90 Minds Community

 View Only
  • 1.  Active Directory Solution for tiny company

    Posted 05-11-2021 10:49
    We have a small Sage 100 customer with 5 people and 8 workstations. Their single, on-prem server burned up in a lightning storm (these things happen in New Orleans) last week. The IT firm they've used forever is pretty bad, but the customer's owner is loathe to switch to the Devil He Doesn't Know. 

    We have a solid proposal to put their Sage and related operations into the cloud, via I-BN. However, that leaves a question about how to provide desktop security on those 8 workstations. Is there a straightforward way to do this without buying another full server?

    I know there are appliances who claim to do this, does anybody have experience with something like that?

    ------------------------------
    Jerry Norman
    At-Large BOD Member, 90 Minds
    Smartbridge Partners
    512.419.1444 x112
    ------------------------------


  • 2.  RE: Active Directory Solution for tiny company

    Posted 05-11-2021 11:07
    You began/titled the message with "tiny" which in my years in consulting always translates to "no budget"/"small budget".

    1. Run everything on I-BN and 2FA/MFA to their server?
    2. VDI - my sense is that the administration of the desktops might be too costly


    ------------------------------
    Wayne Schulz - Schulz Consulting - 860-516-8990
    ------------------------------



  • 3.  RE: Active Directory Solution for tiny company

    Posted 05-12-2021 09:02
      |   view attached
    Nowadays, you can comfortably live without local servers or even Active Directory.

    On our MSP-side, our go-to stack nowadays is Microsoft 365 E3 + E5 Security (~$44/user/month).  That gets you Email, SharePoint, Windows 10 Enterprise, full Office 365 and one-step-from-the-best security offerings.  For your question, the important bits would be Intune, which you would use to set policies and install applications, Defenders for Endpoint/Identity, which you can think of as antimalware, and Azure AD for your identity and access management, which is your security, real-time threat management and multi-factor authentication. It's all cloud based which means you can manage it from anywhere, and the devices can connect in (and be properly secured and protected) from anywhere.

    ------------------------------
    Steve Iwanowski, NextStep Technology Advisors, aka DSD Lancaster PA ¯\_(ツ)_/¯
    ------------------------------