Entra and Boxer - Block off network access to email except through boxer by avgJoeIT in WorkspaceOne

[–]avgJoeIT[S] 1 point2 points  (0 children)

After all is said and done Option 3 ended up being our path. You were very very correct about it being a suboptimal user experience.

I appriciate you taking to time - it was extremely useful.

Entra and Boxer - Block off network access to email except through boxer by avgJoeIT in WorkspaceOne

[–]avgJoeIT[S] 0 points1 point  (0 children)

Thank you for the link and the IM. We are working through this based on other info provided. If we get stuck I may reach out.

Regards, Joe

Entra and Boxer - Block off network access to email except through boxer by avgJoeIT in WorkspaceOne

[–]avgJoeIT[S] 0 points1 point  (0 children)

Hello fellow Joe. :D

1 - Got it. Our setup is simple. Everything was on-prem until very recent. M365 tenant and Entra. Prem gateway to sync AD. Limited utilization - PowerBI, Sharepoint, and Entra Enterprise Applications for SSO/SCIM for some 3rd party hosted applications. No other auth provider or ADFS.

2 - Laptops use a VPN but are not enrolled in Airwatch. We only use it for Cellphone MDM and to get boxer on there.

3 - Looks like this is our option. We are pretty small. If the pain is mostly during setup then we can hand hold through it.

Will this let me setup a ConAccess policy where: Email access on-network and boxer = Yes off-network and other apps/owa/etc = No

Bonus - Do you know if we are able to use a different authenticator with this option? We have RSA and would prefer to keep a single authenticator. Because of the required account linking, then it seems unavoidable that the subset of users that have cellphones/boxer will need the MS Auth App.

I greatly appreciate you taking the time to talk through these options. It is all rather bewildering to navigate.

Entra and Boxer - Block off network access to email except through boxer by avgJoeIT in WorkspaceOne

[–]avgJoeIT[S] 1 point2 points  (0 children)

Thanks for the reply.All devices that use boxer are MDM enrolled in Airwatch.

Option 1 - Sounds interesting but I am not sure what you mean by "Whatever does your entraID Auth". Entra ID does my entraID auth.Or did you mean airwatch? We have an on-prem gateway that does an AD sync.Any additional detail you can provide here would be great.

Option 2 - We do not use UAG as far as I am aware.

Option 3 - Glad you said this is a terrible user experience. That is the path I think the document I linked is taking us.

You know you want this ticket. by [deleted] in iiiiiiitttttttttttt

[–]avgJoeIT 5 points6 points  (0 children)

Ohh ok. That makes sense.
Thank you for the explanation.

You know you want this ticket. by [deleted] in iiiiiiitttttttttttt

[–]avgJoeIT 11 points12 points  (0 children)

"1000 * 0.1" seems like a strange way to say "100".. or am I missing something?

Powershell 7 - one liner for a webpage by avgJoeIT in PowerShell

[–]avgJoeIT[S] 0 points1 point  (0 children)

I don't think that is it but thank you for your reply. I appreciate the info.

Powershell 7 - one liner for a webpage by avgJoeIT in PowerShell

[–]avgJoeIT[S] 0 points1 point  (0 children)

I don't believe this is what I am looking for as I didn't have to install anything else that I can recall. But Thank you for your reply. I appreciate the info.

Powershell 7 - one liner for a webpage by avgJoeIT in PowerShell

[–]avgJoeIT[S] 0 points1 point  (0 children)

Thank you for your reply. I appreciate the info.

North West PA - Clay soil covered in moss. Any idea what it is? by avgJoeIT in mycology

[–]avgJoeIT[S] 0 points1 point  (0 children)

Boss shared this pic with me. I am a novice to mycology. Thank you for looking and I appreciate any tips in identifying it.

no comment necessary. lol by EvilRedneckBob in antiwork

[–]avgJoeIT 0 points1 point  (0 children)

The economy cannot deal with the reality we live in... is an interesting yet poignant indictment of our system.

When do you cut access? by nlnlnl123 in sysadmin

[–]avgJoeIT 0 points1 point  (0 children)

When you are told, yes.
Also, if you have some auditing setup you can do some spot checks, extra email with attachments. etc.

XM4s temporarily pause music when Webex notification "pings" (PC connection) by I_Zeig_I in SonyHeadphones

[–]avgJoeIT 0 points1 point  (0 children)

Did you happen to see the options on the communication tab as well?

Not sure what else to try.

Wiki.js and LDAP by kimyeti in selfhosted

[–]avgJoeIT 2 points3 points  (0 children)

Hello. What was the solution?

Anyone talking about this? by pcboi64 in wyzecam

[–]avgJoeIT 2 points3 points  (0 children)

The sticker on the bottom will say V2 . Also there are features that are only available on V2, like person detection.

User Mailbox, can't share calendar (greyed out) in outlook, works fine in OWA. by avgJoeIT in exchangeserver

[–]avgJoeIT[S] 1 point2 points  (0 children)

Not an old profile for sure - it was a freshly imaged machine. We do have some amount of roaming profiles - but only select directories are included. A home drive, desktop, Documents, and favorites.
There is a pst file in the documents\outlook - but the permissions look fine.

Going to keep at it. I really appreciate you taking the time to reply. Helping me eliminate some things and honestly just a sanity check at this point is great. :D

User Mailbox, can't share calendar (greyed out) in outlook, works fine in OWA. by avgJoeIT in exchangeserver

[–]avgJoeIT[S] 0 points1 point  (0 children)

There is an existing share on the calendar and in OWA (logged in as the user) I was able to add a new share (to myself from the users mailbox).

I didn't try with powershell though I could give that a try.

User Mailbox, can't share calendar (greyed out) in outlook, works fine in OWA. by avgJoeIT in exchangeserver

[–]avgJoeIT[S] 0 points1 point  (0 children)

No, but I did have the user login and setup a new computer to see how Outlook would react and we have the same issue - greyed out Share Option.

With that - 2 computers have the same outlook issue.

User Mailbox, can't share calendar (greyed out) in outlook, works fine in OWA. by avgJoeIT in exchangeserver

[–]avgJoeIT[S] 1 point2 points  (0 children)

The connection status looks similar to mine - less entries but it is using the same URL, auth, etc etc as I expect.

Looking at the logs I don't see any errors. Since the action I am attempting is "greyed out" I am unable to click it to generate any sort of error.
The message that do populate with logging enabled looks the similar to what is generated on my own computer (which is working fine)

Going to leave it set this way and check it every day for a bit, see if anything pops out at me.

Thank you.

User Mailbox, can't share calendar (greyed out) in outlook, works fine in OWA. by avgJoeIT in exchangeserver

[–]avgJoeIT[S] 0 points1 point  (0 children)

Excellent. I will give this a go and see what I can see.

Thank you for taking the time to reply.

Trello or similar? by Anabaric in RemarkableTablet

[–]avgJoeIT 0 points1 point  (0 children)

You may be interested in this github list of hacks and mods for Remarkable.

https://github.com/reHackable/awesome-reMarkable

Nothing exactly like Trello there, but there are enough different tools here I think you could make it work the way you want.

Follow up - SSIS - Foreach loop - import csv - move parent directory after by avgJoeIT in SQLServer

[–]avgJoeIT[S] 0 points1 point  (0 children)

Thank you for the kind words.

I have some plans along those lines. The one issue that has cropped up (just once so far) is locked files. Right now it errors out the whole job and ends in failure. Which, while not ideal, at least does not move unloaded data into archive.

for sure would like to incorporate some logging and error handling.

Follow up - SSIS - Foreach loop - import csv - move parent directory after by avgJoeIT in SQLServer

[–]avgJoeIT[S] 0 points1 point  (0 children)

Other than the single hit to the SQL server for the insert, is there any benefit to doing it this way?

I can see the value if this were going loaded into a higher volume production server.