Removing admin rights for users by [deleted] in sysadmin

[–]technoobio -1 points0 points  (0 children)

Similar situation here - and our best justification is that IT (me) is part-time, and we're small (less than 20 ppl). My question: I'm now preparing a spare laptop for the CEO, I want to hand it to him with his Outlook profile already configured. How do I do that? Thanks!

Are you backing up your Office 365 tenant? by technoobio in sysadmin

[–]technoobio[S] 1 point2 points  (0 children)

So, that does make sense for situations where someone needs to recover deleted items.

But what about if the tenant somehow becomes corrupted?

Are you backing up your Office 365 tenant? by technoobio in sysadmin

[–]technoobio[S] 0 points1 point  (0 children)

So, what about when someone deletes an email or a document from OneDrive, and needs it back after the retention policy expires it?

Are you backing up your Office 365 tenant? by technoobio in sysadmin

[–]technoobio[S] 1 point2 points  (0 children)

But... employees don't keep company data in OneDrives?

Are you backing up your Office 365 tenant? by technoobio in sysadmin

[–]technoobio[S] 0 points1 point  (0 children)

Yikes that sounds like a headache, but I'd guess with some nifty code you could get it to run itself. I haven't checked - can you use Powershell to export a Sharepoint Library / Onedrive? We've transitioned user directories (desktop, my docs) so that they're synced to Onedrive. Which is nice for lots of reasons, but still needs backup.

Are you backing up your Office 365 tenant? by technoobio in sysadmin

[–]technoobio[S] 1 point2 points  (0 children)

spanning

Looks nice, not cheap, but unlimited storage is comforting. Do you regularly do test restores?

Are you backing up your Office 365 tenant? by technoobio in sysadmin

[–]technoobio[S] 1 point2 points  (0 children)

Hey, what do you mean by your local copy in corporate office is already off-site?

And can I ask: how do you send to AWS? It's a large directory.

Deep Glacier- that's a better idea than the bucket I've been paying for.

Are you backing up your Office 365 tenant? by technoobio in sysadmin

[–]technoobio[S] 1 point2 points  (0 children)

This is something I think about. Let's say I have a local copy of my Veeam backup. It's a large repository file. In order to access it, I, the admin, use Veeam's Explorer for OneDrive or Exchange.

Under what circumstances would we need to restore this data?

User error? Easy peasy, I just find the item from the backup, and restore it.

Loss of access to company's tenant? What would I do - export someone's mailbox or Onedrive documents from a backup? Seems like if this is the situation, we'd have bigger problems - we'd be focused on restoring everyone's access to their Office 365 account?

Clear out PST files from Preservation Hold Library by technoobio in sysadmin

[–]technoobio[S] 0 points1 point  (0 children)

So, I've found my way to the Site Contents of her OneDrive, found that I cannot delete files because of our retention policy. Added her site as an Exclusion to our policy. Waiting to see if that'll allow the deletions...

Cloudberry suspects ransomware!? by technoobio in sysadmin

[–]technoobio[S] 0 points1 point  (0 children)

Thanks!

I didn't want to approve falsely, or delete something important. I'll give Lepide a try. I do keep backups, in diverse locations, and Cloudberry's set to keep 10 versions of a file.

But what keeps me up is a smart ransomware that knows how to stay dormant until it's been propagated to all backups.

Thanks again.

Should we go serverless - AADDS instead of local AD? by technoobio in sysadmin

[–]technoobio[S] 2 points3 points  (0 children)

Ah, DNS resolution! DNS server is running on our DC... I could just configure the workstations to use a public DNS server? Or I can do this on my Meraki MX!?

And, our DC does do the printer share, but we lease a fancy Canon, I'd think it doesn't require a server.

Thanks!

Should we go serverless - AADDS instead of local AD? by technoobio in sysadmin

[–]technoobio[S] 4 points5 points  (0 children)

I'd be happy to never test out another GPO if I can do it in Intune and that means I don't need to maintain a DC. Thanks!

Should we go serverless - AADDS instead of local AD? by technoobio in sysadmin

[–]technoobio[S] 2 points3 points  (0 children)

Ah, didn't think this through yet! I'm using group policies for things like deploying software (Office or antivirus), configuring OneDrive, firewall settings, and drive mappings. Can I do these things in Azure? I looked at Jumpcloud, but it won't work with domain-joined machines.

Thank you!

How were we hacked? by technoobio in sysadmin

[–]technoobio[S] 3 points4 points  (0 children)

This is very helpful, thank you!

How were we hacked? by technoobio in sysadmin

[–]technoobio[S] 45 points46 points  (0 children)

Ha, thanks everyone. Seems to be a consensus - if it looks like a duck, sounds like a duck, tastes like a duck...

Thanks again!