

Recovery partitions on servers – especially VMs – are kind of pointless. Just boot the ISO if you need WinRM.


Recovery partitions on servers – especially VMs – are kind of pointless. Just boot the ISO if you need WinRM.


Hyper-V is decent. It’s VMM that is atrocious. Hopefully you don’t have Citrix with MCS catalogs.


You connect directly to the ESXi host with root. Because you’re going to have to boot up vCenter in addition to the DC anyway when you’re using SSO. I would use DRS rules to prefer host1 for vCenter and the PDCe for that reason.
Only in the very early days of virtualization (2008-2012) did I recommend keeping a physical server around. I know a lot more now than I did then.
But anymore, I don’t recommend using SSO for hypervisors or backup infrastructure. It’s better to add another wall in front of an attacker trying to laterally move onto these critical platforms for ransom, data exfiltration, etc.
And in reality, these “kaboom events” aren’t terribly common unless you’ve neglected some other part of your infrastructure.


Which specific PCI requirements did you fail?
Regardless, it sounds like you’re over-complicating things. The cameras should just be on a separate VLAN with proper ACLs at the router/firewall.


Check the following during this unknown network window:
Also are your wireless clients on a different VLAN than your wired clients? Does the firewall treat this traffic differently in any way? Does DHCP give out different DNS settings than wired?
It sounds like you need to set up Exchange Hybrid although it’s really not clear to me what you’re actually doing.
What is the “secondary server?” How did all this work before you bought “MS accounts?” Where was the MX pointing before? When you say “Exchange server” are you talking about Exchange Online or onprem? Which server is rejecting with the relay error?
Regardless, you’re going to need objects in the environment where the MX points that forward to the second location where the rest of the users are. In Exchange onprem/Online this would ideally be a MailUser object created by Azure AD Connect, but a Contact could suffice in certain setups.
And the second environment needs to trust the emails forwarding through the first or you’ll have SPF failures.
But again, a proper Exchange Hybrid setup takes care of all of this.
Does this help?
You should still be able to sync them and let soft matching connect the onprem and cloud accounts. Then the info in that post can be used to clean up the duplicate cloud mailbox and its properties in preparation for a Migration.
This is one of the only remaining use cases (in my opinion) for Public Folders.
I hate public folders.
It’s not exactly clear what the main goal is here and it sounds like a bad idea on first glance after reading your last paragraph. But it sounds like you might be looking for mandatory profiles.
https://learn.microsoft.com/en-us/windows/client-management/client-tools/mandatory-user-profile
But now that I read it again I think you might be conflating users/profiles with sessions. In which case no, this is neither possible nor a good idea. But it still might be okay with mandatory profiles if the device and app works the same from multiple sessions.
Anyway, you might get better answers if you state the full problem, including details on software and device, not just your proposed solution.
https://xyproblem.info/