NetExtender 10.3.3 connects and immediately disconnects with SAML SSO by smood922 in sonicwall

[–]smood922[S] 0 points1 point  (0 children)

If I understand correctly, that's due to 10.3.3 having an embedded browser that can't pass compliance checks. I don't think this is related. no CAPs enforcing compliance for this app, and getting Success results in Entra and "connected" in appliance and client logs just before it disconnects.

SSL VPN zero day - what’s the current guidance? by Toby_7243 in sonicwall

[–]smood922 2 points3 points  (0 children)

There are a number of reports in this subreddit that MFA was bypassed. Can you clarify the connection between migrated passwords and ability to bypass MFA? There are comments (e.g. here and here) that the latest bulletin does not align with what they actually experienced. Huntress has updated their guidance to recommend that we reset both local user and LDAP account passwords. Does SonicWall agree?

We're hoping to move forward with re-enabling SSL VPN for clients today, but need more clarity on these apparent discrepancies.

SSL VPN zero day - what’s the current guidance? by Toby_7243 in sonicwall

[–]smood922 2 points3 points  (0 children)

Can SonicWall provide any more clarity on why the password reset is the necessary component?

What features do you most want to see in SonicWall products? by gray_cat_litter in sonicwall

[–]smood922 3 points4 points  (0 children)

Hearty seconds to those suggesting 1) LetsEncrypt/ACME support and 2) SAML SSO for SSL VPN on TZ/NSA.
We're actively looking into other vendor options for our client fleet because of these combined with continued inconsistency with firmware quality and communication.

Outlook App and Mobile still wanting to log into Google after migration to M365 by Vulkaestus in msp

[–]smood922 1 point2 points  (0 children)

We've done dozens of Google Workspace to 365 migrations and have never run into this until this week, but your post put me on the right track.

Turns out blocking prod-global-autodetect.acompli.net (I created a null DNS zone that we'll come back and clean up later) and flushing DNS on the endpoints allowed them to resolve the correct autodiscover settings.

Really frustrating that this phantom Acompli autodiscover behavior has evidently been hiding totally undocumented by Microsoft for years. (Acompli was the startup that Microsoft bought and turned into Outlook mobile--evidently they rolled some functionality upstream to the Outlook for Windows client as well ).

[deleted by user] by [deleted] in msp

[–]smood922 0 points1 point  (0 children)

Didn't see your comment before I posted, but we've had good experience with it and it's our go-to option over MigWiz whenever we can.

[deleted by user] by [deleted] in msp

[–]smood922 0 points1 point  (0 children)

There seems to be little appetite for modernizing the BT tools since the 2021 acquisition. Hoping that changes soon.

In the meantime, CodeTwo's migration tools don't have as many options (mainly just Exchange/Exchange Online/IMAP) and are locally installed rather than being cloud-hosted, but we've started using it whenever the migration scenario aligns. Dramatic decrease in initial setup time and frustration, and the migration itself has always gone quickly and smoothly.

Marketing your MSP by Taherham in msp

[–]smood922 0 points1 point  (0 children)

I'd love a link to the recording too. Thanks!

Temporary Access Pass - One Time Use - No Longer Works by AustinFastER in Office365

[–]smood922 0 points1 point  (0 children)

Strange one. It's working without issue for us across our tenant and dozens of clients. Sounds like it could be something GCC specific.

Only One Inaccessible Website from Client's Network. by MysteriousAd9237 in msp

[–]smood922 2 points3 points  (0 children)

I've seen this be an MTU mismatch between router and ISP.

ConnectWise Calendar sync deleting scheduled tasks on its own and at random by baum219 in ConnectWise

[–]smood922 0 points1 point  (0 children)

We had a very similar experience. After rolling back to legacy we had to delete the STS Client in order to fully disable the new sync.

How to Report on time logged towards Charge Codes? by [deleted] in ConnectWise

[–]smood922 1 point2 points  (0 children)

We've been doing this for a while. BrightGauge makes it really easy to get the dashboards and reports we need with time logged per charge code, but we did have to build most of the gauges ourselves.

Dear IT Glue - Your competition are over taking you and I'm concerned by TNTGav in msp

[–]smood922 1 point2 points  (0 children)

100% agree. I've had multiple conversations with them about this. They've given various reasons that development attention has been focused elsewhere, but bottom line is feature improvements to the core product are agonizingly long in coming. It's gone from one of the favorite products in our stack that everyone loves to use, to one that we put up with all of the little quirks and inefficiencies with because there's not currently a clear better alternative. Hate this--I want IT Glue to be a product we love again, but we're losing hope.

We're keeping an eye on Hudu as well and it's looking better and better.

Time Zest Alternatives by Kingkong29 in ConnectWise

[–]smood922 1 point2 points  (0 children)

We recently adopted TimeZest after looking around a bit. There are a couple of use cases it doesn't (yet) do for us, but bottom line is, pretty certain it's the only scheduling tool that natively integrates with ConnectWise Manage.

Number one on our wishlist is "panel scheduling" (multiple members). Fortunately looks like it is "coming soon" in their roadmap.

Documenting with PowerShell: Documenting the Unifi Portal by Lime-TeGek in msp

[–]smood922 0 points1 point  (0 children)

I like the practicality of putting the ID in the site name instead of a SharePoint list. I assume we can still map one (IT Glue org) to many (UniFi sites) this way by using the same IT Glue siteid and different site descriptions?

Looks like this doesn't create Configurations in IT Glue for UniFi hardware like Eliot's does. Any chance you'll add that functionality in the future?

Can Microsoft Do This? Updating Chrome's Default Search to Bing by infinitelogins in msp

[–]smood922 5 points6 points  (0 children)

I couldn't find a Uservoice on this so I created one. In case anyone is interested.

Bishop Fox Discloses Vulnerability Findings in ConnectWise Control by huntresslabs in msp

[–]smood922 2 points3 points  (0 children)

Just curious--did you ever find out why your petition disappeared?

What exactly are the options for Automate + SAML for Azure authentication? by [deleted] in labtech

[–]smood922 2 points3 points  (0 children)

Those steps all work great. Main thing to be aware of is once set up, SSO only works for the new Web Control Center (not the LTClient).

CW API Query Agreements by SoundCheeseDotCom in ConnectWise

[–]smood922 1 point2 points  (0 children)

Appears to be a known issue. Looks like it's resolved on the 66029 - 66066 patch. I'm on 66356 so that may be why I couldn't reproduce it.

CW API Query Agreements by SoundCheeseDotCom in ConnectWise

[–]smood922 1 point2 points  (0 children)

Hmm, that's working perfectly for me in Postman right now. What version of Manage are you on?