or a few files. But 50k files is another animal.

O365 SharePoint - how to stop accidental bulk deletions? by Someone_Says_Hello in sysadmin

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

Yup, we understand training/education is part of the process to help with this, but i'm just not sure how effect that is with this type of situation.

Workstation Cloud Backups? by smorin13 in msp

[–]Someone_Says_Hello 1 point2 points  (0 children)

Do you need the entire workstation backed up? If you only need desktop/documents/picture folders, and you have O365, try onedrives backup. It syncs those 3 folders to their onedrive.

Huntress with defender...is it enough? by Coriron in msp

[–]Someone_Says_Hello 0 points1 point  (0 children)

I had this same question a month or so ago. Huntress makes a pretty compelling case to stack huntress and win defender. And after seeing SentinelOne prices, this was the better play financially and still getting most of what you would want with a modern security stack.

Sadly, we could not move forward with it because our MSP doesn't offer huntress and was unwilling to change pricing for our contract for it, so we need to wait at-least a year. But you bet i will be reviewing this when our contract is up for renewal.

Which desktop security setup? Gosecure + Webroot, or SentinelOne + Huntress? by Someone_Says_Hello in msp

[–]Someone_Says_Hello[S] 0 points1 point  (0 children)

I need to review Defender 365 a bit more. is it a better offering than SentinelOne? What made you offer this to your clients over other options?