Posts

One Drive to Rule Them All: Consolidating Mail, Files and Media from Many Accounts into Google Drive

Written with the help of Claude AI The problem: one person, too many accounts Most people don't plan their digital footprint. They accumulate it. A personal Gmail from university, an Outlook.com address from an old job, a OneDrive that came free with an Office subscription, a second Google account set up for a side business. Years later, the emails, documents, spreadsheets and family photos are spread across all of them. That was the situation for a recent client. They had moved onto a Google Workspace account on their own domain and wanted everything else consolidated there: mail into the Workspace mailbox, and every file, folder, photo and video into a single, organised Google Drive. It sounds like a copy-and-paste job. It isn't. This post walks through the four stages we went through, the traps we hit along the way, and the scripts that got us out of them. The overall plan was simple: Move each mailbox into the Workspace account. Copy each account's files into Google Dri...

From Password Spray to SAML: Securing Cisco FTD AnyConnect VPN with Entra ID

 Written with the help of Claude AI Why we did this Random Active Directory lockouts turned out to be a large password spray against our Cisco AnyConnect VPN, and the fix was moving VPN authentication to SAML with Microsoft Entra ID. The starting point was common: a Cisco Firepower 1100-series firewall running FTD, managed on-box, with AnyConnect users signing in with their Windows AD password. Users kept getting locked out for no obvious reason. This post walks through what we found and every step it took to fix it, including the problems we hit along the way. It's written for small IT teams who run a similar setup and are seeing the same symptoms. What you'll end up with: VPN sign-in through Entra ID, with MFA on every connection The firewall never sees or forwards AD passwords, so spray attempts can't lock AD accounts Optional single sign-on through the user's default browser Starting environment: FTD 7.2.x managed by Firepower Device Manager (FDM), AnyConnect 4.10,...

Microsoft 365 emails to Gmail getting blocked with 550 5.7.1 errors

 We are using Microsoft 365 for their email service and recently faced an issue where outgoing emails to Gmail were not getting delivered because of the following error : 550 5.7.350 Remote server returned message detected as spam -> 550 5.7.1 [2a01:111:f403:c40f::7 19] Gmail has detected that this message;is likely suspicious due to the very low reputation of the sending;domain. To best protect our users from spam, the message has been;blocked. For more information, go to; https://support.google.com/mail/answer/188131 d9443c01a7336-220d5320c49si112823045ad.160 - gsmtp Now unless you have some kind of gold-star support with either Microsoft or Gmail, you are stuck with combing through documentation and forums to understand where to even start troubleshooting this error. The usual steps of checking if the domain is listed on spam sites (MultiRBL) and if TestExchangeConnectivity didnt give much insight into the error. After an hour of going through various forum posts, there was ...

Fortigate SDWAN with IPSec Site-to-Site VPN and multiple subnets at both sites

Recently, I was tasked with setting up a Site-to-Site VPN between a Fortigate FG100-F in a High Availability (HA) configuration and a FG60-F. Both sites featured dual WAN links configured in an SD-WAN setup, along with multiple VLANs. I needed to setup multiple VLANs at the branch office Fortigate. I used the VLAN switch feature to create VLANs as sub-interfaces, and then added them to a zone to help with inter-vlan traffic, and for easier firewall policy configuration To completed the site-to-site VPN links despite consulting the Fortigate documentation, I couldn't find an example that exactly matched this scenario. After some extensive searching, I found a YouTube video that demonstrated this particular setup. You can watch it here . YouTube Video Summary The video, although in Spanish, provides a detailed walkthrough of setting up a Site-to-Site VPN between Fortigate devices in a similar environment. It covers the configuration of dual WAN links, SD-WAN, . Thanks to YouTube...

Handling PDF Size Issues with Protected Files: A Solution Using Microsoft PDF Printer

In a recent project, I encountered a challenge involving a protected PDF file that needed to be included in a multi-page document. The PDF file was around 100 KB, and due to file upload limitations, the entire document had to be under 2 MB. Unfortunately, the protection settings of the PDF prevented it from being added to the multi-page document, citing security restrictions. Additionally, Adobe's PDF printer does not allow printing protected PDFs to a new PDF file—quite a limitation from Adobe! To work around this, I used the Microsoft PDF Printer, which allowed me to save the file as an unprotected PDF. However, this resulted in a significant increase in file size, ballooning to around 3 MB. Despite attempting various methods to reduce the size, such as using "Optimize PDF," "Reduce PDF Size," and online compression tools, the results were minimal. After further research, I stumbled upon a forum suggestion to use the "Print As Image" option in the Ad...

Adobe Acrobat DC Fill & sign Tool missing

Acrobat DC has a nifty tool to allow placing of saved signatures on documents. After a recent laptop replacement, one user couldnt find the tool to place the signatures needed. The issue came out to be that Acrobat removes the tool if the language setting of the applications is not set as English only. The application here was set to English & Arabic You have to go to Edit->Preferences->Language The Application Language option should be set as English Only After restarting the program, the Fill&sign option appeared in the Tools Section Ref: https://forums.adobe.com/thread/1945290

Renew expired Microsoft Exchange Server Auth Certificate

Today our Exchange servers refused to send out emails to the user mailboxes. After going through the logs, Warnings popped up for Exchange OAuth, which said that SMTPReceive connector was failing because of a certificate issue. So Exchange server installs a server authentication certificate used for Organizational Authentication for itself and other Exchange servers in the organization for intra-site communication, during initial setup Usually these certificates have a 5 year validity. Upon expiry, some services start failing to work as needed. Following the link and steps below, i was able to get  the services up and running again. ref: https://community.spiceworks.com/topic/512374-missing-the-microsoft-exchange-server-auth-certificate New-ExchangeCertificate -KeySize 2048 -PrivateKeyExportable $true -SubjectName "cn= Microsoft Exchange Server Auth Certificate" -DomainName "*.yourdomain.com" -FriendlyName "Microsoft Exchange Server Auth Certifica...