Monday, August 15, 2016

Our Office 365 Adventure

No how-to here.  Just our adventure into Office 365.

So the company I work for hired a couple of new VP's.  Obviously this means they want to make their mark and show our owners that they made a good hiring choice.  One of them is a complete waste of space so we won't cover that one.  He's pretty much guaranteed to be here as long as he wants.  The other one wants to to a trial of Office 365 as part of how he is trying to impress the owners.

His goals:

Sharepoint
Document control with revision tracking
Forms with workflows
Decrease process times using the above.

I know very little about Office 365 and he has said he would take the lead in showing it's value.  He's going to do his own work and not try to use me to do it for him!  Great!  

We started out with 2 accounts, 1 for me as admin, 1 for him.  This lasted a few days and he wanted to add more.  In a few days add a few more.  The we were up to a total of 9 for this "pilot".  We got Azure AD working so now I have to delete the accounts and recreate them to use our domain.  Not a huge deal.  Then we got email migration working for one of my test users so we start migrating users. Unfortunately one big issue came up.  No public folders.  For us this is a big deal.  Now he wants to add 6 more users.  I convince him not to migrate their email because of the lack of public folders.  He doesn't really care so they don't get migrated.  Great!  6 fewer people complaining to me!

I found a solution from Microsoft on how to get the public folders working.  I ran through the steps.  Nothing.  I tried migrating my test user back to my on premises Exchange server.  Not happening.  Crap!  I've tried running through some solutions I found on migrating back and so far nothing works.  Last resort, I'm waiting until our consultant can help us out with this.

I also got wondering about how this affects my on-premises CAL count for Exchange.  It looks like an Office 365 E1 subscription IS your standard level CAL for on-premises.  Found this article explaining it.  All we are using is standard anyway so this frees up some CAL's for me.

I'll add updates as we progress with this...

1/30/2020 Update

So here we are almost 4 years later.  We've expanded to about 65 O365 E3 users and we will be accelerating that adoption to everyone over the next year.  Our MPSA with Microsoft will expire in early 2021 and I want to drop all Office related items off that renewal since we will be fully migrated to O365.  At that point we will also migrate off our on-site Exchange server to the O365 Exchange servers.

In bad news, for us anyway, Teams is replacing Skype for Business.  It just doesn't seem as easy to use although one VP with nothing better to do has spent a ton of time getting used to it and likes it now.  While we won't block Teams from being used, we have other, and in my opinion, better options.  We have also migrated from AT&T for our phones to a VOIP system using Fuze.  Fuze has a collaboration package that I think is much better than Teams.  Our issue is that we have customers that are only allowed to use certain software.  That means we need to maintain flexibility on what our people can use, and I don't have a problem with that.  Teams, Skype for Business, WebEx, GoToMeeting, Fuze Collaboration, all need to be supported.

I guess overall the migration toward Office 365 hasn't been a disaster so I guess that's a good thing.  I wish I had the time to learn more about the admin side of it.  I still have my job so I guess everyone else is good with it too!!

Friday, May 13, 2016

Windows 10 - Start Button Stops Working


So I've been running Windows 10 for some time now.  Yesterday everything was fine.  I got in to work and turned my PC on...and now the start button doesn't work.  After hours of Google searches and trying different things, here is what worked for me.  You will be working with the registry.  Don't screw it up!  You will also be deleting your profile so make sure you have copies of whatever you need in it.

  1.  Log in as another user with admin permissions.

  2.  Back up your user profile.  I just renamed mine.  c:\users\johmar to c:\users\oldjohmar.  You want to rename so you can get your desktop shortcuts and whatever other files you may need out of your old profile.

  3.  Open regedit and go to HKEY_Users.  Under there will be some big long SIDs.  Anyway, you need to look at the long ones that DON'T say "_Classes" at the end.  Expand it and go to Volatile Environment.  Find the one that is for the logon where the start button isn't working.  Delete that key - not just the Volatile Environment key, the whole thing (highlighted in yellow below.


  4.  Now go to HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList.  There will be several long SIDs again.  Look for an entry with ".bak" on the end.  Click on it on the left side and look at the ProfileImagePath.  You are looking for the one pointing to the user profile you deleted (or renamed).  If you find one with a .bak extension on it that points to the profile you deleted, delete it.  If there is a matching SID without the .bak, delete it too.  Watch the numbers carefully and make sure you delete the right thing!!  When I fixed mine, I had a .bak file but NOT a matching SID without the .bak extension.  I don't have a .bak entry in my registry anymore so I can't show a screen capture.

  5.  Close the registry editor.
  6.  Reboot and if you did everything right, you should not get a temp profile again.
  7.  Delete the renamed profile once you are sure you no longer need any files in it.  Or don't.  It's not hurting anything sitting there.

Thursday, November 12, 2015

Remote Server Administration Tools for Windows 10 - DHCP

I installed Windows 10 on my PC a few weeks ago, along with MS Office 2016.  What a nightmare!  I was able to get along for about a month and then just got tired of dealing with things not working right.  I was going to go back to Windows 7 but then decided to "Reset This PC" under Settings/Update & Security/Recovery.  I used the option to wipe out all installed software/user data and start fresh.  So far, so good.  No major issues and everything works.  I went to install the Remote Server Admin Tools for WIndows 10 and found there was no DHCP management MMC snap-in.  Well that sucks!  There are powershell commands, but I like the old method better.  I poked around Google and found a post on reddit that tells how to do it.  Initially it didn't work for me but reading through the comments, the full answer was there.  So, here is the summary of what was needed to make it work for me.

1.  Copy dhcpsnap.dll and dhcpmgmt.msc from c:\windows\system32 from my one of my server 2012R2 dhcp servers and put them in system32 in my local pc.

2.  Copy dhcpsnap.dll.mui from c:\windows\system32\en-us on my 2012R2 dhcp server to the same folder on my pc.

3.  Open a command prompt as an administrator and type "regsvr32 dhcpsnap.dll" and press enter.

4.  Open dhcpmgmt.msc and it works like it did when I was running Windows 7!

Tuesday, October 6, 2015

Standardized Signatures in Outlook 2013/2016 Part 2

So in Part 1 we got a test standardized signature ready to go in Exchange 2013.  Now we have to enforce our signature and eliminate all signatures the users have made in Outlook.

1.  Ensure you have the ADMX's installed for your version of MS Office.  You can get the ADMX for Office 2013 here and for Office 2016 here.   I'm going to use Office 2016 in my example.

2.  Block access to create/edit/delete signatures in Outlook.  In your group policy go to User Configuration, Policies, Administrative Templates, Microsoft Outlook 2016, Outlook Options, Mail Format.  In there there is a setting Do not allow signatures for e-mail messages.  Enable it.













2.  Get rid of the Signature button in Outlook.  You need the command bar ID to gray out the Signature button.  These are listed on the Microsoft web site as Office Fluent User Interface Control Identifiers.  I could not find one for Office 2016 but I did find the one for Office 2013 here.  This will get you a zip file with a bunch of Excel spreadsheets in it.  I found the codes I needed in outlookexplorercontrols.xlsx.  I found 3 codes related to signatures; 5608, 22965 and 3766.  I put all three in my test group policy.  You need to enter it at User, Policies, Administrative Templates, Microsoft Outlook 2016, Disable Items in User Interface, Custom, Disable command bar buttons and menu items.  Enable the policy and click Show to get to be able to enter those three codes.






















Once your updated policy has gotten to your users, the signature button will now be grayed out so that users can't manually add the signature.  You may need the users to log out/log in for the policy to take effect.


Standardized Signatures in Outlook 2013/2016 Part 1

So apparently HR had nothing to do today and said they wanted to standardize everyone's email signature.  We are still in the process of migrating to Exchange 2013 so I'm not overly familiar where everything is.  With about 2 minutes of poking around I found the mail flow rules.  Googling how to best do this for a few more minutes revealed that I can pull user fields from AD for our commonized signature.  Well, that saved a ton of time over having to create over 200 custom signatures!  Now, what are the fields I'd be likely to use and what is their name in the AD database?  I few more minutes on Google and I found this.  It is a MS TechNet wiki article on Active Directory Attributes in ADUC GUI Tool.  Perfect!  Choose your ADUC tab from their TOC and it takes you to a screen capture of that tab with all the fields you need to create your signature!  Finally, the new mail flow rule signature must be in html so you can control font, size, etc.

For my test signature I'm applying the rule only to myself and appending the disclaimer.  My test "signature" is:

<div style="font-size:12pt;  font-family: 'Calibri',sans-serif;">
</br></br>
<B>%%DisplayName%%</B></br>
<B>%%Title%%</B></br>
<B>%%Company%%</B></br>
<B>%%PhoneNumber%%</B></br>
</br></br></br>
</div>

I have another mail flow rule with a disclaimer on it that follows the signature so that is why there are so many breaks.  That and I don't really know html so there is probably a much better way!

This give me a simple signature showing:

My Name
My Title
Company Name
Phone Number

in Calibri 12 font and in bold.  The info below has been changed but it is what my new simple test signature looks like at the end of an email:

John Martin
IT Director
My Company
847-123-4567

So, that's the absolute basics of it.  You can get a creative as your html abilities allow!

Part 2 will be the Group Policy changes needed to enforce this.

Monday, September 14, 2015

VMware 6.0 Update 1 and Veeam

VMware came out with some updates last week.  Like an idiot, I put them on fairly soon after I saw them.  Then my Veeam backup ran.  Or rather, it didn't run.  In Veeam, it gave the error:

9/14/2015 2:46:30 AM :: Processing Test Error: NFC storage connection is unavailable. Storage: [stg:datastore-23,nfchost:host-2706,conn:10.0.0.0]. Storage display name: [VM-Datastore1].
Failed to create NFC download stream. NFC path: [nfc://conn:10.0.0.0,nfchost:host-2706,stg:datastore-23@Test/Test.vmx].

The VMware knowledge base article said on your Veeam server, look in c:\Program Data\Veeam\Backup\"Name of your backup" and open the file Agent."backupname".Source."VM name".  It opens with Notepad.  Search for "NFC".  Scroll down from there.  You should see something similar to this:

Authd version: [1.10]
[12.09.2015 02:31:08] <  2000> nfc|             SSL connection is required to perform authentication.
[12.09.2015 02:31:08] <  2000> nfc|             Initializing the SSL subsystem...
[12.09.2015 02:31:08] <  2000> nfc|             The SSL subsystem was successfully initialized.
[12.09.2015 02:31:08] <  2000> nfc|             Initializing new SSL connection...
[12.09.2015 02:31:08] <  2000> nfc|               Establishing connection with the SSL server... Failed.
[12.09.2015 02:31:08] <  2000> nfc|             Initializing new SSL connection... Failed.

And a little farther down:

[12.09.2015 02:31:08] <  2000>      ERR |SSL error, code: [336151568].error:14094410:SSL routines:SSL3_READ_BYTES:sslv3 alert handshake failure
[12.09.2015 02:31:08] <  2000>      >>  |SSL_connect() function call has failed.
[12.09.2015 02:31:08] <  2000>      >>  |Failed to establish connection with the SSL server.
[12.09.2015 02:31:08] <  2000>      >>  |Cannot initialize new SSL connection.
[12.09.2015 02:31:08] <  2000>      >>  |Authd handshake has failed.

The important thing to note is the references to Authd.

The problem is that update 1 turns off SSLv3.  Unfortunately, Veeam is still using SSLv3 to communicate with your hosts.  SSLv3 has to be turned back on.  Per the VMware knowledge base article 2121021:

Enable support for SSLv3 on Authd service 902 in ESXi

  1. Create a backup copy of the /etc/vmware/config file 
  2. Edit the /etc/vmware/config file to append the following line at the end of the file:

    vmauthd.ssl.noSSLv3 = false

    Note: If you have the line vmauthd.ssl.noSSLv3 = true in the file, change it to vmauthd.ssl.noSSLv3 = false
    Example:

    [root@w1-fiqabj-003:~] cat /etc/vmware/config
    libdir = "/usr/lib/VMware"
    authd.proxy.nfc = "vmware-hostd:ha-nfc"
    authd.proxy.nfcssl = "vmware-hostd:ha-nfcssl"
    authd.proxy.vpxa-nfcssl = "vmware-vpxa:vpxa-nfcssl"
    authd.proxy.vpxa-nfc = "vmware-vpxa:vpxa-nfc"
    authd.fullpath = "/sbin/authd"
    vmauthd.ssl.noSSLv3 = false
  3. Restart the rhttpproxy service with the command:

    /etc/init.d/rhttpproxy restart
This needs to be done on each of your hosts.  It is simple enough that it only took me maybe 2 minutes per host.  Since I only have 3 hosts, it wasn't a big deal.  I ran a test backup and it worked fine after making this work-around.

Right after I got this resolved, with the help of Veeam support, the support guy emailed me and said there was now a KB article on it.
Vcenter Server Appliance 6.0 - Running out of log space

So I was looking through my VCenter Server and found an entry that shows I was running out of log space.  Hmmm, this may be why I was getting the syslog alerts that VMware support was absolutely no help with.  I started searching around for ways to increase the space for the logs, but with 11 .vmdk's, which one was for the logs??  Fortunately I found the blog Virtually Ghetto by William Lam.  I have stumbled across that blog before but forgot about it, like I do most things in my advancing years! He tells what each vmdk is here.

Copied from VirtuallyGhetto.com













Next problem, although he shows what each vmdk is for, I don't know the command line very well for vcsa.  Fortunately, he assists with the actual mechanics of increasing the drive size with a link in the article here.  It is easy enough that even I can do it!  Using Putty to SSH in to vcsa, get to the BASH shell.  At the command prompt "shell.set --enabled True" and then "shell", Then, run df -h to see the current size of the log file vmdk.  Go in to the vSphere web client and increase the size of Hard Disk 5.  I bumped it up to 15GB.  Then back in Putty, "vpxd_servicecfg storage lvm autogrow". Finally, "df -h" again to show that the vmdk has increased.

This is a copy of my successful attempt at increasing the log size on my vcsa: