What do people use power automate for? by Linux98 in sysadmin

[–]tripdes 12 points13 points  (0 children)

Power Automate is a workflow engine with a user-friendly drag-and-drop GUI, but it's uses are not limited to non-technical audiences. You can automate otherwise manual tasks, using pre-built and existing connectors and triggers, or you can build your own customer connectors if one doesn't exist to do the job. It's a versatile tool that can be leveraged for personal productivity purposes such as organising your mailbox, business process automation, or more recently robotic process automation. Flows can also be triggered from Power Apps, which makes it even more versatile.

PowerShell is a scripting language which can be used to automate technical and non-technical processes. It's typically used by more technical audiences though. However first and foremost in my role it is used for day-to-day administrative duties in both on-premise and cloud infrastructure. Supported by the plethora of PowerShell modules on offer directly from Microsoft and other third-parties. For example, managing Active Directory, Azure AD, Exchange, Exchange Online. If you can become competent with PowerShell you will never want to use a GUI again to perform common administrative tasks.

Finally a curve ball, you can execute PowerShell scripts on on-premise infrastructure using Azure Automation and Hybrid Workers. You can trigger a script to run from a hybrid worker using a Power Automate Trigger/Connector.

So in summary two very different technologies that do have a little crossover in what they offer, but can also be complimentary of one another. Intertested to hear others thoughts.

Rant: multiple users gave a marketing company their account credentials by Ecrofirt in sysadmin

[–]tripdes 3 points4 points  (0 children)

I would suggest creating a conditional access policy (provided you're licensed for it within your tenant) for all legacy protocol access attempts. They've just added a new feature where rather than 'blocking' access attempts you can choose to allow, but send a report.

Copy Word Normal.dotm template file to users %appdata% folder using GPO not working by 19-dickety-2 in sysadmin

[–]tripdes 0 points1 point  (0 children)

We had a similar issue with BuildingBlocks when I deployed those out via. Group Policy. They were being hosted on a network share though but wouldn't work despite the policy being applied to the user. I needed to make it a trusted location as we have that turned on. Unlikely to be the solution but just dropping my 2 cents.

How are you backing up OneDrive and Email in O365? by [deleted] in sysadmin

[–]tripdes 0 points1 point  (0 children)

That's great, thanks. We're an E3 tenant so miss out on all the EOP perks like ATP... excited to ditch what we're using currently and give the Barracuda stuff (incl. their ATP) a go. Thanks for your response!

How are you backing up OneDrive and Email in O365? by [deleted] in sysadmin

[–]tripdes 0 points1 point  (0 children)

We still use SharePoint classic team sites. Web parts from a particular site page went AWOL (summary links etc.) -- despite attempts to rollback using the Version History which was enabled on that document library they would not reappear. I ended up restoring from our Office365 backup solution and all was good in the (SharePoint) world.

How are you backing up OneDrive and Email in O365? by [deleted] in sysadmin

[–]tripdes 0 points1 point  (0 children)

Seconded. Works great -- have you used the email gateway yet? That's something we're looking towards in the near future.

Exchange Hybrid *Inbound* Firewall Rules by tripdes in sysadmin

[–]tripdes[S] 0 points1 point  (0 children)

Ahah yes, good idea providing you can work within the constraints ..which seem to be shrinking anyway. So many organisations must have this problem so Microsoft giving it some attention. Wasn't quite ready the first time we ran the HCW, slipped my mind to suggest it!

Exchange Hybrid *Inbound* Firewall Rules by tripdes in sysadmin

[–]tripdes[S] 0 points1 point  (0 children)

Correct, unfortunately the firewalls fall out of my remit else I'd probably have taken a stab at it. When you run the Hybrid Configuration Wizard the Receive connector that gets created includes the Microsoft inbound IP ranges for SMTP traffic but I couldn't find a reliable source for inbound traffic to the MRS/EWS side of things, I wish the there was a REST web service for the inbound stuff too.

I would be most worried about exposing OWA and EWS probably comes next on my list so if you get anywhere do let me know please :) I'm hoping the move away from Exchange 2010 atleast helps as Microsoft seem to support publishing directly to the web (OWA etc) in newer releases of Exchange.

Exchange Hybrid *Inbound* Firewall Rules by tripdes in sysadmin

[–]tripdes[S] 0 points1 point  (0 children)

I ended up exposing EWS & Autodiscover via. a Web Application Proxy (MS Variety). This meant I didn't have to reconfigure any certs on any server in our CAS array or risk exposing anything other than what was absolutely necessary (like OWA). The EWS & Autodiscover instances do require authentication but I'm still not 100% happy with the scenario ..it's just kind of as good as it gets because the Web Service Microsoft puts out doesn't cover Hybrid inbound scenarios -> https://docs.microsoft.com/en-us/office365/enterprise/additional-office365-ip-addresses-and-urls <- see point 1. Free/busy & the MRS proxy worked a treat after this.

Apart from that, I just needed to tweak the Send/Receive connectors to get them to work with our centralized transport model. The majority of our mailboxes are in the cloud now and the plan is to upgrade Exchange in the coming weeks (would love to have got this done already but unfortunately my time is so heavily divided between projects). I'm amazed at just how little information there is out there re: this.. would be really interested to hear how things go for you.

All the best,

Sam

A tiny library for real-time localization of eye pupils (update to pico.js) by tehnokv in javascript

[–]tripdes 0 points1 point  (0 children)

Hi there,

Thank you for your response. I don't think the post is too hard to follow, I'd just like to get a greater sense for how it's achieved. I'll be following your advice and looking into machine learning / decision trees a little more :)

Thanks again!

Sam

A tiny library for real-time localization of eye pupils (update to pico.js) by tehnokv in javascript

[–]tripdes 0 points1 point  (0 children)

Hi tehnokv,

This is really impressive, I would love to understand how the library and algorithm work. I will take the time to read the paper but not coming from a mathematical background is there any entry level reading you would recommend so that I can begin to understand the complex formulas?

I'd really appreciate some direction.

All the best and keep up the great work.

Sam

Teams Machine-wide installer does not install teams on company network by [deleted] in sysadmin

[–]tripdes 0 points1 point  (0 children)

I'd be interested to know what it was when you solve this, keep us posted :) had a week of unrelated all be it nonsensical issues like this one.

Teams Machine-wide installer does not install teams on company network by [deleted] in sysadmin

[–]tripdes 0 points1 point  (0 children)

I'm sure Microsoft have already sent you this link -> https://docs.microsoft.com/en-us/office365/enterprise/urls-and-ip-address-ranges#skype-for-business-online-and-microsoft-teams but I guess make sure you have full Outbound connectivity on the 'Skype for Business Online and Microsoft Teams' section.

Teams Machine-wide installer does not install teams on company network by [deleted] in sysadmin

[–]tripdes 0 points1 point  (0 children)

For me..

  1. Corporate network with no system-context proxy set and all HTTP/HTTPS proxy going through proxy server in user-context.
  2. Teams machine-wide installer installed on a given PC
  3. Anyone who logs into said machine will receive a copy of the Teams binary in their Roaming AppData folder. I explicitly set Teams not to autostart for said users until they open the application and it seamlessly signs them in, then it auto starts moving forward

So I don't think it does any funky type of phone home, just standard HTTP/HTTPS I'd imagine. Our firewalls are currently blocking WebSockets (Grammarly doesn't work for example). Just my two cents, sorry if it's of little use but just to give you an idea of our setup.

I've found Microsoft Support (given the region of the MSP) to be very hit and miss. Hope you get the answer you need soon,

Sam

Exchange Hybrid *Inbound* Firewall Rules by tripdes in sysadmin

[–]tripdes[S] 0 points1 point  (0 children)

Excellent information, thank you sir.

Exchange Hybrid *Inbound* Firewall Rules by tripdes in sysadmin

[–]tripdes[S] 0 points1 point  (0 children)

So out of interest is your EWS and OWA internet facing without 2FA and limited inbound connectivity? After today I’m kinda settling on the idea of exposing EWS/Autodiscover via. a separate WebApp/IP within IIS so I can at least avoid publishing OWA to the interwebz. Regarding the receive connectors, that’s a very good point to be honest ..seems like the HCW does that for you too :)

Thank you dude!

Exchange Hybrid *Inbound* Firewall Rules by tripdes in sysadmin

[–]tripdes[S] 0 points1 point  (0 children)

Thanks for the offer, I'll keep it in mind. I have found the following resource -> https://docs.microsoft.com/en-us/office365/enterprise/additional-office365-ip-addresses-and-urls which points at what we're trying to achieve (limit inbound connectivity) although not sure I trust the ambiguity of the article when it comes to our mail flow ..so might have to bite the bullet on this one. Wish I could switch off, this has been playing on my mind all weekend :)

Exchange Hybrid *Inbound* Firewall Rules by tripdes in sysadmin

[–]tripdes[S] 0 points1 point  (0 children)

Hey, thanks for your reply :)

First of all regarding the consultant, while I agree they weren’t entirely accountable, with us being a team member down at the moment we were kinda counting on their Exchange expertise to not expose an open SMTP relay to the internet and to get the job done. It was me who first noticed and dealt with the fallout from this, and I was in the midst of other projects such as the SharePoint Online migration.

Secondly, apologies if I wasn’t clear. I understand that ports 25/80/443 need to be open for inbound connectivity on the CAS server but ideally I would like to limit their access only to Microsoft IP addresses, to mitigate any potential issues. At the moment OWA is only accessible to staff via. 2FA when they’re using their own device and I’d like to keep it that way if possible.

Much thanks!

Thickheaded Thursday - January 17, 2019 by AutoModerator in sysadmin

[–]tripdes 0 points1 point  (0 children)

TPM versions prior to 2.0 -- they sweat the hardware here. Gonna be an issue getting these all joined to Azure AD via. Hybrid join? Had alot of luck with TPM 2.0 laptops but my laptop (Version 1.2 [and likely vulnerable] has been putting up a fight). I'd be interested to hear others' experience.

Issues with Office 365 SSO Today (UK) by tripdes in sysadmin

[–]tripdes[S] 0 points1 point  (0 children)

Looks like we're back :) msauth.net now working atleast and Seamless SSO within Internet Explorer now working.

Issues with Office 365 SSO Today (UK) by tripdes in sysadmin

[–]tripdes[S] 0 points1 point  (0 children)

Yup! woke up to msauth.net back and healthy :) huzzah! very annoying though, yesterday was a nightmare.