ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    domain controller in the cloud for small office?

    IT Discussion
    17
    120
    9.9k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • DustinB3403D
      DustinB3403 @scottalanmiller
      last edited by

      @scottalanmiller said in domain controller in the cloud for small office?:

      @dustinb3403 said in domain controller in the cloud for small office?:

      In line with this topic does SAMBA have some kind of tie in with GPO, where you can create / edit / delete GPO's from within SAMBA?

      Tie in? Samba does GPO exactly like any other AD does.

      So there is a Group Policy Editor that operates on CentOS or something? (no windows involved)

      scottalanmillerS PenguinWranglerP 3 Replies Last reply Reply Quote 0
      • scottalanmillerS
        scottalanmiller @DustinB3403
        last edited by

        @dustinb3403 said in domain controller in the cloud for small office?:

        @scottalanmiller said in domain controller in the cloud for small office?:

        @dustinb3403 said in domain controller in the cloud for small office?:

        In line with this topic does SAMBA have some kind of tie in with GPO, where you can create / edit / delete GPO's from within SAMBA?

        Tie in? Samba does GPO exactly like any other AD does.

        So there is a Group Policy Editor that operates on CentOS or something? (no windows involved)

        Nothing I said should lead you to ask that question. I think you are not clear on what GPO is.

        DustinB3403D 1 Reply Last reply Reply Quote 0
        • scottalanmillerS
          scottalanmiller
          last edited by

          GPO is handled identically on Samba as it is on MS AD. That alone should answer all questions. Any editor that works with MS AD with work with Samba, no editor can tell the difference, as they are identical.

          1 Reply Last reply Reply Quote 1
          • scottalanmillerS
            scottalanmiller @DustinB3403
            last edited by

            @dustinb3403 said in domain controller in the cloud for small office?:

            @scottalanmiller said in domain controller in the cloud for small office?:

            @dustinb3403 said in domain controller in the cloud for small office?:

            In line with this topic does SAMBA have some kind of tie in with GPO, where you can create / edit / delete GPO's from within SAMBA?

            Tie in? Samba does GPO exactly like any other AD does.

            So there is a Group Policy Editor that operates on CentOS or something? (no windows involved)

            Why would you want this? He has Windows machines to manage, so why avoid the Windows desktop tools in a scenario that only works when you have Windows desktops?

            Mike DavisM 1 Reply Last reply Reply Quote 1
            • DustinB3403D
              DustinB3403 @scottalanmiller
              last edited by

              @scottalanmiller said in domain controller in the cloud for small office?:

              @dustinb3403 said in domain controller in the cloud for small office?:

              @scottalanmiller said in domain controller in the cloud for small office?:

              @dustinb3403 said in domain controller in the cloud for small office?:

              In line with this topic does SAMBA have some kind of tie in with GPO, where you can create / edit / delete GPO's from within SAMBA?

              Tie in? Samba does GPO exactly like any other AD does.

              So there is a Group Policy Editor that operates on CentOS or something? (no windows involved)

              Nothing I said should lead you to ask that question. I think you are not clear on what GPO is.

              My question was very clear, and you construed it to be something else.

              scottalanmillerS 1 Reply Last reply Reply Quote 0
              • Mike DavisM
                Mike Davis @scottalanmiller
                last edited by

                @scottalanmiller said in domain controller in the cloud for small office?:

                Why would you want this? He has Windows machines to manage, so why avoid the Windows desktop tools in a scenario that only works when you have Windows desktops?

                my Linux skills are weak, so I have no interest in using Linux.

                1 Reply Last reply Reply Quote 0
                • Mike DavisM
                  Mike Davis @scottalanmiller
                  last edited by

                  @scottalanmiller said in domain controller in the cloud for small office?:

                  GPO, Salt, JumpCloud, AzureAD, etc.

                  Hadn't heard of JumpCloud, but this may be the answer. 10 users free.

                  scottalanmillerS gjacobseG 2 Replies Last reply Reply Quote 1
                  • scottalanmillerS
                    scottalanmiller @DustinB3403
                    last edited by

                    @dustinb3403 said in domain controller in the cloud for small office?:

                    @scottalanmiller said in domain controller in the cloud for small office?:

                    @dustinb3403 said in domain controller in the cloud for small office?:

                    @scottalanmiller said in domain controller in the cloud for small office?:

                    @dustinb3403 said in domain controller in the cloud for small office?:

                    In line with this topic does SAMBA have some kind of tie in with GPO, where you can create / edit / delete GPO's from within SAMBA?

                    Tie in? Samba does GPO exactly like any other AD does.

                    So there is a Group Policy Editor that operates on CentOS or something? (no windows involved)

                    Nothing I said should lead you to ask that question. I think you are not clear on what GPO is.

                    My question was very clear, and you construed it to be something else.

                    Yes, very clearly not connected to what I was talking about.

                    1 Reply Last reply Reply Quote 0
                    • scottalanmillerS
                      scottalanmiller @Mike Davis
                      last edited by

                      @mike-davis said in domain controller in the cloud for small office?:

                      @scottalanmiller said in domain controller in the cloud for small office?:

                      GPO, Salt, JumpCloud, AzureAD, etc.

                      Hadn't heard of JumpCloud, but this may be the answer. 10 users free.

                      They are on here, on SW, were at SpiceWorld with a booth, too. Seems like a cool product.

                      larsen161L 1 Reply Last reply Reply Quote 0
                      • gjacobseG
                        gjacobse @Mike Davis
                        last edited by

                        @mike-davis said in domain controller in the cloud for small office?:

                        @scottalanmiller said in domain controller in the cloud for small office?:

                        GPO, Salt, JumpCloud, AzureAD, etc.

                        Hadn't heard of JumpCloud, but this may be the answer. 10 users free.

                        I don't know the name either,.. and they seem like a good viable solution for 8 users..

                        1 Reply Last reply Reply Quote 0
                        • Mike DavisM
                          Mike Davis
                          last edited by

                          Just did the math for moving beyond 10 users. JumpCloud makes sense if you're under 14 users. Beyond that the $111 for Azure works out better.

                          1 Reply Last reply Reply Quote 2
                          • NashBrydgesN
                            NashBrydges @Mike Davis
                            last edited by

                            @mike-davis I've been using JumpCloud on Scott's recommendation from a few months ago. It's worked well for what I needed for my team but I don't have HIPAA requirements.

                            1 Reply Last reply Reply Quote 1
                            • Reid CooperR
                              Reid Cooper @Mike Davis
                              last edited by

                              @mike-davis said in domain controller in the cloud for small office?:

                              @gjacobse said in domain controller in the cloud for small office?:

                              HIPAA security without it.

                              How do you create a password change policy that gets enforced without a domain controller?

                              Enforcement is always local, never from the controller. The Local Group Policy Editor is the standard tool for setting this on a Windows machine, or the Local Security Policy console.

                              With the LSP:

                              1. To open Local Security Policy, on the Start screen, type secpol.msc, and then press ENTER.
                              2. Under Security Settings of the console tree, do one of the following:
                                • Click Account Policies to edit the Password Policy or Account Lockout Policy.
                                • Click Local Policies to edit an Audit Policy, a User Rights Assignment, or Security Options.
                              3. When you find the policy setting in the details pane, double-click the security policy that you want to modify.
                              4. Modify the security policy setting, and then click OK.

                              With the LGPE

                              1. Open the Local Group Policy Editor (gpedit.msc).
                              2. In the console tree, click Computer Configuration, click Windows Settings, and then click Security Settings.
                              3. Do one of the following:
                                • Click Account Policies to edit the Password Policy or Account Lockout Policy.
                                • Click Local Policies to edit an Audit Policy, a User Rights Assignment, or Security Options.
                              4. In the details pane, double-click the security policy setting that you want to modify.
                              5. Modify the security policy setting, and then click OK.

                              Reference: https://docs.microsoft.com/en-us/windows/device-security/security-policy-settings/how-to-configure-security-policy-settings

                              1 Reply Last reply Reply Quote 1
                              • DashrenderD
                                Dashrender
                                last edited by

                                You get baseline AzureAD by using O365 (anything other than hosted Exchange only). This is what I use at one of my clients, works great!

                                As for managing the machines, you can use Salt for that versus the expense of a Windows VM and licensing. though you'll have to learn Linux unless there is a Salt Master that runs on Windows - and then you're right back to the licensing issue.

                                Reid CooperR 2 Replies Last reply Reply Quote 1
                                • Reid CooperR
                                  Reid Cooper @Dashrender
                                  last edited by

                                  @dashrender said in domain controller in the cloud for small office?:

                                  You get baseline AzureAD by using O365 (anything other than hosted Exchange only). This is what I use at one of my clients, works great!

                                  Does that allow for GPO? I think you still have to do GPO locally when using that. Which is fine, just use PS and you are done.

                                  Mike DavisM DashrenderD 2 Replies Last reply Reply Quote 0
                                  • Reid CooperR
                                    Reid Cooper @Dashrender
                                    last edited by

                                    @dashrender said in domain controller in the cloud for small office?:

                                    As for managing the machines, you can use Salt for that versus the expense of a Windows VM and licensing. though you'll have to learn Linux unless there is a Salt Master that runs on Windows - and then you're right back to the licensing issue.

                                    I don't think that there is, but you can just run without a master.

                                    1 Reply Last reply Reply Quote 0
                                    • A
                                      Alex Sage
                                      last edited by

                                      This post is deleted!
                                      1 Reply Last reply Reply Quote 0
                                      • Mike DavisM
                                        Mike Davis @Reid Cooper
                                        last edited by

                                        @reid-cooper said in domain controller in the cloud for small office?:

                                        Does that allow for GPO? I think you still have to do GPO locally when using that. Which is fine, just use PS and you are done.

                                        What do you mean by "just use PS"? Is there a way to export a local group policy and push it to the rest of the machines so I don't have to log on to every desktop and do it manually?

                                        1 Reply Last reply Reply Quote 0
                                        • Mike DavisM
                                          Mike Davis
                                          last edited by

                                          @dashrender said in domain controller in the cloud for small office?:

                                          You get baseline AzureAD by using O365 (anything other than hosted Exchange only). This is what I use at one of my clients, works great!

                                          I tried looking this up. Do I understand that you install the Azure AD Connect client on all the computers and it lets them sign in with their o365 credentials?

                                          DashrenderD scottalanmillerS 2 Replies Last reply Reply Quote 1
                                          • PenguinWranglerP
                                            PenguinWrangler @DustinB3403
                                            last edited by PenguinWrangler

                                            @dustinb3403 said in domain controller in the cloud for small office?:

                                            @scottalanmiller said in domain controller in the cloud for small office?:

                                            @dustinb3403 said in domain controller in the cloud for small office?:

                                            In line with this topic does SAMBA have some kind of tie in with GPO, where you can create / edit / delete GPO's from within SAMBA?

                                            Tie in? Samba does GPO exactly like any other AD does.

                                            So there is a Group Policy Editor that operates on CentOS or something? (no windows involved)

                                            When you create a Samba 4 (SAMBA 4 is the key) domain, you can use the exact same tools to administer it that you would any Windows Domain controller. The caveat is it must be a Samba 4 Domain which is at a Windows 2008 functional level. You can open up RSAT on your Windows box and create new users, open up Group Policy and start pushing out GPOs. It is not hard at all, many many how-tos on how to do this. Here is one of the first links from Google.
                                            https://www.howtoforge.com/tutorial/samba-4-domain-controller-installation-on-centos/

                                            Mike DavisM 1 Reply Last reply Reply Quote 3
                                            • 1
                                            • 2
                                            • 3
                                            • 4
                                            • 5
                                            • 6
                                            • 2 / 6
                                            • First post
                                              Last post