32: IGEL Weekly: How to Login using Active Directory on IGEL OS

Sep 28, 2021

In this blog, we will discuss  how to:

  • 00:00 Introduction
  • 03:40 Create Active Directory Login Profile
  • 06:15 Test Active Directory Connection
  • 08:00 Configure Session Passthrough
  • 09:30 Configure the screenlock
  • 11:20 Configure a Local user for Emergency
  • 13:30 Check if your user is working actually

Host:  Andy Whiteside
Co-Host: Chris Feeney
Co-Host: Seb


Andy Whiteside: Everyone welcome welcome to episode 32 of Idaho weekly i’m your host Andy whiteside crispy knees with me, Chris was just.

Andy Whiteside: letting us know that he had to get some dental stuff for his family, taking care of kind of urgent call last night, Chris it when you have a family never ends right.

Chris Feeney: Now you think you’re getting close to the finish line and then and then just stuff happens to appear out of nowhere so.

Chris Feeney: joys of parenting right, I want to go watch that Steve Martin film called parenthood again just so I could laugh my tears away.

Andy Whiteside: If you just had a US or you could just push down exactly what you want to happen.

Chris Feeney: As a result, would be fantastic.

Chris Feeney: Somebody needs to invent that thing son plug yourself into the ice let’s let’s take care of this right.

Andy Whiteside: Well, we also have said, with a sub as the newest member of the linkedin Community so welcome.

Chris Feeney: Welcome said.

Chris Feeney: You have no idea what you just signed up for.

Sebastien Perusat: yeah that’s apparently is simply that they are since yesterday evening, but yeah i’m late on the party like I said but i’m there, I mean i’m promised it a long time ago and now it’s time not sure how.

00:01:09.180 –> 00:01:12.210
Sebastien Perusat: That but it’s it’s exciting feeling.

Andy Whiteside: it’s a great professional repository to find people and reach out to people, unfortunately, that means people can find you and reach out to you, I must get like.

Andy Whiteside: 10 messages a day from somebody random that wants to be my my life coach or my exercise coach my health coach or or my business coach.

Andy Whiteside: I probably need a coach for all that all those things, but if I did, I would just sit around get coached all the time that’s right.

Chris Feeney: put me in coach i’m ready to play and he’s ready to play.

Chris Feeney: i’m playing he’s playing right there’s there is there is something to be said about sharpening the saw pulling off just kind of get things and then.

Chris Feeney: I think there’s a great story, I came here if it’s real or just sort of one of these things where Abraham Lincoln was asked you know you got to cut a tree down how much time, so well, I spent eight hours sharpening my saw in one hour cutting a tree right like.

Chris Feeney: There it is anyway.

Chris Feeney: there’s certainly we ready to cut some trees, right now, every.

Andy Whiteside: This is, this is the sharpening the saw section.

Chris Feeney: that’s what we’re doing good that’s right you’re sharpening the saw for all you listeners out there, said, what do you got teed up for us today.

Sebastien Perusat: What I would suggest is to take over the active directory topic for today just because there was some misunderstanding that i’m seeing on the database on the on the agile community regarding.

Sebastien Perusat: domain joy and logging into active directory using active directory through I CG and how’s the password process attached as working and which means essence we have and what possibilities and opportunities we have if you use active directory instead of going directly into the desktop.

Sebastien Perusat: So Sarah was able to just for today.

Andy Whiteside: Let me set that up with some you know real world consulting experience i’ve had.

Andy Whiteside: You know my first interaction and most people’s first interaction with an eye gel solution let’s say in the citrix or vmware world is kind of.

Andy Whiteside: Where you take this really powerful Linux operating system.

Andy Whiteside: And you manage it down to basically a zero client now zero client has a long history, may have talked about on the podcast before but.

Andy Whiteside: there’s thin clients and then there’s zero clients zero clients pretty much mitigate all functionality and just take it straight into whatever the uc solution of choice is.

Andy Whiteside: Zero client was a gimmick from day one, where it just took great existing stuff skinny down a little further.

Andy Whiteside: And then, and then limited it to going into one solution or another period, you can only do one or the other but the the experience for the user.

Andy Whiteside: was simply they turn it on it comes right up to let’s say the citrix workspace APP that’s all you can log into you log into that you hit your citrix environment, you get out of that or disconnect from and it logs you back out.

Andy Whiteside: very minimal experience what we found with customers who needed more advanced functionality, where they truly needed a thin operating system, but not a zero operating system.

Andy Whiteside: Is where they need to actually log in to the thin client first the thin client operating system.

Andy Whiteside: And then, they need to go from there, wherever they go, it could be web Apps to be you see of flavor extra flavor why and we found that we really needed people to login in a.

Andy Whiteside: More enterprise way and that’s where something like active directory, which is you know curb rose space system from back in the day from Microsoft still really very, very relevant it’s like the phone book right it knows who.

Andy Whiteside: knows what your device operating system is knows who you are.

Andy Whiteside: knows what your password for both is and how you should be coming into the system and even does things to proactively like change the machine account password.

Andy Whiteside: I think we’re going to talk about here and tell me if i’m wrong is that we need that you’re gonna help us understand how that works and how we bring a system into an active directory world as a machine account.

Sebastien Perusat: yeah I would go maybe not that far, because the machine account, in that case wouldn’t match directly, we are really focusing in how to login into the active directory by using.

Sebastien Perusat: By using username and password coming from the active directory, though, the goal of this active directory part of our configuration is.

Sebastien Perusat: Obviously, first of all to give a little bit more security, since we released that have no six version i’m just jumping to that because it was one main argument of the active directory topic before 1106 that as soon as you brought up an agile device, it will go directly into the desktop.

Sebastien Perusat: So even if the address is safe and we have a lot of security layers you are still some malicious people on the desktop and you could start, something which is already there.

Sebastien Perusat: So.

Andy Whiteside: yeah and you’re and you’re assuming, which is more often than not, or almost 100% accurate that that device is now at a desktop and has access to maybe some basic Apps maybe a browser APP maybe a command line APP.

Andy Whiteside: you’ll see a lie and it’s plugged into or wireless wirelessly connected to that important resource of the companies, which is the network right, we want to we don’t want just let them jump right on the network like them.

Sebastien Perusat: he’s like i’m.

Sebastien Perusat: Adding also some sorry good.

Chris Feeney: No, I just want to say so, I think you were referring to earlier said, you are not joining I jell O s to the active directory domain it doesn’t becoming machine object.

Chris Feeney: Like you would a normal windows machine so for those windows admins out there, active directory admins that are kind of used to that type of thing that’s not what’s happening here if you’ve ever i’m going to bring up our.

Chris Feeney: Competition, unfortunately, because this is the most equivalent thing I can think of right, but if you’ve ever seen delfin ios you can turn on a login screen but you’re not joining that to the domain.

Chris Feeney: you’re just pointing it at some authentication source and that’s what’s happening with I jail.

Chris Feeney: I mean you’re welcome to create a domain object out there, you can do that, but it’s not going to be relevant because you’re not using any of that to manage the.

Chris Feeney: device is still going to be you, Ms maybe that’s pretty well known, but I suspect there may be some confusion out there, so I bring it up.

Chris Feeney: So, and then of course there’s and while we’re talking here and he’s browsing the difference between a user versus a computer object so.

Andy Whiteside: Is it possible, is it possible to associate the machine with active directory or it’s always just going to be the user and I gels use cases.

Sebastien Perusat: How the moment it’s only the user only.

Sebastien Perusat: On we have some requests or we had some requests coming from the market to join a some azure.

Sebastien Perusat: Active directory is etc, and we have also some enterprise level customers who wanted to have that feature.

Sebastien Perusat: But I would say, in most cases, as soon as we showed how the US is working now the profiles are working.

Sebastien Perusat: The domain join wasn’t required anymore, so we have this it’s not covered there because it’s something that we have not enabled by default, but to have this real real D.

Sebastien Perusat: Which is the ability to join computer to the active directory, even if it’s an Linux device which would work in specific cases, but it’s not part of what we call today so.

Sebastien Perusat: We might have something that that in the future, but for the moment it’s really just logging into dexterity like Chris mentioned.

Andy Whiteside: user.

00:08:31.260 –> 00:08:33.420
00:08:34.470 –> 00:08:44.430
00:08:45.900 –> 00:09:00.780
00:09:02.130 –> 00:09:10.230
00:09:10.680 –> 00:09:22.680
00:09:23.430 –> 00:09:29.430
00:09:31.110 –> 00:09:32.070
00:09:32.970 –> 00:09:34.650
00:09:36.150 –> 00:09:36.570
00:09:37.110 –> 00:09:39.000
00:09:39.240 –> 00:09:48.150
00:09:48.600 –> 00:09:57.990
00:09:59.040 –> 00:10:03.630
00:10:04.080 –> 00:10:05.190
00:10:07.500 –> 00:10:11.070
00:10:12.480 –> 00:10:20.250
00:10:20.610 –> 00:10:27.450
00:10:27.870 –> 00:10:33.120
00:10:33.570 –> 00:10:41.370
00:10:42.030 –> 00:10:57.090
00:10:57.390 –> 00:11:02.670
00:11:03.930 –> 00:11:13.620
00:11:14.430 –> 00:11:25.320
00:11:25.740 –> 00:11:35.700
00:11:36.750 –> 00:11:37.980
00:11:39.390 –> 00:11:52.590
00:11:53.100 –> 00:12:01.740
00:12:02.160 –> 00:12:20.610
00:12:21.270 –> 00:12:26.610
00:12:27.150 –> 00:12:27.990
00:12:29.100 –> 00:12:37.770
00:12:38.610 –> 00:12:49.680
00:12:49.950 –> 00:13:01.170
00:13:01.470 –> 00:13:07.770
00:13:09.030 –> 00:13:14.250
00:13:16.110 –> 00:13:27.900
00:13:28.950 –> 00:13:29.880
00:13:31.080 –> 00:13:47.400
00:13:47.670 –> 00:13:55.860
00:13:56.280 –> 00:14:05.220
00:14:06.060 –> 00:14:21.000
00:14:22.020 –> 00:14:24.840
00:14:25.860 –> 00:14:35.940
00:14:37.530 –> 00:14:47.490
00:14:48.090 –> 00:15:01.500
00:15:02.670 –> 00:15:14.430
00:15:14.700 –> 00:15:15.090
00:15:15.120 –> 00:15:15.630
00:15:15.720 –> 00:15:24.360
00:15:26.010 –> 00:15:28.890
00:15:29.520 –> 00:15:39.240
00:15:40.200 –> 00:15:49.080
00:15:49.530 –> 00:15:55.650
00:15:56.280 –> 00:16:06.750
00:16:08.190 –> 00:16:19.800
00:16:21.030 –> 00:16:21.780
00:16:23.610 –> 00:16:31.200
00:16:32.250 –> 00:16:46.860
00:16:48.210 –> 00:16:53.160
00:16:53.580 –> 00:17:01.680
00:17:02.190 –> 00:17:20.040
00:17:21.090 –> 00:17:26.280
00:17:27.060 –> 00:17:42.450
00:17:43.320 –> 00:17:48.210
00:17:49.260 –> 00:17:56.490
00:17:57.390 –> 00:18:06.690
00:18:07.380 –> 00:18:16.020
00:18:17.460 –> 00:18:18.960
00:18:19.320 –> 00:18:28.500
00:18:31.020 –> 00:18:39.120
00:18:40.740 –> 00:18:43.290
00:18:44.250 –> 00:18:54.930
00:18:57.780 –> 00:19:09.660
00:19:11.100 –> 00:19:17.910
00:19:18.360 –> 00:19:29.280
00:19:30.030 –> 00:19:46.650
00:19:47.670 –> 00:20:02.040
00:20:02.550 –> 00:20:11.310
00:20:11.820 –> 00:20:27.480
00:20:29.040 –> 00:20:35.760
00:20:36.510 –> 00:20:48.990
00:20:49.830 –> 00:20:58.350
00:20:59.460 –> 00:21:21.660
00:21:22.830 –> 00:21:31.260
00:21:31.980 –> 00:21:41.250
00:21:42.210 –> 00:21:53.250
00:21:53.790 –> 00:22:03.690
00:22:04.770 –> 00:22:24.150
00:22:25.290 –> 00:22:39.840
00:22:41.400 –> 00:22:49.740
00:22:50.160 –> 00:23:01.380
00:23:04.500 –> 00:23:12.870
00:23:13.770 –> 00:23:24.600
00:23:25.200 –> 00:23:35.220
00:23:35.670 –> 00:23:42.360
00:23:43.290 –> 00:23:59.010
00:24:03.330 –> 00:24:04.680
00:24:05.400 –> 00:24:09.930
00:24:11.400 –> 00:24:16.650
00:24:16.920 –> 00:24:23.130
00:24:23.400 –> 00:24:35.220
00:24:35.970 –> 00:24:56.190
00:24:57.210 –> 00:25:09.180
00:25:09.540 –> 00:25:21.780
00:25:22.920 –> 00:25:24.300
00:25:25.350 –> 00:25:35.070
00:25:35.070 –> 00:25:35.250
00:25:35.820 –> 00:25:38.010
00:25:38.850 –> 00:25:40.230
00:25:40.440 –> 00:25:45.510
00:25:47.970 –> 00:25:59.040
00:25:59.640 –> 00:26:00.390
00:26:00.930 –> 00:26:04.500
00:26:05.880 –> 00:26:14.730
00:26:15.270 –> 00:26:24.720
00:26:26.040 –> 00:26:36.750
00:26:38.070 –> 00:26:46.500
00:26:47.010 –> 00:26:58.230
00:26:58.860 –> 00:27:14.580
00:27:16.500 –> 00:27:20.310
00:27:20.880 –> 00:27:30.390
00:27:31.020 –> 00:27:41.310
00:27:42.750 –> 00:27:43.170

Sebastien Perusat: So just a smart in for myself, because I know that I lost a little bit of my ass on some curious at the beginning and I wasn’t even sure where to look at.

Sebastien Perusat: yeah that’s I just met a screenshot of my lab so everything that i’m seeing something like that, under Jim posting that configuration window where i’m referring to, and in 99% of the cases as soon as this configuration is corrected the complete path was education is, what can I expect.

Andy Whiteside: i’m sorry to hear what.

Andy Whiteside: He lost a little bit of your what.

Your first.

Sebastien Perusat: yeah yeah like by the FCC.

Chris Feeney: Very careful.

Andy Whiteside: These things I always have to check a box, whether it’s explicit or not, and I never have had to check that box and now because it says he’s on linkedin.

Sebastien Perusat: So sorry.

Chris Feeney: yeah.

Chris Feeney: Well, we have a lot of fun here we just gotta Be careful boys and girls.

Chris Feeney: No, no, I was gonna ask you.

Andy Whiteside: That one doesn’t count.

Andy Whiteside: i’m sure that.

Chris Feeney: I mean there’s worse things that have been on TV but uh I was gonna ask you do you touch on the domain realm mapping.

Sebastien Perusat: and

Chris Feeney: In the.

Chris Feeney: US yeah it’s honestly i’m trying remember if I ever had to use that in any circumstance and nothing’s coming to mind right now but it’s out there certainly maybe somebody on the Community has had to deal with that, but.

Chris Feeney: anyways lori’s let’s move on.

Sebastien Perusat: No, I didn’t call it, but.

Sebastien Perusat: I must admit that i’m the same page and Q Chris didn’t have to do so much with that, I mean I know it there, and I hope that in the moment we have a customer in front of me.

Sebastien Perusat: With wanting to other feature integrity can speak with them and give him the feelings that I understand what he’s referring to.

Sebastien Perusat: But, to be honest.

Sebastien Perusat: I never had to deal with that.

Sebastien Perusat: that’s The short answer.

Chris Feeney: No problem there’s a lot of what we have 7000 features in your mess i’m sure we’ve only touched on, maybe 200.

Sebastien Perusat: yeah definitely.

Andy Whiteside: I know what we’re going to talk about may sound trivial to people, but the ability to enable a.

Andy Whiteside: password protected via username active directory username and password screen lock.

Andy Whiteside: It does it’s like a necessity, every time you do a project that includes this sub you want to talk through this part of the the video that you created.

Sebastien Perusat: Yes, for sure.

Sebastien Perusat: that’s I would say it’s.

Sebastien Perusat: Especially actually with 11 or six version, one of the main advantages of the active directory login on the end on.

Sebastien Perusat: Let me just cover one thing which is only a playable on citrix if I remember right we already have a feature which is called synchronize citrix passwords that mean that even if you’re not using the active directory login.

Sebastien Perusat: And you just put up into the depths of your stature citrix session you’re leaving your workspace for lunchtime, and you don’t have a specific hotkey pre configured by your actual presets people which lock the endpoint.

Andy Whiteside: Well, hold on says, assuming I use your does that hockey so let’s just assume they don’t.

Sebastien Perusat: Because they don’t exactly.

Sebastien Perusat: Go ahead exactly so you leave your your workspace and, obviously, your session will be there on to the citrix time what will hit.

Sebastien Perusat: But that’s sometimes pretty long can be half an hour an hour sometimes not configured at all, or maybe removed for some reasons and what we do, there is, we synchronize the active directory password that you enter the citrix workspace client with a local screen.

Sebastien Perusat: So even if you’re not using the negative territory you’re still able to have the screensaver from I just starting.

Sebastien Perusat: And having your personal active directory password to unlock the screensaver.

Andy Whiteside: So said you’re actually thinking that or you’re just calling on that.

Sebastien Perusat: Note there it there it’s definitely something but but it’s not related to that topic directly what we’re looking at at the moment because it’s not relate to as the active directory login process.

Sebastien Perusat: i’m just telling you that there is this feature this configuration on the citrix storefront plugin now would you can activate even if you’re not using the active directory level.

Sebastien Perusat: Okay, do you know what is the same.

Sebastien Perusat: Like the active directory login but without having that pre identification.

Sebastien Perusat: mechanism happen.

Andy Whiteside: Okay that’s good to know i’ve been in that situation before I know how to solve that where you.

Andy Whiteside: You need to be able to lock the screen, but you don’t want to give everybody you don’t want to use the same generic local password to unlock it yeah you’re saying it syncs with the Ad password so that I guess it can read your ad password and bring that down local or.

Sebastien Perusat: Yes, modest, I mean, I will not go into detail because it’s it’s a really complex process, but just.

Sebastien Perusat: In a few words we modified a little bit the citrix workspace a plugin mechanism, and then we were able to use.

Sebastien Perusat: Still encrypted and secure your password with the times of need to re enter it somewhere and that’s that is macadam that is doing the synchronize password look like I said it’s only on citrix, just in case on the horizon, on a dp is not there okay.

Andy Whiteside: So that’s a way to get around the the need of needing to lock the screen, so people can you know sneaker net behind you.

Andy Whiteside: You know just browse up behind you when you’re going to the bathroom or lunch or whatever.

Andy Whiteside: But a better, more holistic way of managing the experiences to have you use the your active directory username password and pass that through and then use that to unlock the screen lock, which I think we’re going next.

Sebastien Perusat: yeah exactly.

Chris Feeney: So I was thinking that that’s feature i’m looking at it now it’s under sessions citrix citrix global storefront login synchronized citrix password with screen lock.

Chris Feeney: That would be something you would use if you have not already set up an ad off into Idaho.

Chris Feeney: So there’s typical boot up I tell you get to that I Joe desktop and then you log into citrix from there.

Chris Feeney: But you want to put a screen lock on that’s what that it would be, for we should probably have a session on that at some point so back to this scheduled program keep keep moving along here sorry.

Sebastien Perusat: Thank you very much for for completing that.

Sebastien Perusat: This cleanup password in general, so coming to the active directory topic again we have the ability to use that feature still.

Sebastien Perusat: That Chris just mentioned, with the synchronized password but, in our case we’re just it’s a standard way so as soon as you start your screen.

Sebastien Perusat: It will automatically use the active directory login mechanism so as soon as let’s say five minutes after leaving your your workspace.

Sebastien Perusat: Your screen separate starting, you will have to enter the active directory path that he was in for us using it in the password field, and then you are not your PC.

Sebastien Perusat: But now let’s imagine that you as an administrator needs an access to the desktop so you have let’s say some maintenance that you want to achieve and you need an access to the to the endpoint.

Sebastien Perusat: that’s something that you can configure under user interface screen lock, and they are you have a specific option on the option which is called is clean up password that you can create.

Sebastien Perusat: And this password is obviously, but that is 90 plus two audio endpoints of be extremely careful with the kind of Pennsylvania up there.

Sebastien Perusat: But it would give you as an administrator the ability to unlock the local edge operating platform to do something about it mandatory to have it in SA but it just sometimes the best practice, yes.

Andy Whiteside: So, have you covered something briefly, which was Okay, when you set a screen like policy by default if the users logging in with active directory they’re gonna be able to unlock that screen lock using that what you’re talking about here is.

Andy Whiteside: A workaround in case the administrator of the ideal environment needs to walk up and unlock it because you know somebody locked in and he needs to get in this is that that global local universal back nano coated back door, but override.

Sebastien Perusat: Exactly yes.

Andy Whiteside: Okay, great.

Sebastien Perusat: that’s more or less it on the screen up passwords like I said is still one of the main feature of the active directory again that you want me to use if you’re not on citrix i’m just mentioning our next topic that i’m looking at the list is a local user forum agency.

Sebastien Perusat: I must say that to retest it because I had a couple of issues in.

Sebastien Perusat: Earlier burdens on 10 Oh, I guess, it was until six and then never tried it again on a seven or four, five and six, which you mentioned the following.

Sebastien Perusat: The device booting up into the active directory login mask and you have not 100 devices that you want to manage locally, because you want to check some stuff.

Sebastien Perusat: You would have to log in every time was active directory login which is pretty easy if you are coming from the same company, if your your Internet service he.

Andy Whiteside: said, let me Let me set this up for you real quick isn’t the world of windows right it’s it’s good to use active directory.

Andy Whiteside: group policy manager to push out a local user with a local username and password that your whole team knows that you can systematically change and manage through active directory, but this is kind of the.

Andy Whiteside: The way the workstation workstation admins always have a way to get into a system even maybe if it’s offline or something yeah the good practice not often done but a good practice.

Sebastien Perusat: definitely yes so that’s what we try to cover it in that in the next section.

Sebastien Perusat: let’s imagine the field service know, coming from a company, and you will not give some external workers some active directory login just to look into an endpoint.

Sebastien Perusat: that’s one approach now thought the thought is maybe but 10 other approaches, where you will need to look at user but that’s the first that came to my mind.

Sebastien Perusat: And there we have the ability to use a local user that you can configure in our profile.

Sebastien Perusat: The standard configuration and that’s something that you might expect, as soon as you see the login screen front manager, there is a small other users on the bottom left part of your of just cream.

Sebastien Perusat: My expectation, I have been to click on that enter the user user, which is in case, our local you with a matter of us and enter no password or maybe the password user and I would be able to login.

Sebastien Perusat: It will not function, so you can’t do that that’s the reason why we have a specific feature which is again on the security and again under log on, and again in the same submenu like the active directory, which is called local user.

Sebastien Perusat: And if you remember that we set a specific password it just before and the screen lock feature, you can say hey give the local he was the same password.

Sebastien Perusat: Like the screener password that you created just before on your profile so as soon as we did that just enable this local log on screen lock password for the local user, you will be able to login into the agile rise operating platform, without having to enter an active directory.

Sebastien Perusat: that’s good for emergency reasons can be a great reason for updating, we can do that locally, for your field service, maybe offer local it administrator charity on site.

Andy Whiteside: yeah I love it, I mean one of my first jobs, and it was i’ve run around updating a bunch of workstations one of the time.

Andy Whiteside: And I had a local user ID that I would use and it took me years to realize how this systematically man and system had a local user ID that you know was correct everywhere, I went.

Andy Whiteside: At some point, I worked with a really smart guy and I saw him do it and it all made sense that’s exactly what you’re doing here.

Sebastien Perusat: that’s one of the let’s say 10 or 15 different approach web this configuration makes sense.

Andy Whiteside: But your advice is not to make that password like simple 123 right you want to make it somewhat hard to guess and and and probably change it every so often.

Sebastien Perusat: Absolutely, and even if it’s let’s say not extremely dangerous to have that password leaked, I would even recommend to create a master profile for that matter, profiles, just as a short reminder is the highest priority of proof of that we haven’t yet told us.

Sebastien Perusat: which cannot be overwritten by a standard profile and which cannot be edited by a non administrator your misuse or like I said it’s not mandatory, but my best practice would say hey as soon as it hits a password.

Sebastien Perusat: Remote access, like the shadowing function depending from the customer, where we are speaking to i’m recommending to use the mass of cool feature but that’s another topic, but absolutely yes.

Chris Feeney: I would concur with that.

Chris Feeney: yeah definitely I would concur for a global settings and master profile is a very nice feature, by the way, it is not on, by default, you have to go into a mess and turn on that as well as the template stuff.

Chris Feeney: That you could leverage, so one example, for me the master profile, I have a standard location where I point all my firmware updates to.

Chris Feeney: So that always has that address said it never changes and then, what does change, I have a template where i’m pointing at.

Chris Feeney: different versions of firmware so I just you know, create a new value for that and that plugs into that one little spot on the firmware updates so.

Chris Feeney: You could use master profiles for all kinds of things, but a bit of password or security baseline profile would probably be a great example of use case there.

Sebastien Perusat: To present yes definitely provide for that specific use case.

Andy Whiteside: So said I kind of moved forward a little bit.

Andy Whiteside: And you’re the very end here and you’re actually showing in this video how to understand the legend of what it means for a machine, the list of certain way, and you, Ms.

Andy Whiteside: All this time I never realized this thing was even here and.

Andy Whiteside: And i’ve always just kind of been guessing and too lazy to go look it up and well there, it is the way just to look and see what the different colored screens and icons mean in us.

Sebastien Perusat: And that’s just a small piece of information that we haven’t actually your mess, but, just in case I want to mention it, because.

Sebastien Perusat: Besides the fact that a lot of people are not knowing the differences between the different icons slicing magenta color or the orange for the update.

Sebastien Perusat: You still have the ability, without going to the kb that agile.com website to open the legend locally in the US.

Sebastien Perusat: Justice more features that was introduced, I can’t remember and five or nine or six one I can’t remember when, but if you go to help and two legends that menu.

Sebastien Perusat: You will get accomplished, the east of the icon and what they mean and especially if you look at, if we look at the future we’re talking today about the active directory login.

Sebastien Perusat: You will see inside of you, if your device is let’s say in use by someone that mean that is not in the active directory login mask.

Sebastien Perusat: Or if it isn’t the active active directory login my switch would have to you as an administrator to say hey I need to push an update in lunchtime.

Sebastien Perusat: The user is not logged in on the end point, there was a high probability that he’s not working at the moment, come on just hit update.

Sebastien Perusat: without having to interrupt the engine because he’s not about the working and this small legends really helping a lot of our customers to better understand the state of the endpoint.

Chris Feeney: yeah that’s a great point on that is a.

Chris Feeney: If you haven’t seen it, you should definitely go check it out, because it is.

Chris Feeney: I think it wasn’t really a large fanfare feature, I would say, but it is when you see it and it’s color coded really nice, I mean it really kind of help you fully understand what are those icon colors actually mean.

Chris Feeney: case in point, I never saw the black one right the black one says the device has never been connected how it got to that spot I can’t remember but i’ve seen that before and.

Chris Feeney: i’ve tried.

Sebastien Perusat: Can you give an example, if you like.

Chris Feeney: Sure yeah go ahead, the.

Sebastien Perusat: The easiest way to reproduce, that is, you have an import your csv file, or you create the end on the right click devices new things new endpoint.

Sebastien Perusat: To hit a new device, and as soon as you enter their the MAC address of the device that you might have.

Sebastien Perusat: One month to joining your your mess so without having the need to activate the enabled automatic registration without mechanism for the device will stay black until the moment where it first connect to your mess.

Chris Feeney: So sort of like a pre populating of devices and then they come in and then I can map up and obviously license and from there okay exactly.

Andy Whiteside: Because i’m jump in here and talk about you know I gel the company, the the amount of stuff I learned on every one of these calls just kind of reinforces the idea that this is.

Andy Whiteside: This is, I gels business, this is what I gel does and and when you try to compare it to another product out there, that that you know doesn’t focus on nuance like this.

Andy Whiteside: it’s not even close it’s just you i’m five years into this idol experience of mine and i’m still learning stuff a ton of stuff.

Andy Whiteside: All the time I was, I was a have a machine behind me here this morning that used to be ideal had to convert it to something else for some testing and.

Andy Whiteside: I just don’t get to play in the eye gel I tell us world my team now runs are you, Ms server I you know.

Andy Whiteside: I would love to get in and play with this stuff more it’s just not my job anymore, but always impressed with how I Joe has features that i’m I didn’t know I needed but it’s in here and there, it is right in my face.

Chris Feeney: yeah i’m sitting here, looking at some of these things, and especially as we were going through some of the ad local login kind of setup and i’m like thinking to myself that I run into a customer situation where I said no, and the answer was actually yes, because I just didn’t know.

Andy Whiteside: i’m that’s what i’m saying I i’ve had experiences not past like I don’t think you can do that, and now I found out, you can Am I go I was.

Chris Feeney: Right yeah.

Chris Feeney: well.

Chris Feeney: If you’re not sure I guess the short answer is maybe, let me check okay to get it it’s okay to get back to somebody.

Chris Feeney: But.

Andy Whiteside: Well, I think I don’t know and the next step next step is, let me call SEB and find out.

Chris Feeney: he’s on linkedin let me hit him up.

Andy Whiteside: You guys seem to know all this stuff know where it’s buried, I mean i’ve had great resources that I do still do it man said this constantly shows me something new every every one of these calls.

Sebastien Perusat: Between that.

Andy Whiteside: said, you want to move to North Carolina and come hang out with us i’ll put you to the office, right here, right here.

Sebastien Perusat: And just give you already give you one arm with with linkedin don’t ask for the second time there’s something would happen.

Sebastien Perusat: I kind of promised that again.

Chris Feeney: The weather’s nice here nice a great time even.

Andy Whiteside: Though I won’t ask again for another week.

Sebastien Perusat: that’s right perfect.

Chris Feeney: The crowd is going to be like.

Chris Feeney: That graph is going to show up on this by guess stop trying to take my guy.

Andy Whiteside: When I say take it like I said, having come see you.

that’s right.

Chris Feeney: it’s a relocation right he works for Joe he just happens to be in North.

Chris Feeney: Carolina now.

Chris Feeney: Exactly so.

Andy Whiteside: Alright guys well, I appreciate the time today i’ve got a i’ve got to move on to my other job, which is, I gotta go meet with the Bank and find out how to.

Andy Whiteside: fund more money for my service now practice, so I I go from being kind of the interviewer of awesome technical resources, like you, guys to begging the Bank to give me some more money.

Chris Feeney: i’ll do your thing man do your thing.

Chris Feeney: And look forward to.

Chris Feeney: Another one of these in a couple weeks we added a couple more topics we could probably deeply dive into for next time or future one so.

Andy Whiteside: If you’re out there listening look for an eye gel disrupt somewhere near you.

Sebastien Perusat: Absolutely, yes, this one is Frankfurt in two days, I will be there.

Andy Whiteside: Alright guys.

Chris Feeney: Thanks thanks Andy.

Sebastien Perusat: Thanks settings again have a good week.