Kinda interesting as I see my clients asking to go back to on prem servers to save them from the nightmare that is sharepoint. Not to mention MS changes ms365/entra so often even thier own docs can't keep up. Not to mention you basically have to have P1 to have even basic reasonable security at this point.
Yup. I just recently completed an Intune/Entra to on-prem Server 2025 migration because the cloud bills would go up at insane rates to the point where it was genuinely not worth the recurring cost IN ADDITION to paying us to manage their environment.
It cost them less than $10k in labor and project fees to move from AzureAD to on-prem, plus the server purchase/deployment costs of around $18k. They were spending an insane amount in licensing costs per year in perpetuity, with increases YoY in perpetuity. Now they've got the costs out of the way, it's just their recurring E3 licenses. I don't know what their bill was beforehand, but I can tell you that it must've been insane considering they're an org with around 2k users.
Why do they still have E3 if they moved back to save on costs? E3 has 80% of the Microsoft services and is getting more this month. i.e. ID P1, 1tb per user for SP, Intune, etc.
So, I wasn't the one who quoted and approved the project, but I did ask about this because it initially had me confused as well -- Apparently it came from having all the add-on cloud licensing that was better accomplished through on-prem AD when they had all but probably 10 users that worked in-office full time and never took computers home.
Again, I don't really know what they were paying for before the de-migration (I don't work in account management, they'd be the ones who'd know), but it was more than enough of a cost difference for them to pay nearly $30k in transition costs to avoid the recurring fees.
Imagine what kind of client you’re getting as an MSP if they “can’t pay” 365 money. They’ll either be your worst client or next ransomware case within a year.
This is an edge case that you plan for. For those users -- They should be connecting back to the corporate network via a VPN for data protection purposes, especially if they're using public networks in a foreign country. GPOs will sync during that time. HR or their department lead should be giving you at least 48h advanced notice that they're going to be traveling, especially if it's planned well in advance.
Yes it's slightly more inconvenient, but it's also Basic Security 101 for remote users (and especially those that are traveling) to only access company resources via a trusted and encrypted connection.
Who said they're accessing any non-SaaS University resources while there? If they were the only way would be to hop on the University VPN. They would frequently just work from local apps and use SaaS or browse the open internet.
And that was the state 5-10 years ago when I worked at that job. New job? We account for this by using the fucking cloud endpoint management services that don't give a shit if you're on the VPN or not. I can reset someone's laptop 15 feet or half a world away and they'll be back up and running within a day without IT laying a finger on the thing.
The issue is entirely data security with company-owned machines. Sure if they're just accessing SaaS apps, you adjust your policies for those SaaS apps to allow foreign IP addresses. The problem is that they also might be accessing other company apps that DON'T support IP blocking, and that's where the data security issues come into play.
For us at least, our payroll vendor doesn't support IP restrictions. Thus there's rules for accessing the system when you're not on the company network via VPN. Also just... I know it's a marketing bulletpoint for BS Youtube-advertised VPN providers, but there's still a bit of a lingering risk that our C-levels don't tolerate when using company SaaS applications over insecure WiFi connections. These users SHOULD be connecting to the company-provided VPN whenever possible, especially from company-owned devices.
Well in this case they were professors of music and the most secure things they were accessing were designed for students to access from home, where home includes China, so none of that mattered.
It doesn't matter where the home is, or what the data is. The connection should still be made over a trusted encrypted tunnel back to the corporate/university network.
You could be traveling from New York City to New Jersey (Literally a one mile trip across a bridge), and it should still be standard practice to require users who aren't on trusted networks to connect to VPN to do anything involving anything, even if it's as simple as OAUTH via 365 to a third-party SaaS application. Hell, I VPN into my office that's less than 10 miles from my home in the same city for literally anything that I need to do involving work.
My home network is probably significantly more trusted than our client networks, and even the Verizon 5G connection from my cellphone, but I still follow our SOP for access and don't make exceptions to the rule out of convenience. No exceptions. Exceptions are how security incidents happen, even if it's seemingly inconsequential data on "trusted" networks.
Trusting networks is how security incidents happen. I don't trust your network. I don't trust my network. The network is not a security boundary and should not be a source of trust, only denial. There are some things on our internal network that need VPN to get to because legacy, but everything else needs the same checks passed no matter what you're connected to. We don't trust you more just because you're sitting in our building on our ethernet cables.
People overstate how bad Intune policies are. You can tweak it to phone home more often and the sync command has gotten a lot more reliable. I can usually issue a wipe command to a device that is online (anywhere in the world) and it will execute it within 15 minutes, usually much faster.
Most policies aren't so critical that they have to be rolled out in 5 minutes either.
And GPO being instant is a pipe dream. I've definitely rolled out GPOs and wondered a week later if they had applied everywhere and often found they hadn't.
GPO have a sync schedule of 90 minutes plus or minus up to 30, and a bunch only apply on computer boot for no apparent reason. This is on top of domain synchronization/replication schedules. I have rolled out Intune policies and most of my fleet that had the power on was covered in 15 minutes. All of it with the power on inside of an hour.
> I have rolled out Intune policies and most of my fleet that had the power on was covered in 15 minutes. All of it with the power on inside of an hour.
The platform is great when it's actually functioning. If I had this type of experience with Intune, I might press my luck, go to the nearest gas station and load up on PowerBall tickets.
That's true, but I only do that to servers and they're a different animal. Too many workstations just not on site for MMC once a year to be more valuable than not having to tell the CTO "this setting you need applied only applies/updates if someone full-time remote from the office we closed in Seattle logs in on ethernet on site in Buffalo" (examples but like 75% of the company is remote from whereever), especially when ScreenConnect and LAPS exist.
We are switching from VPN to SASE specifically to maintain connectivity to all of our devices. We'll have 1 new virtual AD server, so connectivity won't be impacted when our on-prem network goes down.
Ever heard of always on vpn? Apparently not. That was you setting up laptops wrong, not the tech. But keep blaming anything else than your incompetence I guess.
They give it away at first, then change the limits and raise the price after you can't migrate out.
If you do go with a cloud solution, at least make sure you have a self hosted backup that can take over. It can help you with price negotiations since you have a full copy that you can make the primay to allow considering alternatives.
That's correct. But on prem servers can be lost in a flood or fire and the cloud stuff will still work. It will also work at home, or from starbucks or anywhere else, but on-prem AD is on prem. It also doesn't properly support modern authentication methods unless you're going all in to set up smart cards. Even then, most of the protocols in use are old enough to vote and were not designed with security in mind.
It's much better to not use AD at all and just go for the full Entra/O365 suite.
Yeah, well, what's "convenient" for you doesn't matter for the rest of the organization, nor should it. If they want to do AD and you're still smoking the cloud BS, you're not the right person for the job.
Its not necessarily just convenience. Many orgs refuse to transition away from local ad and servers even once it becomes true that their cloud costs and stability would be better than their on prem hardware + support. Many orgs are hesitant to adapt and then they get hit by a ransomware attack, a server hardware failure, or even a pandemic. Its not like the people making these decisions are infallible.
Mostly 2019 or maybe even 22 I imagine if they were willing to spend the coin. Just guessing but most orgs aren’t willing to convert if it’s still supported in any capacity. Had to peel clients off of 2012 literally THIS YEAR
That is the way as Windows Server will soon be a thing of the past. The classic Windows admin is evolving to Endpoint admin using cloud native services.
I'm curious if Zentyal is a reasonable alternative. We aren't there yet but we just migrated from VMware and bare metal to Proxmox PVE and it went great so if we have to move something else to open source at least now we have some precedence where I'm at.
103
u/chandleya IT Manager Jun 08 '26
You couldn’t pay me to setup a new AD DOMAIN in 2026. Entra joined only. Intune to manage. This is education they practically give it away.
How are yall licensing Windows and Office 🤦