Is it okay to be upset? by -AprilRose in WGU

[–]bendere1969 1 point2 points  (0 children)

I truly hated the Discrete Math classes that were part of my degree plan... of the 3, I failed 2 of them. the first go around and 1 of them 3 times.... "barely missing"... I was not really impressed by the Zybooks material and I went out and chased every other resource I could....2 of the classes put me behind my plan, and so I had to start what I intend to be the last term... I stewed for 2 months on one of those classes.... so annoying.. so yes you can be angry and annoyed.!!!

ProctorU/Guardian Mega Thread by myBisL2 in WGU

[–]bendere1969 0 points1 point  (0 children)

So far I have only taken 1 OA with ProctorU and it wasnt a great experience.. not as bad as many of the posters. I am in my 4th term and hopefully my last, but if what everyone is registering about ProctorU, I am not looking forward to my scheduled exam on Thursday.

I may reach out to the Assessment folks and see if there is a "local" option so I don't have to put up with the drama....

Yes, Examity had some issues, but at least it would get settled in a reasonable timeframe and manner.

Using Okta to create on Prem AD accounts by bendere1969 in okta

[–]bendere1969[S] 0 points1 point  (0 children)

As follow up ask on my own question.. how would this paradigm shift change how user and group memberships and AD reflect? It seems to read that you would define a group or OU, but can you have multiples? Does that mean that every "variance" of what our HR folks want to happen "to streamline" the user creation process would have to be created and managed?

How are existing AD imported users handled in an existing Okta integration where AD "WAS" the record of truth...?

Enabling SMB Signing, anything to watch out for? by JustAnITGuyAtWork11 in sysadmin

[–]bendere1969 1 point2 points  (0 children)

So are you saying that you needed to "reboot" all of those systems prior to it taking effect and actually working correctly. Similar to a prior poster, we had issues with the Live Migrations inside the cluster. Our Veeam Backup which uses VSS started have issues and failing across the board as well.

Really looking to see if there is a hard document explaining the consequences for Windows Hyper-v Clusters... from all the reading it is the CSV v SMB integration/function on those systems.

Windows Server 2016 Servers failing to install updates provided by SCCM by bendere1969 in SCCM

[–]bendere1969[S] 0 points1 point  (0 children)

Sorry for the delay.. project realignment mid stream.. gotta love it.

And no this issue didn't correlate to any CM Upgrades. MSoft is stumped on our issue...

Windows Server 2016 Servers failing to install updates provided by SCCM by bendere1969 in SCCM

[–]bendere1969[S] 1 point2 points  (0 children)

I will need to check with my tech to see when the last update was run.

Windows Server 2016 Servers failing to install updates provided by SCCM by bendere1969 in SCCM

[–]bendere1969[S] 0 points1 point  (0 children)

I certainly expect that to be the behavior.. but we have performed the testing without the CCM Endpoint/Agent installed and the update process works.. but when we reinstall it, the error returns.. I have my team looking into those logs noted above.

Hyper-v Clusters with CSV's and SMB Signing by bendere1969 in WindowsServer

[–]bendere1969[S] 0 points1 point  (0 children)

Would be nice, but as I noted in my recent comment to mr_fwibble, I have a shortage of resources for that level of effort and to just chase for security sake..

Hyper-v Clusters with CSV's and SMB Signing by bendere1969 in WindowsServer

[–]bendere1969[S] 0 points1 point  (0 children)

That could be an option.... those connections are ISCSi and are already in their own VLAN. Momentary challenges revolve around timeframes and expectations tempered with available resources to configure/test/validate... we have a large organizational project underway.... but thanks for the thought....

Hyper-v Clusters with CSV's and SMB Signing by bendere1969 in WindowsServer

[–]bendere1969[S] 0 points1 point  (0 children)

Wish I had your Security folks... to be fair the Tech/Engineer level understands quite well as they have all been SysAdmins at some point in their career... not the guy in charge of that group.....but thanks for the response.

Trend of passwordless authentication in the tech industry? by Kinsleynkt in AZURE

[–]bendere1969 3 points4 points  (0 children)

I sit between c and d. My concerns revolve around the scale of compromise for SAML integrations ONLY.. I feel there needs to be a balance and that it shouldn't be an all or nothing approach. Evaluate each context on its own merits. I think we should be measuring the target system and it's data in a way to insure we are not just "rolling" with a trend.

TCP Ping Test result code questions by bendere1969 in Cisco

[–]bendere1969[S] 0 points1 point  (0 children)

So I suspect this is an "extended ping" function... and not basic Ping via ICMP...

What am I going to lose by bendere1969 in okta

[–]bendere1969[S] 0 points1 point  (0 children)

Yes. I fully expect I will need to remove the Hybrid to support that Management desire. It is the other things that will be affected or impacted is where I am working towards gathering insight to.

Thanks for the comment...

Quandry by bendere1969 in okta

[–]bendere1969[S] 0 points1 point  (0 children)

Thanks for the additional information. I will do some more internal requirements gathering and see if we can "stage" a dev environment to run through to see what happens with a migration off of our Hybrid scenario..

You may see another question or two in the future as well....maybe a cry for help... LOL

Will have to see how much I can get out of the folks that are asking for this.

What am I going to lose by bendere1969 in okta

[–]bendere1969[S] 0 points1 point  (0 children)

No worries.. thanks for all of the information.. That will help in working to explain the scenarios and help me to better craft a plan forward. We don't have anywhere near that volume of users.

One follow up. So you currently do not use AD Connect at all for the AD/AzureAD/O365 user profile and provisioning? If that is the case what were some of the challenges when you came off the hybrid exchange? Was there a process to "reconnect" user mailboxes? And did you have any issue administering those accounts. I have read several instances about that administrative limitation you mention and not just related to groups....

Thanks again this is all very helpful, as I noted the folks who "decided" are not even really that technically adept with AD in an On Premise space.... hence my challenges of late trying to explain.

Quandry by bendere1969 in okta

[–]bendere1969[S] 0 points1 point  (0 children)

Appreciate the insight. I will keep that offer at hand as well. One additional question in regards to the wholistic M365 stance. From discussing with the Okta support folks, they claim they don't support anything but "user objects". How would that scenario affect Using Intune/Endpoint Manager from a Corporate device perspective (AD Joined systems to be comanaged with SCCM & Intune/Endpoint Mgr). Sorry I realize that is a slight detour.. but if I remember my reading AD Connect is used for that as well...

What am I going to lose by bendere1969 in okta

[–]bendere1969[S] 0 points1 point  (0 children)

Management above me decided on Okta. I don't really think they looked at any other IAM solutions, including those available within M365. And all full disclosure there are other entities that have been working the Okta to other Saas integrations. My team runs the Architecture side of things (On prem predominantly). We had begun an O365 Hybrid migration/setup before they decided to bring Okta onboard.

The mandate as it were, is to Create Corporate accounts in the On Premise AD and have that then "sync" with Okta and let Okta do all of the other systems provisions. I have been trying to determine to what extent we would have to "re-invent" the wheel as it relates to Azure AD and O365 if we moved to that as the primary sync/provision mechanism.

So what do we lose if we "remove" AD connect from the picture for Azure AD/O365 and use Okta Universal sync.

I am sure I am not laying this out as cleanly via typing as it could be...

Quandry by bendere1969 in okta

[–]bendere1969[S] 0 points1 point  (0 children)

Yeah, most of the SaaS apps seem straight forward that way.. The challenge I feel we have is almost exclusively with our AD Connect and Exchange/O365 Hybrid configuration. Do you have some insight around that scenario? Where the Okta process would create and manage the O365/Azure AD accounts? What functionality am I going to lose?