﻿<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://owl.unipharm.com/mediawiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Aaront</id>
	<title>uniWIKI - User contributions [en]</title>
	<link rel="self" type="application/atom+xml" href="https://owl.unipharm.com/mediawiki/api.php?action=feedcontributions&amp;feedformat=atom&amp;user=Aaront"/>
	<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php/Special:Contributions/Aaront"/>
	<updated>2026-09-01T13:43:05Z</updated>
	<subtitle>User contributions</subtitle>
	<generator>MediaWiki 1.35.4</generator>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Adobe_Creative_Cloud_for_Teams&amp;diff=13959</id>
		<title>Information Systems:Adobe Creative Cloud for Teams</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Adobe_Creative_Cloud_for_Teams&amp;diff=13959"/>
		<updated>2021-06-21T18:01:53Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Notes */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Configuration==&lt;br /&gt;
uniPHARM has an Adobe Creative Cloud for Teams monthly subscription (4 users). The current usernames/passwords are:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Username !! Password !! Activation 1 !! Activation 2 || Notes&lt;br /&gt;
|-&lt;br /&gt;
| adobecc@unipharm.com || !NewVisionIT2051 || - || - || Used for billing only&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser1@unipharm.com || NewVisionIT2051|| teresab1 || - || Adobe Creative Cloud License&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser2@unipharm.com || NewVisionIT2051|| donnak1|| - || Adobe Creative Cloud License&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser3@unipharm.com || NewVisionIT2051! || aaront || angelac1 || Adobe Acrobat Pro License only&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser4@unipharm.com || NewVisionIT2051 || || || No license. &lt;br /&gt;
|-&lt;br /&gt;
| ralphl@unipharm.com || same as windows login|| |||| Adobe Acrobat Pro License only&lt;br /&gt;
|-&lt;br /&gt;
| nancyn@unipharm.com || same as outlook login || |||| Adobe Acrobat Pro License only&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Notes==&lt;br /&gt;
* During exchange deployment, ccmediauser* emails are now aliased to it@unipahrm.com&lt;br /&gt;
* June 2021, Adobe individual IDs created and assigned for Nancy and Ralph. &lt;br /&gt;
* 11:27, 25 May 2020 (PDT) Adobe Sign is an Acrobat module for e-signatures. Because Nancy and Ralph use this feature under ccmediauser4, this email address is now being forwarded to nancyn@unipharm.com. There are many alerts generated as part of the audit trail during the esignature document lifecycle.&lt;br /&gt;
* (Dec. 13, 2018) When signing in to the 3rd computer, Adobe CC now lets you sign another user out directly from said computer in order to free up a license/seat. It's a neat feature, and all but an official confirmation that &lt;br /&gt;
they understand people will use their licenses in revolving manner.&lt;br /&gt;
* On November 26, 2018 Darren created a new Adobe account because we changed from a monthly-credit-card-paying subscription to a yearly-purchase-order subscription.  The new yearly purchase reduced the number of Creative Cloud licenses from 4 to 2 and added a quantity of 1 for Acrobat Pro.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Desktop Software]]&lt;br /&gt;
[[Category: Adobe]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Adobe_Creative_Cloud_for_Teams&amp;diff=13958</id>
		<title>Information Systems:Adobe Creative Cloud for Teams</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Adobe_Creative_Cloud_for_Teams&amp;diff=13958"/>
		<updated>2021-06-21T17:58:08Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Configuration */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Configuration==&lt;br /&gt;
uniPHARM has an Adobe Creative Cloud for Teams monthly subscription (4 users). The current usernames/passwords are:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Username !! Password !! Activation 1 !! Activation 2 || Notes&lt;br /&gt;
|-&lt;br /&gt;
| adobecc@unipharm.com || !NewVisionIT2051 || - || - || Used for billing only&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser1@unipharm.com || NewVisionIT2051|| teresab1 || - || Adobe Creative Cloud License&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser2@unipharm.com || NewVisionIT2051|| donnak1|| - || Adobe Creative Cloud License&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser3@unipharm.com || NewVisionIT2051! || aaront || angelac1 || Adobe Acrobat Pro License only&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser4@unipharm.com || NewVisionIT2051 || || || No license. &lt;br /&gt;
|-&lt;br /&gt;
| ralphl@unipharm.com || same as windows login|| |||| Adobe Acrobat Pro License only&lt;br /&gt;
|-&lt;br /&gt;
| nancyn@unipharm.com || same as outlook login || |||| Adobe Acrobat Pro License only&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Notes==&lt;br /&gt;
* June 2021, Adobe individual IDs created and assigned for Nancy and Ralph. &lt;br /&gt;
* 11:27, 25 May 2020 (PDT) Adobe Sign is an Acrobat module for e-signatures. Because Nancy and Ralph use this feature under ccmediauser4, this email address is now being forwarded to nancyn@unipharm.com. There are many alerts generated as part of the audit trail during the esignature document lifecycle.&lt;br /&gt;
* (Dec. 13, 2018) When signing in to the 3rd computer, Adobe CC now lets you sign another user out directly from said computer in order to free up a license/seat. It's a neat feature, and all but an official confirmation that &lt;br /&gt;
they understand people will use their licenses in revolving manner.&lt;br /&gt;
* On November 26, 2018 Darren created a new Adobe account because we changed from a monthly-credit-card-paying subscription to a yearly-purchase-order subscription.  The new yearly purchase reduced the number of Creative Cloud licenses from 4 to 2 and added a quantity of 1 for Acrobat Pro.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Desktop Software]]&lt;br /&gt;
[[Category: Adobe]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Adobe_Creative_Cloud_for_Teams&amp;diff=13957</id>
		<title>Information Systems:Adobe Creative Cloud for Teams</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Adobe_Creative_Cloud_for_Teams&amp;diff=13957"/>
		<updated>2021-06-21T17:51:45Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Notes */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Configuration==&lt;br /&gt;
uniPHARM has an Adobe Creative Cloud for Teams monthly subscription (4 users). The current usernames/passwords are:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Username !! Password !! Activation 1 !! Activation 2 || Notes&lt;br /&gt;
|-&lt;br /&gt;
| adobecc@unipharm.com || !NewVisionIT2051 || - || - || Used for billing only&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser1@unipharm.com || NewVisionIT2051|| teresab1 || - || Adobe Creative Cloud License&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser2@unipharm.com || NewVisionIT2051|| donnak1|| - || Adobe Creative Cloud License&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser3@unipharm.com || NewVisionIT2051! || aaront || angelac1 || Adobe Acrobat Pro License only&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser4@unipharm.com || NewVisionIT2051 || || || Adobe Acrobat Pro Licence only. Used for Adobe Sign.&lt;br /&gt;
|-&lt;br /&gt;
| ralphl@unipharm.com || same as windows login|| |||| Adobe Acrobat Pro License only&lt;br /&gt;
|-&lt;br /&gt;
| nancyn@unipharm.com || same as outlook login || |||| Adobe Acrobat Pro License only&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Notes==&lt;br /&gt;
* June 2021, Adobe individual IDs created and assigned for Nancy and Ralph. &lt;br /&gt;
* 11:27, 25 May 2020 (PDT) Adobe Sign is an Acrobat module for e-signatures. Because Nancy and Ralph use this feature under ccmediauser4, this email address is now being forwarded to nancyn@unipharm.com. There are many alerts generated as part of the audit trail during the esignature document lifecycle.&lt;br /&gt;
* (Dec. 13, 2018) When signing in to the 3rd computer, Adobe CC now lets you sign another user out directly from said computer in order to free up a license/seat. It's a neat feature, and all but an official confirmation that &lt;br /&gt;
they understand people will use their licenses in revolving manner.&lt;br /&gt;
* On November 26, 2018 Darren created a new Adobe account because we changed from a monthly-credit-card-paying subscription to a yearly-purchase-order subscription.  The new yearly purchase reduced the number of Creative Cloud licenses from 4 to 2 and added a quantity of 1 for Acrobat Pro.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Desktop Software]]&lt;br /&gt;
[[Category: Adobe]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_365_Billing&amp;diff=13953</id>
		<title>Information Systems:Microsoft 365 Billing</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_365_Billing&amp;diff=13953"/>
		<updated>2021-06-15T23:25:57Z</updated>

		<summary type="html">&lt;p&gt;Aaront: Created page with &amp;quot;In order to add another mailbox or active user to our Microsoft 365, we need to purchase an additional license from the cdw site.  csp.cdw.ca, each member of the IT staff has...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;In order to add another mailbox or active user to our Microsoft 365, we need to purchase an additional license from the cdw site. &lt;br /&gt;
csp.cdw.ca, each member of the IT staff has their own login and should be able to add or remove licenses from here. It should be noted that the vendor did say that reducing the number of licenses is more involved if we pay per year. &lt;br /&gt;
&lt;br /&gt;
From there the licenses should become available in our M365admin center to be assigned.&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Adobe_Creative_Cloud_for_Teams&amp;diff=13952</id>
		<title>Information Systems:Adobe Creative Cloud for Teams</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Adobe_Creative_Cloud_for_Teams&amp;diff=13952"/>
		<updated>2021-06-15T19:27:29Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Configuration==&lt;br /&gt;
uniPHARM has an Adobe Creative Cloud for Teams monthly subscription (4 users). The current usernames/passwords are:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Username !! Password !! Activation 1 !! Activation 2 || Notes&lt;br /&gt;
|-&lt;br /&gt;
| adobecc@unipharm.com || !NewVisionIT2051 || - || - || Used for billing only&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser1@unipharm.com || NewVisionIT2051|| teresab1 || - || Adobe Creative Cloud License&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser2@unipharm.com || NewVisionIT2051|| donnak1|| - || Adobe Creative Cloud License&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser3@unipharm.com || NewVisionIT2051! || aaront || angelac1 || Adobe Acrobat Pro License only&lt;br /&gt;
|-&lt;br /&gt;
| ccmediauser4@unipharm.com || NewVisionIT2051 || || || Adobe Acrobat Pro Licence only. Used for Adobe Sign.&lt;br /&gt;
|-&lt;br /&gt;
| ralphl@unipharm.com || same as windows login|| |||| Adobe Acrobat Pro License only&lt;br /&gt;
|-&lt;br /&gt;
| nancyn@unipharm.com || same as outlook login || |||| Adobe Acrobat Pro License only&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Notes==&lt;br /&gt;
* 11:27, 25 May 2020 (PDT) Adobe Sign is an Acrobat module for e-signatures. Because Nancy and Ralph use this feature under ccmediauser4, this email address is now being forwarded to nancyn@unipharm.com. There are many alerts generated as part of the audit trail during the esignature document lifecycle.&lt;br /&gt;
* (Dec. 13, 2018) When signing in to the 3rd computer, Adobe CC now lets you sign another user out directly from said computer in order to free up a license/seat. It's a neat feature, and all but an official confirmation that &lt;br /&gt;
they understand people will use their licenses in revolving manner.&lt;br /&gt;
* On November 26, 2018 Darren created a new Adobe account because we changed from a monthly-credit-card-paying subscription to a yearly-purchase-order subscription.  The new yearly purchase reduced the number of Creative Cloud licenses from 4 to 2 and added a quantity of 1 for Acrobat Pro.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Desktop Software]]&lt;br /&gt;
[[Category: Adobe]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Staff_Onboarding_How-To&amp;diff=13951</id>
		<title>Information Systems:Staff Onboarding How-To</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Staff_Onboarding_How-To&amp;diff=13951"/>
		<updated>2021-06-15T16:52:14Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Extra things to check */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This page outlines the process for setting up a new Unipharm employee / staff member.&lt;br /&gt;
&lt;br /&gt;
Main areas where user profiles have to be defined or linked to AD/green-screen profiles:&lt;br /&gt;
* Active Directory domain user&lt;br /&gt;
* IBM i user profile (green-screen/Mocha access)&lt;br /&gt;
* ASW profile for IBM i user&lt;br /&gt;
* UNITY user profile&lt;br /&gt;
* MS365 Mailbox &lt;br /&gt;
* Moodle user (linked to AD user)&lt;br /&gt;
* Unipharm wiki user (linked to AD user)&lt;br /&gt;
* WiNG wireless (staff WiFi)&lt;br /&gt;
* Kofax scanning profile, if applicable (linked to AD user)&lt;br /&gt;
* DocView permissions (IBM i user profile)&lt;br /&gt;
* Xerox scanning profile, if applicable&lt;br /&gt;
&lt;br /&gt;
==Instructions==&lt;br /&gt;
* Create AD user, verify group membership if copying another user, or set manually. &lt;br /&gt;
* Use Navigator or green screen to create IBM i user profile. Also copy existing user for convenience.&lt;br /&gt;
* Go into UNITY (green-screen), System Administration -&amp;gt; OMM Menus -&amp;gt; Work with User Security (if prompted for password, just press Enter back out and wait for a few moments then go back in to find the person on the list).&lt;br /&gt;
* Position to or search for existing user to be used a template, use 8 beside the entry to copy user into a new UNITY user matching green-screen username.&lt;br /&gt;
* Configure MA (menu authority) for new user by entering MA beside their name. F10 to copy from existing user. Leave Menu name blank and just enter the source and target user profiles to copy all menu authorities.&lt;br /&gt;
* Configure FA (functional authority) using FA beside the name. To copy from existing user, type 'USR' in '''Type''', and the source user profile in '''Qualifier'''. Press Enter, and you should see a comparison of the source and target functional authorities. Use F19 (shift F7) to grant missing.&lt;br /&gt;
* Configure ASW user profile [[Information Systems: ASW User Security|using these instructions]]&lt;br /&gt;
&lt;br /&gt;
==Extra things to check==&lt;br /&gt;
Depending on the role of the new employee, the following may also need to be checked and configured in advance:&lt;br /&gt;
&lt;br /&gt;
* Mapped drives&lt;br /&gt;
* Permissions to send to Notes distribution lists&lt;br /&gt;
* SRFax&lt;br /&gt;
*Build RF, Build RET&lt;br /&gt;
*http://owl.unipharm.local/mediawiki/index.php/Information_Systems:Extension_User_Security&lt;br /&gt;
* If there is uncertainty on whether the account has what it needs ( specifically for RF admins, there is no harm in showing the profile to a supervisory to ensure the best experience for the new staff)&lt;br /&gt;
* [[Information Systems:ASW favorites (menu items)|ASW favorites (menu items)]]&lt;br /&gt;
&lt;br /&gt;
[[Category: Staff On-boarding]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Staff_Onboarding_How-To&amp;diff=13950</id>
		<title>Information Systems:Staff Onboarding How-To</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Staff_Onboarding_How-To&amp;diff=13950"/>
		<updated>2021-06-15T16:25:19Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This page outlines the process for setting up a new Unipharm employee / staff member.&lt;br /&gt;
&lt;br /&gt;
Main areas where user profiles have to be defined or linked to AD/green-screen profiles:&lt;br /&gt;
* Active Directory domain user&lt;br /&gt;
* IBM i user profile (green-screen/Mocha access)&lt;br /&gt;
* ASW profile for IBM i user&lt;br /&gt;
* UNITY user profile&lt;br /&gt;
* MS365 Mailbox &lt;br /&gt;
* Moodle user (linked to AD user)&lt;br /&gt;
* Unipharm wiki user (linked to AD user)&lt;br /&gt;
* WiNG wireless (staff WiFi)&lt;br /&gt;
* Kofax scanning profile, if applicable (linked to AD user)&lt;br /&gt;
* DocView permissions (IBM i user profile)&lt;br /&gt;
* Xerox scanning profile, if applicable&lt;br /&gt;
&lt;br /&gt;
==Instructions==&lt;br /&gt;
* Create AD user, verify group membership if copying another user, or set manually. &lt;br /&gt;
* Use Navigator or green screen to create IBM i user profile. Also copy existing user for convenience.&lt;br /&gt;
* Go into UNITY (green-screen), System Administration -&amp;gt; OMM Menus -&amp;gt; Work with User Security (if prompted for password, just press Enter back out and wait for a few moments then go back in to find the person on the list).&lt;br /&gt;
* Position to or search for existing user to be used a template, use 8 beside the entry to copy user into a new UNITY user matching green-screen username.&lt;br /&gt;
* Configure MA (menu authority) for new user by entering MA beside their name. F10 to copy from existing user. Leave Menu name blank and just enter the source and target user profiles to copy all menu authorities.&lt;br /&gt;
* Configure FA (functional authority) using FA beside the name. To copy from existing user, type 'USR' in '''Type''', and the source user profile in '''Qualifier'''. Press Enter, and you should see a comparison of the source and target functional authorities. Use F19 (shift F7) to grant missing.&lt;br /&gt;
* Configure ASW user profile [[Information Systems: ASW User Security|using these instructions]]&lt;br /&gt;
&lt;br /&gt;
==Extra things to check==&lt;br /&gt;
Depending on the role of the new employee, the following may also need to be checked and configured in advance:&lt;br /&gt;
&lt;br /&gt;
* Mapped drives&lt;br /&gt;
* Permissions to send to Notes distribution lists&lt;br /&gt;
* SRFax&lt;br /&gt;
*Build RF, Build RET&lt;br /&gt;
*http://owl.unipharm.local/mediawiki/index.php/Information_Systems:Extension_User_Security&lt;br /&gt;
* [[Information Systems:ASW favorites (menu items)|ASW favorites (menu items)]]&lt;br /&gt;
&lt;br /&gt;
[[Category: Staff On-boarding]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Staff_Onboarding_How-To&amp;diff=13949</id>
		<title>Information Systems:Staff Onboarding How-To</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Staff_Onboarding_How-To&amp;diff=13949"/>
		<updated>2021-06-14T22:45:09Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Extra things to check */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This page outlines the process for setting up a new Unipharm employee / staff member.&lt;br /&gt;
&lt;br /&gt;
Main areas where user profiles have to be defined or linked to AD/green-screen profiles:&lt;br /&gt;
* Active Directory domain user&lt;br /&gt;
* IBM i user profile (green-screen/Mocha access)&lt;br /&gt;
* ASW profile for IBM i user&lt;br /&gt;
* UNITY user profile&lt;br /&gt;
* MS365 Mailbox &lt;br /&gt;
* Moodle user (linked to AD user)&lt;br /&gt;
* Unipharm wiki user (linked to AD user)&lt;br /&gt;
* WiNG wireless (staff WiFi)&lt;br /&gt;
* Kofax scanning profile, if applicable (linked to AD user)&lt;br /&gt;
* DocView permissions (IBM i user profile)&lt;br /&gt;
* Xerox scanning profile, if applicable&lt;br /&gt;
&lt;br /&gt;
==Instructions==&lt;br /&gt;
* Create AD user, verify group membership if copying another user, or set manually. &lt;br /&gt;
* Use Navigator or green screen to create IBM i user profile. Also copy existing user for convenience.&lt;br /&gt;
* Go into UNITY (green-screen), System Administration -&amp;gt; OMM Menus -&amp;gt; Work with User Security (if prompted for password, just press Enter).&lt;br /&gt;
* Position to or search for existing user to be used a template, use 8 beside the entry to copy user into a new UNITY user matching green-screen username.&lt;br /&gt;
* Configure MA (menu authority) for new user by entering MA beside their name. F10 to copy from existing user. Leave Menu name blank and just enter the source and target user profiles to copy all menu authorities.&lt;br /&gt;
* Configure FA (functional authority) using FA beside the name. To copy from existing user, type 'USR' in '''Type''', and the source user profile in '''Qualifier'''. Press Enter, and you should see a comparison of the source and target functional authorities. Use F19 (shift F7) to grant missing.&lt;br /&gt;
* Configure ASW user profile [[Information Systems: ASW User Security|using these instructions]]&lt;br /&gt;
&lt;br /&gt;
==Extra things to check==&lt;br /&gt;
Depending on the role of the new employee, the following may also need to be checked and configured in advance:&lt;br /&gt;
&lt;br /&gt;
* Mapped drives&lt;br /&gt;
* Permissions to send to Notes distribution lists&lt;br /&gt;
* SRFax&lt;br /&gt;
*Build RF, Build RET&lt;br /&gt;
*http://owl.unipharm.local/mediawiki/index.php/Information_Systems:Extension_User_Security&lt;br /&gt;
* [[Information Systems:ASW favorites (menu items)|ASW favorites (menu items)]]&lt;br /&gt;
&lt;br /&gt;
[[Category: Staff On-boarding]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:VoIP_Phone_Configuration&amp;diff=13948</id>
		<title>Information Systems:VoIP Phone Configuration</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:VoIP_Phone_Configuration&amp;diff=13948"/>
		<updated>2021-06-11T16:38:53Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* 3CX Windows client */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This article discusses the user-facing side of the phone system including deskphones, cordless phones, and headsets.&lt;br /&gt;
&lt;br /&gt;
==Administration==&lt;br /&gt;
===Initial Setup===&lt;br /&gt;
====Deskphone Setup (Yealink)====&lt;br /&gt;
* The first step when configuring a new phone desk phone is to unbox and label the phone to its extension. &lt;br /&gt;
* The second step is to determine what port it will be plugged into , meaning which port on which switch it plugs into. &lt;br /&gt;
* Tag The port switch port&lt;br /&gt;
* Plug the phone into the local port &lt;br /&gt;
* Log into 3cx&lt;br /&gt;
* Under the phones tab find the new phone by extension &lt;br /&gt;
* Hit assign extension&lt;br /&gt;
* Use Lan at the office &lt;br /&gt;
* Use Interface 192.168.44.2&lt;br /&gt;
* Log into the phone interface and set the phone with a static IP? (maybe)&lt;br /&gt;
&lt;br /&gt;
====Cordless (DECT) Base and Phone Setup====&lt;br /&gt;
web link to general setup https://www.3cx.com/sip-phones/manually-provision-yealink-dect/&lt;br /&gt;
&lt;br /&gt;
* unbox the base and handset &lt;br /&gt;
* plug the base into switch &lt;br /&gt;
* navigate to the 3cx management page &lt;br /&gt;
* under the advanced tab select FXS/DECT&lt;br /&gt;
* add the base using the mac address to the list of bases already present.&lt;br /&gt;
* use the interface 192.168.44.2&lt;br /&gt;
* copy the provisioning link provided here in the general tab&lt;br /&gt;
* define the extensions in the extensions tab&lt;br /&gt;
* navigate to the ip address of the wireless base&lt;br /&gt;
* navigate to settings and auto configuration , use the provisioning link copied before in the space for server URL&lt;br /&gt;
* confirm, auto provision now.&lt;br /&gt;
* to add a phone to a base, press and hold the wifi button on the base until the top light starts to flash, then on the handset select register and they will find each other.&lt;br /&gt;
*username is admin, and the password for the base is found on the FS/Dect page for the base.&lt;br /&gt;
*The handsets are managed by the base on the accounts page. In a case where you are just replacing a non functioning unit, use the settings( Register name/username/password) from the unit you are going to replace. Disable the account of the non functioning unit and enable the new handset on a new account.&lt;br /&gt;
&lt;br /&gt;
====DECT Repeater Setup====&lt;br /&gt;
*Setting up a repeater requires a dect base, handset that is paired to that base and the repeater itself.&lt;br /&gt;
*from a paired handset navigate to settings and put it into repeater mode, choosing the type of repeater. &lt;br /&gt;
*the base will automatically reset when the paired handset is put into repeater mode,  wait for the base to come online &lt;br /&gt;
*connect the repeater to power &lt;br /&gt;
*hold down the pairing button on the base until the phone light starts to flash&lt;br /&gt;
*press the pairing button on the repeater. &lt;br /&gt;
* the dect light should go from red to orange when it finds the base.&lt;br /&gt;
&lt;br /&gt;
''There is one repeater in the recieving mezzannine, and one in large down''&lt;br /&gt;
&lt;br /&gt;
====3CX Windows client====&lt;br /&gt;
The 3cx windows client is installed by the I.T staff, configuration requires the config file from the welcome email. Dragging and dropping is all that should be needed to configure the client. &lt;br /&gt;
&lt;br /&gt;
The client is user profile based, meaning if another staff logs into their profile on a workstation that has the client configured on another profile it will not load their configuration.&lt;br /&gt;
&lt;br /&gt;
====3CX App (iOS/Android)====&lt;br /&gt;
&lt;br /&gt;
These apps are available to download from their respective stores. A QR code is sent to a user when their client is configured and they may use that to search the app and load their profile. &lt;br /&gt;
&lt;br /&gt;
Once connected it is important to remind the user that it will use cellular data if wifi is not available.&lt;br /&gt;
&lt;br /&gt;
===Firmware updates===&lt;br /&gt;
The Yealink deskphones and DECT bases require firmware updates. The firmware for the deskphones can and should only be updated through 3CX. This is because there is specific, 3CX-certified firmware which is different (and often lags behind) what Yealink generally releases. The firmware is auto-downloaded into the 3CX system as a part of its auto-updater. Once newer firmware is auto-downloaded into the repository, the system displays a warning for applicable phones that are now out of date. The firmware can be pushed from the 3CX console. This will reboot the phone and reset any user customizations that are not managed through 3CX. For example, the ringtone is manageable through 3CX, but the ''Display Clock'' within ''Screensaver'', is not.&lt;br /&gt;
&lt;br /&gt;
==Supported deployment configurations==&lt;br /&gt;
This section discusses the different configurations that are in use currently. Originally there were only 2 standard configurations (office and warehouse employees), but the situation evolved rapidly due to COVID/WFH. In particular, the softphones, web client and mobile app have become part of standard usage, in some cases replacing the use of deskphones entirely e.g. Customer Service.&lt;br /&gt;
&lt;br /&gt;
====General (in-office)====&lt;br /&gt;
:'''''Setup 1 (office):''''' Yealink deskphone, EPOS wireless headset via USB (connected to deskphone)&lt;br /&gt;
:'''''Setup 2 (warehouse):''''' Yealink cordless DECT phone&lt;br /&gt;
:'''''Setup 3 (certain staff):''''' 3CX Web Client, EPOS wireless headset via USB (connected to computer)&lt;br /&gt;
:'''''Optional components:''''' 3CX Web Client, 3CX App (mobile)&lt;br /&gt;
&lt;br /&gt;
Setup 1 was the original setup for all office users, and involves a Yealink deskphone (T54W) and, for staff using a headset, an EPOS SD-Pro Or D10 DECT headset connected to the phone via USB. &lt;br /&gt;
&lt;br /&gt;
Some staff who have been exposed to either the web client or mobile app (due to WFH or other means) continue to use these in-office for the additional features. For example, some warehouse supervisors use the mobile app instead of the cordless phone.&lt;br /&gt;
&lt;br /&gt;
====WFH (except Customer Service)====&lt;br /&gt;
:'''''Setup:''''' 3CX Web Client and 3CX App (mobile)&lt;br /&gt;
:'''''Additional components: ''''' 3CX Browser Extension for Chrome or Edge (Chromium-based)&lt;br /&gt;
&lt;br /&gt;
When working from home, the web client is the recommended deployment for office staff that are not in Customer Service. Theoretically, the web client is more performant through the WAN compared to the softphone as it uses WebRTC rather than SIP/RTP (I think...). Being browser-accessible, the web client is also simpler to deploy and maintain than the Windows client. &lt;br /&gt;
&lt;br /&gt;
====Customer Service====&lt;br /&gt;
:'''''Setup 1: ''''' 3CX for Windows softphone, EPOS Connect, 3CX Plugin for EPOS&lt;br /&gt;
:'''''Setup 2 (WFH): ''''' 3CX for Windows softphone (through RDP), Poly/Plantronics C3220 USB headset (USB pass-through), Plantronics Hub Software (supports 3CX integration)&lt;br /&gt;
:'''''Additional components: ''''' Kuando BusyLight&lt;br /&gt;
&lt;br /&gt;
The '''3CX for Windows''' softphone (a.k.a. desktop client) has become the preferred deployment for Customer Service agents, along with the headset connected directly to the computer. This is true whether in-office or WFH. Call control and other features are enabled through the EPOS Connect softaware and the 3CX Plugin for EPOS. While the headset could theoretically work in plug-and-play mode, both of these need to be installed for a smooth experience.&lt;br /&gt;
&lt;br /&gt;
This software communicates to the server via the main LAN, which is different from the deskphones that [[Information_Systems:VoIP_LAN_configuration |communicate on the VoIP VLAN]].&lt;br /&gt;
&lt;br /&gt;
For historical reference, the original deployment for CS agents involved a deskphone (including a sidecar attachment for the receptionist), and a wireless headset connected to the deskphone via USB. The deskphone introduced another vendor into the equation - Yealink, which in turn presented limitations due to only a subset of features on the deskphone being interoperable with 3CX. For example, the deskphone neither displays call queue information nor Away status for other users.&lt;br /&gt;
&lt;br /&gt;
TBC -[[User:Norwinu|norwizzle]] ([[User talk:Norwinu|talk]])&lt;br /&gt;
&lt;br /&gt;
[[Category: Phone System]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:VoIP_Phone_Configuration&amp;diff=13947</id>
		<title>Information Systems:VoIP Phone Configuration</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:VoIP_Phone_Configuration&amp;diff=13947"/>
		<updated>2021-06-11T16:35:04Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* 3CX App (iOS/Android) */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This article discusses the user-facing side of the phone system including deskphones, cordless phones, and headsets.&lt;br /&gt;
&lt;br /&gt;
==Administration==&lt;br /&gt;
===Initial Setup===&lt;br /&gt;
====Deskphone Setup (Yealink)====&lt;br /&gt;
* The first step when configuring a new phone desk phone is to unbox and label the phone to its extension. &lt;br /&gt;
* The second step is to determine what port it will be plugged into , meaning which port on which switch it plugs into. &lt;br /&gt;
* Tag The port switch port&lt;br /&gt;
* Plug the phone into the local port &lt;br /&gt;
* Log into 3cx&lt;br /&gt;
* Under the phones tab find the new phone by extension &lt;br /&gt;
* Hit assign extension&lt;br /&gt;
* Use Lan at the office &lt;br /&gt;
* Use Interface 192.168.44.2&lt;br /&gt;
* Log into the phone interface and set the phone with a static IP? (maybe)&lt;br /&gt;
&lt;br /&gt;
====Cordless (DECT) Base and Phone Setup====&lt;br /&gt;
web link to general setup https://www.3cx.com/sip-phones/manually-provision-yealink-dect/&lt;br /&gt;
&lt;br /&gt;
* unbox the base and handset &lt;br /&gt;
* plug the base into switch &lt;br /&gt;
* navigate to the 3cx management page &lt;br /&gt;
* under the advanced tab select FXS/DECT&lt;br /&gt;
* add the base using the mac address to the list of bases already present.&lt;br /&gt;
* use the interface 192.168.44.2&lt;br /&gt;
* copy the provisioning link provided here in the general tab&lt;br /&gt;
* define the extensions in the extensions tab&lt;br /&gt;
* navigate to the ip address of the wireless base&lt;br /&gt;
* navigate to settings and auto configuration , use the provisioning link copied before in the space for server URL&lt;br /&gt;
* confirm, auto provision now.&lt;br /&gt;
* to add a phone to a base, press and hold the wifi button on the base until the top light starts to flash, then on the handset select register and they will find each other.&lt;br /&gt;
*username is admin, and the password for the base is found on the FS/Dect page for the base.&lt;br /&gt;
*The handsets are managed by the base on the accounts page. In a case where you are just replacing a non functioning unit, use the settings( Register name/username/password) from the unit you are going to replace. Disable the account of the non functioning unit and enable the new handset on a new account.&lt;br /&gt;
&lt;br /&gt;
====DECT Repeater Setup====&lt;br /&gt;
*Setting up a repeater requires a dect base, handset that is paired to that base and the repeater itself.&lt;br /&gt;
*from a paired handset navigate to settings and put it into repeater mode, choosing the type of repeater. &lt;br /&gt;
*the base will automatically reset when the paired handset is put into repeater mode,  wait for the base to come online &lt;br /&gt;
*connect the repeater to power &lt;br /&gt;
*hold down the pairing button on the base until the phone light starts to flash&lt;br /&gt;
*press the pairing button on the repeater. &lt;br /&gt;
* the dect light should go from red to orange when it finds the base.&lt;br /&gt;
&lt;br /&gt;
''There is one repeater in the recieving mezzannine, and one in large down''&lt;br /&gt;
&lt;br /&gt;
====3CX Windows client====&lt;br /&gt;
====3CX App (iOS/Android)====&lt;br /&gt;
&lt;br /&gt;
These apps are available to download from their respective stores. A QR code is sent to a user when their client is configured and they may use that to search the app and load their profile. &lt;br /&gt;
&lt;br /&gt;
Once connected it is important to remind the user that it will use cellular data if wifi is not available.&lt;br /&gt;
&lt;br /&gt;
===Firmware updates===&lt;br /&gt;
The Yealink deskphones and DECT bases require firmware updates. The firmware for the deskphones can and should only be updated through 3CX. This is because there is specific, 3CX-certified firmware which is different (and often lags behind) what Yealink generally releases. The firmware is auto-downloaded into the 3CX system as a part of its auto-updater. Once newer firmware is auto-downloaded into the repository, the system displays a warning for applicable phones that are now out of date. The firmware can be pushed from the 3CX console. This will reboot the phone and reset any user customizations that are not managed through 3CX. For example, the ringtone is manageable through 3CX, but the ''Display Clock'' within ''Screensaver'', is not.&lt;br /&gt;
&lt;br /&gt;
==Supported deployment configurations==&lt;br /&gt;
This section discusses the different configurations that are in use currently. Originally there were only 2 standard configurations (office and warehouse employees), but the situation evolved rapidly due to COVID/WFH. In particular, the softphones, web client and mobile app have become part of standard usage, in some cases replacing the use of deskphones entirely e.g. Customer Service.&lt;br /&gt;
&lt;br /&gt;
====General (in-office)====&lt;br /&gt;
:'''''Setup 1 (office):''''' Yealink deskphone, EPOS wireless headset via USB (connected to deskphone)&lt;br /&gt;
:'''''Setup 2 (warehouse):''''' Yealink cordless DECT phone&lt;br /&gt;
:'''''Setup 3 (certain staff):''''' 3CX Web Client, EPOS wireless headset via USB (connected to computer)&lt;br /&gt;
:'''''Optional components:''''' 3CX Web Client, 3CX App (mobile)&lt;br /&gt;
&lt;br /&gt;
Setup 1 was the original setup for all office users, and involves a Yealink deskphone (T54W) and, for staff using a headset, an EPOS SD-Pro Or D10 DECT headset connected to the phone via USB. &lt;br /&gt;
&lt;br /&gt;
Some staff who have been exposed to either the web client or mobile app (due to WFH or other means) continue to use these in-office for the additional features. For example, some warehouse supervisors use the mobile app instead of the cordless phone.&lt;br /&gt;
&lt;br /&gt;
====WFH (except Customer Service)====&lt;br /&gt;
:'''''Setup:''''' 3CX Web Client and 3CX App (mobile)&lt;br /&gt;
:'''''Additional components: ''''' 3CX Browser Extension for Chrome or Edge (Chromium-based)&lt;br /&gt;
&lt;br /&gt;
When working from home, the web client is the recommended deployment for office staff that are not in Customer Service. Theoretically, the web client is more performant through the WAN compared to the softphone as it uses WebRTC rather than SIP/RTP (I think...). Being browser-accessible, the web client is also simpler to deploy and maintain than the Windows client. &lt;br /&gt;
&lt;br /&gt;
====Customer Service====&lt;br /&gt;
:'''''Setup 1: ''''' 3CX for Windows softphone, EPOS Connect, 3CX Plugin for EPOS&lt;br /&gt;
:'''''Setup 2 (WFH): ''''' 3CX for Windows softphone (through RDP), Poly/Plantronics C3220 USB headset (USB pass-through), Plantronics Hub Software (supports 3CX integration)&lt;br /&gt;
:'''''Additional components: ''''' Kuando BusyLight&lt;br /&gt;
&lt;br /&gt;
The '''3CX for Windows''' softphone (a.k.a. desktop client) has become the preferred deployment for Customer Service agents, along with the headset connected directly to the computer. This is true whether in-office or WFH. Call control and other features are enabled through the EPOS Connect softaware and the 3CX Plugin for EPOS. While the headset could theoretically work in plug-and-play mode, both of these need to be installed for a smooth experience.&lt;br /&gt;
&lt;br /&gt;
This software communicates to the server via the main LAN, which is different from the deskphones that [[Information_Systems:VoIP_LAN_configuration |communicate on the VoIP VLAN]].&lt;br /&gt;
&lt;br /&gt;
For historical reference, the original deployment for CS agents involved a deskphone (including a sidecar attachment for the receptionist), and a wireless headset connected to the deskphone via USB. The deskphone introduced another vendor into the equation - Yealink, which in turn presented limitations due to only a subset of features on the deskphone being interoperable with 3CX. For example, the deskphone neither displays call queue information nor Away status for other users.&lt;br /&gt;
&lt;br /&gt;
TBC -[[User:Norwinu|norwizzle]] ([[User talk:Norwinu|talk]])&lt;br /&gt;
&lt;br /&gt;
[[Category: Phone System]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Symantec_Endpoint_Protection&amp;diff=13946</id>
		<title>Information Systems:Symantec Endpoint Protection</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Symantec_Endpoint_Protection&amp;diff=13946"/>
		<updated>2021-06-10T21:35:32Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;SEPM – Symantec Endpoint Protection Manager&lt;br /&gt;
&lt;br /&gt;
Symantec Endpoint Protection is the anti-virus and anti-malware application that is used at UWD.  SEP provides a barrier for malware on all desktops, laptops and Windows based servers.  The application needs to have its license renewed every February and the cost of the license is determined by the number of seats needed.  As of November of 2013, the number of seats needed is 70.  The actual number of used seats is about 65 but there needs to be some extra for spare or temporary computers.&lt;br /&gt;
The client application is controlled by SEP Manager which is installed on the Smithers server.  SEPM is responsible for controlling the configuration, maintenance and deployment of the SEP clients.  SEPM also is responsible for downloading the anti-virus and anti-malware definitions and then distributing them to the SEP clients.&lt;br /&gt;
&lt;br /&gt;
The specific configuration of SEP is extremely important and absolutely critical to the software working correctly.  The default factory configuration of the SEP client is too restrictive and will prevent UWD staff from being productive.  The SEP client consists of modules that have different functions.  The only modules that are needed by UWD are the anti-virus and anti-malware modules.  Other modules such as the Symantec firewall are not needed because they conflict with the built in firewall that is included in Windows.&lt;br /&gt;
The configuration of the SEP clients is also not change-able by restricted Windows users.  The settings for turning off and on the SEP client and how it behaves is locked out to the SEPM program only.  The reason for this is to prevent a virus from having the ability to disable the SEP client.&lt;br /&gt;
&lt;br /&gt;
The SEP clients are configured to query SEPM for new definitions once per hour each day.  If new definitions are available they are distributed from SEPM which downloads them directly from Symantec.  Having only SEPM query Symantec for definitions saves on network bandwidth.&lt;br /&gt;
&lt;br /&gt;
The SEP clients are configured to do a complete anti-virus scan of all files on the local hard drive each day at 5AM.  It is set to occur at that time because the scan is processor intensive and would be disruptive to users if it was set to run during the work day.  In the case of laptops that are usually not powered on at 5AM, the scan occurs when the machine is on and at idle and the scan runs at a low intensity for a longer period.&lt;br /&gt;
&lt;br /&gt;
When a virus or malware touches the local file system or the memory of desktop/laptop/server, the SEP client will try to halt that process and present a pop up window to the user telling them to stop what they are doing and contact the IT department.  The SEP client is configured to first try to delete the virus but if it can’t do that, it will try to quarantine it.  If possible the SEP client will communicate to SEPM about the infection.  SEPM will then notify IT by email that an infection occurred and on what machine.&lt;br /&gt;
It is up to the IT administrator to determine if the infection is first real or a false positive, and then how to properly clean out the virus if SEP hasn’t already done it.  The only way to be 100% positive that a virus is gone is to re-image the computer.  This erases the entire hard drive and restores the user profile from the Superserver.  Re-imaging is not always convenient but for some cases it is the quickest method to restore from a real virus infection.  The safety of the corporate network is paramount and sometimes it is just the best method to wipe the machine and restore the OS image.&lt;br /&gt;
&lt;br /&gt;
SEPM is capable of producing some useful reports on which computers have the latest definitions and the rates and types of infections.  SEPM is also the recommended starting point to deploy the SEP client to desktops/laptops/servers.  The configuration settings in SEPM are integrated into a client package and then sent over the network to install remotely on the computer.  SEPM then instructs the client to reboot if needed.  Doing deployments in this method makes sure that the client gets the right settings and the latest definitions in one step.  Upgraded versions of the SEP client can also be deployed this way and do not require IT staff to walk around to each work station.&lt;br /&gt;
&lt;br /&gt;
SEPM can be access from the Smithers desktop directly or from the web administration page at&lt;br /&gt;
https://smithers.unipharm.local:8443/console/apps/sepm&lt;br /&gt;
&lt;br /&gt;
Technical support is part of the license with first level being off shore based and second level located in Oregon.  The phone number for technical support is 1-800-721-3934 and is available 24/7.  The support technician will need a license number and that can be found on the license certificate document that is emailed to IT when the license is renewed each year.&lt;br /&gt;
&lt;br /&gt;
==CHANGELOG==&lt;br /&gt;
*As of Feb-05-2020 mysymentec is the way to reach out to them , https://support.symantec.com/us/en.html is the url and the username password have been added to the password list. &lt;br /&gt;
*As of march-01-20 Broadcom has taken ownership of support , the above link and credentials have been migrated tot he broadcom site by aaront&lt;br /&gt;
*AS OF MAY2021 &lt;br /&gt;
*SYMANTEC ENDPOINT MANAGER VERSION IS 14&lt;br /&gt;
*CLIENT VERSIONS FOR WORKSTATIONS IS 14&lt;br /&gt;
*CLIENT VERSIONS FOR SERVERS IS 12&lt;br /&gt;
*Client packages located on SUPERSERVER|UWDSOFTWARE|SYMANTEC&lt;br /&gt;
*SYMANTEC DIAGNOSTIC TOOL located on SUPERSERVER|UWDSOFTWARE|SYMANTEC&lt;br /&gt;
&lt;br /&gt;
[[Category: Servers - Software]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Windows_Admin_Centre_WAC&amp;diff=13945</id>
		<title>Information Systems:Windows Admin Centre WAC</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Windows_Admin_Centre_WAC&amp;diff=13945"/>
		<updated>2021-06-10T18:33:56Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;WAC is a free program that helps centrally manage windows devices, it is very useful in our non enterprise environment. &lt;br /&gt;
&lt;br /&gt;
How it is deployed and configured will be added here, in its current state it is able to connect to the windows workstations that have the GPO to enable the WS-Management service running called enable WinRM.&lt;br /&gt;
&lt;br /&gt;
It is not yet configured to administer the servers but should be done.&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Windows_Admin_Centre_WAC&amp;diff=13944</id>
		<title>Information Systems:Windows Admin Centre WAC</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Windows_Admin_Centre_WAC&amp;diff=13944"/>
		<updated>2021-06-10T18:33:08Z</updated>

		<summary type="html">&lt;p&gt;Aaront: Created page with &amp;quot;WAC is a free program that helps centrally manage windows devices, it is very useful in our non enterprise environment.   How it is deployed and configured will be added here,...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;WAC is a free program that helps centrally manage windows devices, it is very useful in our non enterprise environment. &lt;br /&gt;
&lt;br /&gt;
How it is deployed and configured will be added here, in its current state it is able to connect to the windows workstations that have the GPO to enable the WS-Management service running on the destination, WinRM.&lt;br /&gt;
&lt;br /&gt;
It is not yet configured to administer the servers but should be done.&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:WSUS&amp;diff=13902</id>
		<title>Information Systems:WSUS</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:WSUS&amp;diff=13902"/>
		<updated>2021-05-31T21:37:37Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;WSUS – Windows Software Update Service&lt;br /&gt;
&lt;br /&gt;
The WSUS application is provided to IT administrators for free from Microsoft.  The application is installed on the Smithers server, on top of its Windows Server 2012R2 operating system.  The purpose of the WSUS application is to provide a managed local version of the Windows Updates website that consumers use to get patches from Microsoft.  WSUS presents all of the patches that have been created by Microsoft for all of its products going back at least 14 years.  Since it is not practical to download everything for all products, WSUS allows an IT administrator to choose not only which products get patches, but also which patches get applied to client machines.&lt;br /&gt;
The client machines ( in the context of WSUS )include all desktops and laptops plus all the Windows based servers.  The client machines are configured to query the WSUS application based on settings applied from GPO objects in Active Directory.  Machines not connected to AD don’t use WSUS.&lt;br /&gt;
&lt;br /&gt;
The GPO settings instruct the client machines to query the WSUS application every 4 hours for any new patches.  If there are patches, then they are downloaded right away and set to install at midnight of whichever day the patches were given authorization to install.  The one exception to that is for the Windows servers.  They download the patches when they are detected and then install on Saturday at midnight.  In most cases one or more patches will require a reboot and that happens automatically after the last patch is installed for the server or the desktops/laptops.  If the laptop, for example, is powered off, the patches get installed the next day when it is turned on.&lt;br /&gt;
Microsoft publishes patches and updates on the first Tuesday of every month.  The number of patches and updates do vary but sometimes there are many and it may be advisable and wise to delay the installation of them for a week or two, to allow Microsoft to fix any defects in the published patches.  Critical security patches that fix vulnerabilities by “unauthenticated remote attackers” should be installed as soon as possible.&lt;br /&gt;
&lt;br /&gt;
It is important to review the patches and updates that are published by Microsoft each month.  Even though WSUS is currently configured to only present patches for products we use, there are instances where a particular version of a product or an architecture of a product does not apply.  When that happens, that patch or update can be declined from the WSUS GUI.  Patches that don’t apply to any of our machines should not be downloaded to the WSUS database because they only take up valuable hard drive space.  An example of this is when an update to Internet Explorer is published for the Itanium architecture.  Since we have no servers with Itanium processors, that patch should be declined and not downloaded.&lt;br /&gt;
&lt;br /&gt;
Other Important Information&lt;br /&gt;
&lt;br /&gt;
*	Dictionary updates for Microsoft Office should be declined because they take up very large amounts of hard drive space ( on Smithers ) which is disproportional to their usefulness&lt;br /&gt;
*	Once per year, the superseded updates need to be removed from the WSUS database.  The command for this is inside the settings GUI&lt;br /&gt;
*	It is important to remove old decommissioned computers from the WSUS GUI as well as place newly installed computers into the correct WSUS group&lt;br /&gt;
*	It is very rare that new Microsoft products are installed at UWD, but when they are, the corresponding product needs to be added into WSUS, otherwise it will not be recognized as needing updates.  Same goes for when old Microsoft products are removed – they need to be removed from WSUS to save on disk space.&lt;br /&gt;
*	There is no technical support from Microsoft for WSUS as it is a free product.  There are many public websites that contain useful tips and those are the only available option for sorting out technical problems.  That being said, WSUS is highly reliable and is the industry standard for enterprise grade patching of Microsoft software.  If an IT administrator is not using WSUS, then they are doing it wrong.&lt;br /&gt;
*       Microsoft has changed functionality in WSUS installed on Server 2012R2 for Windows10 clients.  Make sure that if we deploy Windows10 clients they are getting the right patches in the correct manner from the WSUS server&lt;br /&gt;
* Feature updates have a .esd file extension, and therefore for IIS to pass it along, .esd needs to be added to the MIME file types on the WSUS server. &lt;br /&gt;
&lt;br /&gt;
[[Category: Desktops/Company Workstations]]&lt;br /&gt;
[[Category: System Administration]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Cannot_Close_Inbound_Shipment-Purchase_Order_Locked_by_Another_User&amp;diff=13892</id>
		<title>Information Systems:Cannot Close Inbound Shipment-Purchase Order Locked by Another User</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Cannot_Close_Inbound_Shipment-Purchase_Order_Locked_by_Another_User&amp;diff=13892"/>
		<updated>2021-05-27T22:00:31Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;When a user opens a PO in 'Work with Purchase Orders', the PO header records in file SROORPHE is flagged, so that no other process will attempt to update it until the first user is finished.  If 'Work with Purchase Orders' does not complete properly, that flag is left on, so that the record remains locked.  (Note - a software lock; not a system lock.)&lt;br /&gt;
&lt;br /&gt;
Use [[Information Systems:DFU]] on file SRBPOH in library UP1480BFVA to clear the field 'WSID'.&lt;br /&gt;
&lt;br /&gt;
When I position to the file, then put 18 in front of it, it takes me to a page that asks for the production order and the order number. Order number is what the user will give you and production number needs to be figured out. &lt;br /&gt;
&lt;br /&gt;
[[Category: Receiving Problems (I.T.)]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:VoIP_Phone_Configuration&amp;diff=13877</id>
		<title>Information Systems:VoIP Phone Configuration</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:VoIP_Phone_Configuration&amp;diff=13877"/>
		<updated>2021-05-27T17:51:03Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Cordless (DECT) Base and Phone Setup */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This article discusses the user-facing side of the phone system including deskphones, cordless phones, and headsets.&lt;br /&gt;
&lt;br /&gt;
==Administration==&lt;br /&gt;
===Initial Setup===&lt;br /&gt;
====Deskphone Setup (Yealink)====&lt;br /&gt;
* The first step when configuring a new phone desk phone is to unbox and label the phone to its extension. &lt;br /&gt;
* The second step is to determine what port it will be plugged into , meaning which port on which switch it plugs into. &lt;br /&gt;
* Tag The port switch port&lt;br /&gt;
* Plug the phone into the local port &lt;br /&gt;
* Log into 3cx&lt;br /&gt;
* Under the phones tab find the new phone by extension &lt;br /&gt;
* Hit assign extension&lt;br /&gt;
* Use Lan at the office &lt;br /&gt;
* Use Interface 192.168.44.2&lt;br /&gt;
* Log into the phone interface and set the phone with a static IP? (maybe)&lt;br /&gt;
&lt;br /&gt;
====Cordless (DECT) Base and Phone Setup====&lt;br /&gt;
web link to general setup https://www.3cx.com/sip-phones/manually-provision-yealink-dect/&lt;br /&gt;
&lt;br /&gt;
* unbox the base and handset &lt;br /&gt;
* plug the base into switch &lt;br /&gt;
* navigate to the 3cx management page &lt;br /&gt;
* under the advanced tab select FXS/DECT&lt;br /&gt;
* add the base using the mac address to the list of bases already present.&lt;br /&gt;
* use the interface 192.168.44.2&lt;br /&gt;
* copy the provisioning link provided here in the general tab&lt;br /&gt;
* define the extensions in the extensions tab&lt;br /&gt;
* navigate to the ip address of the wireless base&lt;br /&gt;
* navigate to settings and auto configuration , use the provisioning link copied before in the space for server URL&lt;br /&gt;
* confirm, auto provision now.&lt;br /&gt;
* to add a phone to a base, press and hold the wifi button on the base until the top light starts to flash, then on the handset select register and they will find each other.&lt;br /&gt;
*username is admin, and the password for the base is found on the FS/Dect page for the base.&lt;br /&gt;
*The handsets are managed by the base on the accounts page. In a case where you are just replacing a non functioning unit, use the settings( Register name/username/password) from the unit you are going to replace. Disable the account of the non functioning unit and enable the new handset on a new account.&lt;br /&gt;
&lt;br /&gt;
====DECT Repeater Setup====&lt;br /&gt;
*Setting up a repeater requires a dect base, handset that is paired to that base and the repeater itself.&lt;br /&gt;
*from a paired handset navigate to settings and put it into repeater mode, choosing the type of repeater. &lt;br /&gt;
*the base will automatically reset when the paired handset is put into repeater mode,  wait for the base to come online &lt;br /&gt;
*connect the repeater to power &lt;br /&gt;
*hold down the pairing button on the base until the phone light starts to flash&lt;br /&gt;
*press the pairing button on the repeater. &lt;br /&gt;
* the dect light should go from red to orange when it finds the base.&lt;br /&gt;
&lt;br /&gt;
''There is one repeater in the recieving mezzannine, and one in large down''&lt;br /&gt;
&lt;br /&gt;
====3CX Windows client====&lt;br /&gt;
====3CX App (iOS/Android)====&lt;br /&gt;
&lt;br /&gt;
===Firmware updates===&lt;br /&gt;
The Yealink deskphones and DECT bases require firmware updates. The firmware for the deskphones can and should only be updated through 3CX. This is because there is specific, 3CX-certified firmware which is different (and often lags behind) what Yealink generally releases. The firmware is auto-downloaded into the 3CX system as a part of its auto-updater. Once newer firmware is auto-downloaded into the repository, the system displays a warning for applicable phones that are now out of date. The firmware can be pushed from the 3CX console. This will reboot the phone and reset any user customizations that are not managed through 3CX. For example, the ringtone is manageable through 3CX, but the ''Display Clock'' within ''Screensaver'', is not.&lt;br /&gt;
&lt;br /&gt;
==Supported deployment configurations==&lt;br /&gt;
This section discusses the different configurations that are in use currently. Originally there were only 2 standard configurations (office and warehouse employees), but the situation evolved rapidly due to COVID/WFH. In particular, the softphones, web client and mobile app have become part of standard usage, in some cases replacing the use of deskphones entirely e.g. Customer Service.&lt;br /&gt;
&lt;br /&gt;
====General (in-office)====&lt;br /&gt;
:'''''Setup 1 (office):''''' Yealink deskphone, EPOS wireless headset via USB (connected to deskphone)&lt;br /&gt;
:'''''Setup 2 (warehouse):''''' Yealink cordless DECT phone&lt;br /&gt;
:'''''Setup 3 (certain staff):''''' 3CX Web Client, EPOS wireless headset via USB (connected to computer)&lt;br /&gt;
:'''''Optional components:''''' 3CX Web Client, 3CX App (mobile)&lt;br /&gt;
&lt;br /&gt;
Setup 1 was the original setup for all office users, and involves a Yealink deskphone (T54W) and, for staff using a headset, an EPOS SD-Pro Or D10 DECT headset connected to the phone via USB. &lt;br /&gt;
&lt;br /&gt;
Some staff who have been exposed to either the web client or mobile app (due to WFH or other means) continue to use these in-office for the additional features. For example, some warehouse supervisors use the mobile app instead of the cordless phone.&lt;br /&gt;
&lt;br /&gt;
====WFH (except Customer Service)====&lt;br /&gt;
:'''''Setup:''''' 3CX Web Client and 3CX App (mobile)&lt;br /&gt;
:'''''Additional components: ''''' 3CX Browser Extension for Chrome or Edge (Chromium-based)&lt;br /&gt;
&lt;br /&gt;
When working from home, the web client is the recommended deployment for office staff that are not in Customer Service. Theoretically, the web client is more performant through the WAN compared to the softphone as it uses WebRTC rather than SIP/RTP (I think...). Being browser-accessible, the web client is also simpler to deploy and maintain than the Windows client. &lt;br /&gt;
&lt;br /&gt;
====Customer Service====&lt;br /&gt;
:'''''Setup 1: ''''' 3CX for Windows softphone, EPOS Connect, 3CX Plugin for EPOS&lt;br /&gt;
:'''''Setup 2 (WFH): ''''' 3CX for Windows softphone (through RDP), Poly/Plantronics C3220 USB headset (USB pass-through), Plantronics Hub Software (supports 3CX integration)&lt;br /&gt;
:'''''Additional components: ''''' Kuando BusyLight&lt;br /&gt;
&lt;br /&gt;
The '''3CX for Windows''' softphone (a.k.a. desktop client) has become the preferred deployment for Customer Service agents, along with the headset connected directly to the computer. This is true whether in-office or WFH. Call control and other features are enabled through the EPOS Connect softaware and the 3CX Plugin for EPOS. While the headset could theoretically work in plug-and-play mode, both of these need to be installed for a smooth experience.&lt;br /&gt;
&lt;br /&gt;
This software communicates to the server via the main LAN, which is different from the deskphones that [[Information_Systems:VoIP_LAN_configuration |communicate on the VoIP VLAN]].&lt;br /&gt;
&lt;br /&gt;
For historical reference, the original deployment for CS agents involved a deskphone (including a sidecar attachment for the receptionist), and a wireless headset connected to the deskphone via USB. The deskphone introduced another vendor into the equation - Yealink, which in turn presented limitations due to only a subset of features on the deskphone being interoperable with 3CX. For example, the deskphone neither displays call queue information nor Away status for other users.&lt;br /&gt;
&lt;br /&gt;
TBC -[[User:Norwinu|norwizzle]] ([[User talk:Norwinu|talk]])&lt;br /&gt;
&lt;br /&gt;
[[Category: Phone System]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:VoIP_Phone_Configuration&amp;diff=13875</id>
		<title>Information Systems:VoIP Phone Configuration</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:VoIP_Phone_Configuration&amp;diff=13875"/>
		<updated>2021-05-27T17:21:13Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Cordless (DECT) Base and Phone Setup */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This article discusses the user-facing side of the phone system including deskphones, cordless phones, and headsets.&lt;br /&gt;
&lt;br /&gt;
==Administration==&lt;br /&gt;
===Initial Setup===&lt;br /&gt;
====Deskphone Setup (Yealink)====&lt;br /&gt;
* The first step when configuring a new phone desk phone is to unbox and label the phone to its extension. &lt;br /&gt;
* The second step is to determine what port it will be plugged into , meaning which port on which switch it plugs into. &lt;br /&gt;
* Tag The port switch port&lt;br /&gt;
* Plug the phone into the local port &lt;br /&gt;
* Log into 3cx&lt;br /&gt;
* Under the phones tab find the new phone by extension &lt;br /&gt;
* Hit assign extension&lt;br /&gt;
* Use Lan at the office &lt;br /&gt;
* Use Interface 192.168.44.2&lt;br /&gt;
* Log into the phone interface and set the phone with a static IP? (maybe)&lt;br /&gt;
&lt;br /&gt;
====Cordless (DECT) Base and Phone Setup====&lt;br /&gt;
web link to general setup https://www.3cx.com/sip-phones/manually-provision-yealink-dect/&lt;br /&gt;
&lt;br /&gt;
* unbox the base and handset &lt;br /&gt;
* plug the base into switch &lt;br /&gt;
* navigate to the 3cx management page &lt;br /&gt;
* under the advanced tab select FXS/DECT&lt;br /&gt;
* add the base using the mac address to the list of bases already present.&lt;br /&gt;
* use the interface 192.168.44.2&lt;br /&gt;
* copy the provisioning link provided here in the general tab&lt;br /&gt;
* define the extensions in the extensions tab&lt;br /&gt;
* navigate to the ip address of the wireless base&lt;br /&gt;
* navigate to settings and auto configuration , use the provisioning link copied before in the space for server URL&lt;br /&gt;
* confirm, auto provision now.&lt;br /&gt;
* to add a phone to a base, press and hold the wifi button on the base until the top light starts to flash, then on the handset select register and they will find each other.&lt;br /&gt;
*username is admin, and the password for the base is found on the FS/Dect page for the base.&lt;br /&gt;
&lt;br /&gt;
====DECT Repeater Setup====&lt;br /&gt;
*Setting up a repeater requires a dect base, handset that is paired to that base and the repeater itself.&lt;br /&gt;
*from a paired handset navigate to settings and put it into repeater mode, choosing the type of repeater. &lt;br /&gt;
*the base will automatically reset when the paired handset is put into repeater mode,  wait for the base to come online &lt;br /&gt;
*connect the repeater to power &lt;br /&gt;
*hold down the pairing button on the base until the phone light starts to flash&lt;br /&gt;
*press the pairing button on the repeater. &lt;br /&gt;
* the dect light should go from red to orange when it finds the base.&lt;br /&gt;
&lt;br /&gt;
''There is one repeater in the recieving mezzannine, and one in large down''&lt;br /&gt;
&lt;br /&gt;
====3CX Windows client====&lt;br /&gt;
====3CX App (iOS/Android)====&lt;br /&gt;
&lt;br /&gt;
===Firmware updates===&lt;br /&gt;
The Yealink deskphones and DECT bases require firmware updates. The firmware for the deskphones can and should only be updated through 3CX. This is because there is specific, 3CX-certified firmware which is different (and often lags behind) what Yealink generally releases. The firmware is auto-downloaded into the 3CX system as a part of its auto-updater. Once newer firmware is auto-downloaded into the repository, the system displays a warning for applicable phones that are now out of date. The firmware can be pushed from the 3CX console. This will reboot the phone and reset any user customizations that are not managed through 3CX. For example, the ringtone is manageable through 3CX, but the ''Display Clock'' within ''Screensaver'', is not.&lt;br /&gt;
&lt;br /&gt;
==Supported deployment configurations==&lt;br /&gt;
This section discusses the different configurations that are in use currently. Originally there were only 2 standard configurations (office and warehouse employees), but the situation evolved rapidly due to COVID/WFH. In particular, the softphones, web client and mobile app have become part of standard usage, in some cases replacing the use of deskphones entirely e.g. Customer Service.&lt;br /&gt;
&lt;br /&gt;
====General (in-office)====&lt;br /&gt;
:'''''Setup 1 (office):''''' Yealink deskphone, EPOS wireless headset via USB (connected to deskphone)&lt;br /&gt;
:'''''Setup 2 (warehouse):''''' Yealink cordless DECT phone&lt;br /&gt;
:'''''Setup 3 (certain staff):''''' 3CX Web Client, EPOS wireless headset via USB (connected to computer)&lt;br /&gt;
:'''''Optional components:''''' 3CX Web Client, 3CX App (mobile)&lt;br /&gt;
&lt;br /&gt;
Setup 1 was the original setup for all office users, and involves a Yealink deskphone (T54W) and, for staff using a headset, an EPOS SD-Pro Or D10 DECT headset connected to the phone via USB. &lt;br /&gt;
&lt;br /&gt;
Some staff who have been exposed to either the web client or mobile app (due to WFH or other means) continue to use these in-office for the additional features. For example, some warehouse supervisors use the mobile app instead of the cordless phone.&lt;br /&gt;
&lt;br /&gt;
====WFH (except Customer Service)====&lt;br /&gt;
:'''''Setup:''''' 3CX Web Client and 3CX App (mobile)&lt;br /&gt;
:'''''Additional components: ''''' 3CX Browser Extension for Chrome or Edge (Chromium-based)&lt;br /&gt;
&lt;br /&gt;
When working from home, the web client is the recommended deployment for office staff that are not in Customer Service. Theoretically, the web client is more performant through the WAN compared to the softphone as it uses WebRTC rather than SIP/RTP (I think...). Being browser-accessible, the web client is also simpler to deploy and maintain than the Windows client. &lt;br /&gt;
&lt;br /&gt;
====Customer Service====&lt;br /&gt;
:'''''Setup 1: ''''' 3CX for Windows softphone, EPOS Connect, 3CX Plugin for EPOS&lt;br /&gt;
:'''''Setup 2 (WFH): ''''' 3CX for Windows softphone (through RDP), Poly/Plantronics C3220 USB headset (USB pass-through), Plantronics Hub Software (supports 3CX integration)&lt;br /&gt;
:'''''Additional components: ''''' Kuando BusyLight&lt;br /&gt;
&lt;br /&gt;
The '''3CX for Windows''' softphone (a.k.a. desktop client) has become the preferred deployment for Customer Service agents, along with the headset connected directly to the computer. This is true whether in-office or WFH. Call control and other features are enabled through the EPOS Connect softaware and the 3CX Plugin for EPOS. While the headset could theoretically work in plug-and-play mode, both of these need to be installed for a smooth experience.&lt;br /&gt;
&lt;br /&gt;
This software communicates to the server via the main LAN, which is different from the deskphones that [[Information_Systems:VoIP_LAN_configuration |communicate on the VoIP VLAN]].&lt;br /&gt;
&lt;br /&gt;
For historical reference, the original deployment for CS agents involved a deskphone (including a sidecar attachment for the receptionist), and a wireless headset connected to the deskphone via USB. The deskphone introduced another vendor into the equation - Yealink, which in turn presented limitations due to only a subset of features on the deskphone being interoperable with 3CX. For example, the deskphone neither displays call queue information nor Away status for other users.&lt;br /&gt;
&lt;br /&gt;
TBC -[[User:Norwinu|norwizzle]] ([[User talk:Norwinu|talk]])&lt;br /&gt;
&lt;br /&gt;
[[Category: Phone System]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Barcodes_for_LTO5/6_Tapes&amp;diff=13865</id>
		<title>Information Systems:Barcodes for LTO5/6 Tapes</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Barcodes_for_LTO5/6_Tapes&amp;diff=13865"/>
		<updated>2021-05-25T20:09:52Z</updated>

		<summary type="html">&lt;p&gt;Aaront: Created page with &amp;quot;The Barcodes for LTO5/6 tapes are being created using the brother P-touch editor on the Lab PC or can have it installed on a laptop and communicate with either the Qnl7xx whic...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;The Barcodes for LTO5/6 tapes are being created using the brother P-touch editor on the Lab PC or can have it installed on a laptop and communicate with either the Qnl7xx which is wireless on the network, or the Qnl5xx which is USB attached. &lt;br /&gt;
&lt;br /&gt;
Barcode size needs to be exact and testing the label using an RF scanner should be done before sticking it to a tape.&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_Office_2019_Training&amp;diff=13864</id>
		<title>Information Systems:Microsoft Office 2019 Training</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_Office_2019_Training&amp;diff=13864"/>
		<updated>2021-05-20T23:28:01Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Oulook how-to, FAQ */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Microsoft Office 2019 Training=&lt;br /&gt;
&lt;br /&gt;
The following link is provided as a free resource that provides comprehensive training on a variety of topics from basic to more advanced topics for Word 2019, Excel 2019, Powerpoint 2019 and Access 2019.  Feel free to go through this training material on your own if you feel you need a refresher or would like to better familiarize yourself with the new look and features of Office 2019.&lt;br /&gt;
&lt;br /&gt;
https://edu.gcfglobal.org/en/topics/office/&lt;br /&gt;
&lt;br /&gt;
Additional training as needed will be added to this page.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Outlook 2019 Training=&lt;br /&gt;
&lt;br /&gt;
The following link is provided by Microsoft as a free resource that provides an excellent overview of Microsoft Outlook functionality for all platforms.  For most staff Windows and iOS &amp;amp; Android training would be the training courses to focus on as we mainly use Outlook on our work provided Windows computers or as an app on your personal Apple or Android mobile device.&lt;br /&gt;
&lt;br /&gt;
https://support.microsoft.com/en-us/office/outlook-training-8a5b816d-9052-4190-a5eb-494512343cca&lt;br /&gt;
&lt;br /&gt;
=Oulook how-to, FAQ=&lt;br /&gt;
'''Outbox'''-This is holding area for emails that are not yet sent. The outbox is in alphabetical order in the folder tree by default, it may be dragged to any position needed.( this is true for all folders!)&lt;br /&gt;
  &lt;br /&gt;
'''Outbox''' is a folder that holds your emails before sending  either by user choice or because you are offline. By default our outlook clients are set to not delay sending emails so this folder will be empty for most. If there is a need to delay the sending of an email, outbox should be configured to meet that requirement. In outlook options under advanced uncheck send immediately if connected, if you would like all emails to wait in the outbox before sending. &lt;br /&gt;
&lt;br /&gt;
'''Junk Mail'''- If you are in your inbox or any folder that receives email, and there is mail there that you would like to block right click on the email and then  hit junk, then hit  block the sender, from now on that senders emails will go to your junk folder. &lt;br /&gt;
Junk Folder&lt;br /&gt;
&lt;br /&gt;
This is a folder that has emails that have been flagged as junk. It may be in alphabetical order in the list of folders and can be dragged into whatever position is best. &lt;br /&gt;
This folder should be checked regularly when there is missing email, similar to barracuda. If an email is expected and it isn’t in your inbox, check the junk folder then reach out to Information Services. &lt;br /&gt;
&lt;br /&gt;
What to do if….&lt;br /&gt;
*an email is in your junk folder and it shouldn’t you may right click on it and can choose to mark it as not junk.&lt;br /&gt;
*an email is in your inbox  and you always want email from this sender to be junk, hit block sender. &lt;br /&gt;
*an email should never be blocked from a domain ,a mailing list, or a group we can choose to never block the sender  preventing the mail from being marked as junk. &lt;br /&gt;
&lt;br /&gt;
If you select junk mail options you will get choices to change the behaviour of automatic filtering, by default this is off. &lt;br /&gt;
There is a tab that has all the safe senders, recipients and blocked senders, you may unblock someone from here, if accidentally blocked. &lt;br /&gt;
&lt;br /&gt;
*If you are selecting many emails at once you may use the home tab and section that is called delete to find the junk icon with all the same options but can be more easily applied to multiple emails at once. &lt;br /&gt;
&lt;br /&gt;
'''Out of Office''' There is an out of office setting it is found by pressing file, then Automatic Replies ( out of office), from here you must choose to enable it for internal and external users and set the day and times for it to start and stop. There is also a rules function similar to mail rules that allows specific out of office messages conditions. &lt;br /&gt;
&lt;br /&gt;
Additional training as needed will be added to this page.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Training]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:SRFax_(desktop_faxing)_Administration&amp;diff=13863</id>
		<title>Information Systems:SRFax (desktop faxing) Administration</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:SRFax_(desktop_faxing)_Administration&amp;diff=13863"/>
		<updated>2021-05-20T21:41:05Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Valid Fax Numbers For Outside Sources Like Pharmacies And Vendors When THEY Need To Send TO uniPHARM */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; This is a technical guide. For user guides (e.g. how to send faxes), consult the [[:Category: Fax|'''Fax category''']].&lt;br /&gt;
==Overview==&lt;br /&gt;
uniPHARM uses a hosted fax service, SRFax, to send and receive fax documents such as recall notices to and from our business partners. This replaced Xerox/device-based faxing.&lt;br /&gt;
&lt;br /&gt;
===How it works===&lt;br /&gt;
Users fax PDFs (or other supported documents) from the desktop as they would print something. A fax printer driver (downloadable from SRFax) is (or should be) installed on each computer, and printing from Windows applications should summon a pop-up where you configure cover pages, enter destination numbers etc., and finally, send the fax.&lt;br /&gt;
&lt;br /&gt;
==Configuration==&lt;br /&gt;
===Account Details===&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
| Website (administration/user portal) || https://www.srfax.com&lt;br /&gt;
|-&lt;br /&gt;
| Login credentials || admin@unipharm.com / NewVisionIT2051&lt;br /&gt;
|-&lt;br /&gt;
| Subscription Details ||&lt;br /&gt;
:* $16.95 per month Health Care Plan &lt;br /&gt;
:* 800 pages included&lt;br /&gt;
:* $0.03/page overage&lt;br /&gt;
:* 6 additional inbound/outbound numbers at $4.95/month each                   &lt;br /&gt;
|-&lt;br /&gt;
| Company Info || Located in Sydney, BC&lt;br /&gt;
|-&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===SRFax Accounts===&lt;br /&gt;
If you really want a full understanding of the SRFax setup, make the effort to understand this section. Otherwise, skip it and wing it. The way the accounts are setup is a little complicated but was determined to achieve the best outcome (with regards to user ease-of-use and convenience of administration). &lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! style=&amp;quot;width: 15%&amp;quot;|Account Name !! style=&amp;quot;width: 5%&amp;quot;|Account type (Main/Sub) !!  style=&amp;quot;width: 9%&amp;quot;|Billing account type (Inbound/Outbound) !! Purpose !! style=&amp;quot;width: 7%&amp;quot;|Fax number !! Username/login !! Mapped aliases !! Account number !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| Administration Account || '''Main''' || Inbound/Outbound || Primarily for admin purposes, also the ultimate ''route'' through which outbound faxes travel. || 604-276-8478 || admin@unipharm.com || norwinu, darrenf, jeremym, nancyn || 92531 || nancyn and jeremym aliased to this account for address book management and billing administration, respectively.&lt;br /&gt;
|-&lt;br /&gt;
| Outbound Fax - Company Main || Sub || Outbound only || Used to group users (majority of staff members) for outbound faxing || 604-276-8478 (routes through Main account) || fax@unipharm.com, or aliased users || Most staff members, with their usernames in AD format (e.g. norwinu; '''Exceptions''': tomc, timm&amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt;) || 99797 ||&lt;br /&gt;
|-&lt;br /&gt;
| Outbound Fax - Purchasing Dept. || Sub || Outbound only || Used to group Purchasing Dept. users for outbound faxing || 604-276-8478 (routes through Main account) || purchasing@unipharm.com, or aliased users || elizag, johnt, judyt, rubys, shannonm, simonl, monicat || 99783 || Separated out so department can keep their own address books, local to the group.&lt;br /&gt;
|-&lt;br /&gt;
| Inbound Fax - Receiving || Sub || Inbound/Outbound&amp;lt;sup&amp;gt;2&amp;lt;/sup&amp;gt; || Placeholder for inbound route only; for receiving faxes destined for Receiving department copier (reccopier) || 604-276-5250 || faxreceiving@unipharm.com || None || 99645 ||&lt;br /&gt;
|-&lt;br /&gt;
| Inbound Fax - Returns || Sub || Inbound/Outbound&amp;lt;sup&amp;gt;2&amp;lt;/sup&amp;gt; || Placeholder for inbound route only; for receiving faxes destined for Returns department copier (rtncopier) || 604-276-5283 || faxreturns@unipharm.com || None || 99643 ||&lt;br /&gt;
|-&lt;br /&gt;
| Inbound Fax - Elaho || Sub || Inbound/Outbound&amp;lt;sup&amp;gt;2&amp;lt;/sup&amp;gt; || Placeholder for inbound route only; for receiving faxes destined for 2nd-floor copier (elaho) || 604-270-9728 || faxelaho@unipharm.com || None || 99639 ||&lt;br /&gt;
|-&lt;br /&gt;
| Inbound Fax - Stein || Sub || Inbound/Outbound&amp;lt;sup&amp;gt;2&amp;lt;/sup&amp;gt; || Placeholder for inbound route only; for receiving faxes destined for 1st-floor copier (stein) || 604-270-8537 || faxstein@unipharm.com || None || 99647 ||&lt;br /&gt;
|-&lt;br /&gt;
| Angela Chan || Sub || Inbound/Outbound || Inbound and outbound; dedicated for use by Angela only || 604-270-2884 || angelac@unipharm.com || None || 99571 || Inbound faxes will print to ''angelacprinter''&lt;br /&gt;
|-&lt;br /&gt;
| Ralph Lai || Sub || Inbound/Outbound || Inbound and outbound; dedicated for use by Ralph only || 604-276-5255 || ralphl@unipharm.com || None || 99579 || Inbound faxes will print to ''rongprinter''&lt;br /&gt;
|-&lt;br /&gt;
|colspan=&amp;quot;9&amp;quot;| &amp;lt;sup&amp;gt;1&amp;lt;/sup&amp;gt; &amp;lt;small&amp;gt;SRFax requires aliases to have a username &amp;gt; 4 characters, yet the email address cannot be used (reserved for user accounts). So the user names for tomc and timm are 'Tom Chotwanwirach' and 'Tim Matiachuk' respectively. Will they notice? Lol c'mon now, it's fax.&amp;lt;/small&amp;gt;&lt;br /&gt;
&amp;lt;sup&amp;gt;2&amp;lt;/sup&amp;gt; &amp;lt;small&amp;gt;Note that while these accounts are of the Inbound/Outbound type (billing-wise), the point is that they are being used for inbound purposes only.&amp;lt;/small&amp;gt;&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
 The primary justification for the level of complexity in the way the users were set up came from the desire to keep the inbound fax &amp;quot;experience&amp;quot; the same as when uniPHARM used traditional Xerox/device-based faxing. Each Xerox had a phone number and thus represented a distinct inbound route. Each Xerox was also a distinct outbound route, yet this was not as important (i.e. origin of the fax was not important; the cover page always indicated the return fax number). Yet another factor was that that faxing is an infrequently used (and outdated) means of communication, so it was not ideal to set users up as full-featured sub-accounts, as that would've incurred unnecessary administrative burden. Lastly, it was sensible to have groups like Purchasing to have group-local address books. Thus to translate all these requirements to hosted/internet faxing, users were set up as shown above.&lt;br /&gt;
&lt;br /&gt;
Key points: &lt;br /&gt;
&lt;br /&gt;
* There are 2 concepts of &amp;quot;users&amp;quot; - '''user accounts''' and '''aliases'''. User accounts are those listed in the table above and, in our design, are mostly symbolic/representational, with the exception of Ron and Angela's (these are true user sub-accounts in the conventional sense). The rest of the staff members are not user accounts, but are aliases, aliased to one of the two symbolic &amp;quot;Outbound&amp;quot; users listed above. I.T. staff are aliased to the admin account.&lt;br /&gt;
&lt;br /&gt;
* Regarding user accounts, there is one main account, to which all sub-accounts fall under. This is for administration purposes. User accounts can also be inbound/outbound and outbound-only. Inbound/outbound accounts have a dedicated fax number, while outbound-only accounts use the main account's fax number. '''''If I haven't lost you by now, congratulations. I am truly impressed. Not that this stuff is hard, but rather because of the [https://en.wikipedia.org/wiki/Rube_Goldberg_machine Rube Goldberg-ness] of the entire setup (a fax setup, no less). -[[User:Norwinu|norwizzle]] ([[User talk:Norwinu|talk]])'''''&lt;br /&gt;
&lt;br /&gt;
* Any time a fax is sent, it is done through a specific user account. Aliased users therefore send as the user they are aliased to. When aliased users log in, they are all logging into the same account (which for most staff members, is '''Outbound Fax - Company Main''').&lt;br /&gt;
&lt;br /&gt;
* Any time a fax is sent, it also must go out a certain fax number. For inbound/outbound user accounts, its own fax number is used. For outbound-only users, the main account's fax number is used.&lt;br /&gt;
&lt;br /&gt;
* The concept of users only really comes into play during administration. That is, if you follow the table above, you will notice that all staff members (with the exception of Ron and Angela) ultimately send faxes through one number. &lt;br /&gt;
&lt;br /&gt;
* All inbound faxing occurs through pre-defined routes, with phone numbers mapped to email addresses, which in turn are mapped to printers.&lt;br /&gt;
&lt;br /&gt;
* Logging into the admin/main account lets you see everything across the sub-accounts, but some settings may require you to &amp;quot;admin-log-in&amp;quot; to the sub-account (similar to Barracuda administration, where you can enter into each user's account from the admin account).&lt;br /&gt;
&lt;br /&gt;
===Address book===&lt;br /&gt;
The main account has the master address books, which all sub-accounts and their aliases can read, but not edit. The main account and its aliases, however, can edit these address books.&lt;br /&gt;
&lt;br /&gt;
Each sub-account can have their local address books as well. This is primarily why some of them were created (e.g. '''Outbound Fax - Purchasing Dept.)&lt;br /&gt;
&lt;br /&gt;
===Delivery notifications===&lt;br /&gt;
Because of the way users are set up, setting up delivery notifications (success/failure fax confirmations) to notify the original sender was a somewhat tricky matter. SRFax has been pre-configured to do the following:&lt;br /&gt;
&lt;br /&gt;
* When faxing through the print driver, delivery notifications will be sent to the Email field in the Account Details tab (success or fail). This is a suitable workaround for the fact that aliased users all send faxes under the same account. Note that the user account's email address will also receive a copy. For example, if alias ''rubys'' sends a fax, it will send to ''rubys@unipharm.com'', as the fax driver is configured with this email. A delivery notification will also be sent to purchasing@unipharm.com (and since this email doesn't exist, we can expect this pathway to just be a blackhole).&lt;br /&gt;
&lt;br /&gt;
* When faxing through the web portal, there is no Email field to specify. Thus, delivery confirmations will not be specific to the user, but &lt;br /&gt;
&lt;br /&gt;
* The relevant settings can be found under '''Settings''' -&amp;gt; '''Sending Faxes'''. These settings are specific to each user account.&lt;br /&gt;
&lt;br /&gt;
===Automatic Email Manager===&lt;br /&gt;
Automatic Email Manager is a piece of software installed inside the SuperServer virtual machine, that checks emails and auto-processes (prints or files) any contained attachments. It is an important part of the fax workflow as it prints inbound fax documents automatically to their designated printers (determined by destination email address, which in turn, [[#SRFax Accounts|is mapped to a specific inbound phone number]]). &lt;br /&gt;
&lt;br /&gt;
[[Information Systems: Automatic Email Manager|Read more about Automatic Email Manager here]]&lt;br /&gt;
&lt;br /&gt;
==Basic administration==&lt;br /&gt;
===Editing the master address books===&lt;br /&gt;
# Log in to SRFax as any of admin@unipharm.com, 92531, or the aliased users for this account.&lt;br /&gt;
# Navigate to '''Faxes''' -&amp;gt; '''Edit Address Book'''.&lt;br /&gt;
# Edit contact(s). A group may have to be selected first.&lt;br /&gt;
# This address book and its contacts are special in that they are visible to all users when sending a fax, but will not show up in the 'Edit Address Book' area of their accounts.&lt;br /&gt;
&lt;br /&gt;
===Adding/removing a staff member (alias)===&lt;br /&gt;
 Also for changing permissions for aliased users.&lt;br /&gt;
# Log in to SRFax as admin.&lt;br /&gt;
# Navigate to '''My Account''' -&amp;gt; '''User Administration'''.&lt;br /&gt;
# Most staff members will be aliased to '''Outbound Fax - Company Main'''. Click the Edit button for that account to log into it as admin.&lt;br /&gt;
# Navigate to '''My Account''' -&amp;gt; Account Access to see the aliases for this account. &lt;br /&gt;
# Add or remove users as needed. Edit permissions as needed.&lt;br /&gt;
# Click 'Exit' at the top left to return back to the admin account.&lt;br /&gt;
&lt;br /&gt;
===Configuring the print driver===&lt;br /&gt;
 Prior to doing this, make sure you have the account number of the user being set up. To retrieve this, log in as admin and navigate to '''My Account''' -&amp;gt; '''User Administration''', or consult the table above.&lt;br /&gt;
# Acquire and install the print driver from SRFax ('''Support''' -&amp;gt; '''SRFax Printer Driver''') if it is not already installed. &lt;br /&gt;
# Bring up the configuration/fax wizard by attempting to print something using the fax driver (the printer is named just SRFax).&lt;br /&gt;
# In the '''Account Details''' tab, click Change. &lt;br /&gt;
# Fill in the proper account number. ''For the majority of situations, it should be the account number of one of the Outbound accounts''.&lt;br /&gt;
# Enter the corresponding password. {{userpass}}&lt;br /&gt;
# '''Important: ''' If this computer is used primarily by one user, enter their email address in the Email field. This is where [[#Delivery notifications|delivery notifications]] are sent. &lt;br /&gt;
# Review the settings under the other tabs, change if necessary.&lt;br /&gt;
# Cancel out of the wizard.&lt;br /&gt;
&lt;br /&gt;
===Inspecting fax traffic===&lt;br /&gt;
# Log in to SRFax as admin.&lt;br /&gt;
# Under '''Faxes''', navigate to any of '''Faxes Received''', '''Faxes Sent''', or '''Faxes Queued''' to analyze corresponding traffic. Use '''Call Log Reports''' to generate a report.&lt;br /&gt;
# Recall that since this the admin account, you can inspect/analyze usage/traffic of the sub-accounts. &lt;br /&gt;
&lt;br /&gt;
===Billing tasks===&lt;br /&gt;
* Invoices are emailed to accountspayable@unipharm.com and jeremym@unipharm.com.&lt;br /&gt;
* The admin account can access and generate invoices in the web portal. There are also functions to display charges summarized by user in '''My Account''' -&amp;gt; '''Past Invoices'''.&lt;br /&gt;
&lt;br /&gt;
===Valid Fax Numbers For Outside Sources Like Pharmacies And Vendors When THEY Need To Send TO uniPHARM===&lt;br /&gt;
* Main 604-270-8537&lt;br /&gt;
* Buying 604-270-9728&lt;br /&gt;
* Receiving 604-276-5250&lt;br /&gt;
* Returns 604-276-5283&lt;br /&gt;
* RalphL 604-276-5255&lt;br /&gt;
* AngelaC 604-270-2884&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Fax]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Renewing_the_Web_Orders_SSL_Certificate&amp;diff=13858</id>
		<title>Information Systems:Renewing the Web Orders SSL Certificate</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Renewing_the_Web_Orders_SSL_Certificate&amp;diff=13858"/>
		<updated>2021-05-19T16:01:25Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Instructions On How To Renew An SSL Certificate For Web order Or InfoNet&lt;br /&gt;
These instructions were written by DarrenF on January 11 2016 and describe what needs to be done when the SSL certificate on a website hosted on the Power8 needs to be renewed.  Hopefully this all happens before the current expiry date.&lt;br /&gt;
#	Go to https://bart.unipharm.local:2005/ibm/console - No as of 2019 use Web Navigator instead&lt;br /&gt;
#	Ignore unsupported browser message&lt;br /&gt;
#	Login with credentials – probably all object auth or qsec&lt;br /&gt;
#	On left side IBM I Management panel, at the bottom, click on “Internet Configurations”&lt;br /&gt;
#	Then click on “Digital Certificate Manager” in the main tab&lt;br /&gt;
#	Log in again with same credentials&lt;br /&gt;
#	On the left side, click on “Select A Certificate Store”&lt;br /&gt;
#	Choose *SYSTEM and click continue&lt;br /&gt;
#	Enter in the password which is visionit and click continue&lt;br /&gt;
#	Click the triangle twisty next to “Manage Certificates” and then click “View Certificate”&lt;br /&gt;
#	Write down the friendly name of the certificate that needs to be renewed because there may be duplicates from past years – make sure that you renew the correct certificate by checking the expiry date!&lt;br /&gt;
#	Click “Renew Certificate” in the “Manage Certificate” menu&lt;br /&gt;
#	Select the correct certificate that needs to be renewed and click the Renew button&lt;br /&gt;
#	The next screen should only have 1 option as an Internet Certificate Authority, click continue&lt;br /&gt;
#	Choose “Yes – Create a new key pair” and click continue&lt;br /&gt;
#	The “New Certificate Label” is the friendly name for this renewal – try and make the label descriptive and unique&lt;br /&gt;
#	Key size must be 2048&lt;br /&gt;
#	Fill out the rest of the fields underneath Certificate Information and take a screenshot of that screen&lt;br /&gt;
#	Country code is CA and then click continue&lt;br /&gt;
#	Copy the certificate request into Notepad and save the file – be sure to copy from the first dash line to the end of the last dash line&lt;br /&gt;
#	Click OK&lt;br /&gt;
#	Take the saved block of text and provide that to the CA reseller when purchasing the renewed certificate&lt;br /&gt;
#	Try and buy a renewed certificate for the longest period of time possible unless the website or server doing the hosting is going to be decommissioned&lt;br /&gt;
#       If using Network Solutions they will do an email and phone validation on the SSL renewal to make sure that the certificate is going to the correct company&lt;br /&gt;
#	When the CA has issued the renewed certificate, download it&lt;br /&gt;
#	On the Digital Certificate Manager website, on the left side click “Import Certificate” from the “Manage Certificates” menu&lt;br /&gt;
#	Choose “Server or client” and click continue&lt;br /&gt;
#	The renewed certificate file from the CA needs to be copied to the IFS, /temp works well&lt;br /&gt;
#	Type the file path into the import screen and click continue&lt;br /&gt;
#       Assign the NEW certificate to the correct application which should be either Web Orders or InfoNet at the bottom of the list&lt;br /&gt;
#	Specify the same friendly label as you chose in step 16 and click continue&lt;br /&gt;
#	If you get an error that validation of the certificate failed then the CA’s root certificates also need to be imported in the correct order so that the renewed certificate can be validated all the way up the chain by going back to step 26 and choosing CA instead of server ( if unsure of this process call it in as doing it wrong can break the key and requires a repurchase of the key) &lt;br /&gt;
#	Click on “Assign Certificate” from the “Manage Certificates” menu&lt;br /&gt;
#	Choose the newly renewed certificate you just imported and click “Assign to Application”&lt;br /&gt;
#	Either InfoNet or Web Orders should be at the bottom of the list, put a check mark in the right application and click REPLACE&lt;br /&gt;
#	Delete the files that were put on the IFS as they are not needed anymore&lt;br /&gt;
#	Log out of the Digital Certificate Manager page and the web Navigator site&lt;br /&gt;
#	At this point you could stop the IBM HTTP( using IBMI navigator|File Systems|IBM Web Administration for i|Manage|Http Server|Websmart)  server and then restart it to see the renewed certificate immediately – otherwise you will have to wait for the EOD to automatically bounce the web server instances&lt;br /&gt;
#	Check in a web browser that the new certificate with the correct expiry dates is actually being used&lt;br /&gt;
#	Profit&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: WebSmart]]&lt;br /&gt;
[[Category: How-to pages]]&lt;br /&gt;
[[Category: I.T. Periodic Tasks]]&lt;br /&gt;
[[Category: SSL Certificates]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Retro_PC_VM-_windows_7_pro&amp;diff=13857</id>
		<title>Information Systems:Retro PC VM- windows 7 pro</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Retro_PC_VM-_windows_7_pro&amp;diff=13857"/>
		<updated>2021-05-17T23:28:12Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For RF administration this VM was created. &lt;br /&gt;
In order to get the VM to see the usb device, right click on the device in the vm pane. Then hover over removable devices, all usb devices will be listed, go ahead and connect to the usb device you want to connect to which will disconnect the device from the host and pass through to the VM.&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Retro_PC_VM-_windows_7_pro&amp;diff=13856</id>
		<title>Information Systems:Retro PC VM- windows 7 pro</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Retro_PC_VM-_windows_7_pro&amp;diff=13856"/>
		<updated>2021-05-17T22:09:22Z</updated>

		<summary type="html">&lt;p&gt;Aaront: Created page with &amp;quot;For Rf administration this VM was created.  in order to get the vm to see the usb device, right click on the device in the vm pane. Then hover over removable devices, all usb...&amp;quot;&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;For Rf administration this VM was created. &lt;br /&gt;
in order to get the vm to see the usb device, right click on the device in the vm pane. Then hover over removable devices, all usb devices will be listed, go ahead and connect to the usb device you want to connect to which will disconnect the device from the host and pass through to the VM.&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:RF_configuration_/_Standard_deployment_package&amp;diff=13855</id>
		<title>Information Systems:RF configuration / Standard deployment package</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:RF_configuration_/_Standard_deployment_package&amp;diff=13855"/>
		<updated>2021-05-17T21:16:41Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Files */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Changes=&lt;br /&gt;
&lt;br /&gt;
A single executable contains all the files necessary to install the MobiControl agent and Windows CE settings for deployment of an RF gun into production use. The following summarizes every single change that the MobiControl agent exacts on the device from its default configuration.&lt;br /&gt;
&lt;br /&gt;
==Registry settings==&lt;br /&gt;
===DHCP===&lt;br /&gt;
DHCP is enabled&lt;br /&gt;
===Power===&lt;br /&gt;
* Display timeout:&lt;br /&gt;
* Backlight settings:&lt;br /&gt;
* Sleep timeout:&lt;br /&gt;
&lt;br /&gt;
===Wireless (Summit Client Utility)===&lt;br /&gt;
The WAP G2 uses a wireless adapter by Summit Wireless. The utility (Start --&amp;gt; Programs --&amp;gt; Summit) has its own registry settings and defines settings associated with roaming, transmit power etc. The roaming settings are particularly important. &lt;br /&gt;
&lt;br /&gt;
More info: http://www.summitdata.com/Documents/Glossary/knowledge_center_r.html#standard_roaming&lt;br /&gt;
&lt;br /&gt;
==Files==&lt;br /&gt;
All the files needed to work with an RF gun are located in superserver\tech\RFguns&lt;br /&gt;
This includes the windows CE OS files &lt;br /&gt;
MCagent &lt;br /&gt;
ActiveSync Installer for windows 7&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Wallpaper===&lt;br /&gt;
Logo-v2.bmp is used as the device wallpaper.&lt;br /&gt;
&lt;br /&gt;
===Config Change: Full ASCII mode for sign-on ID badges (Distribution Centre)===&lt;br /&gt;
&lt;br /&gt;
May 29, 2015 - User accounts will have case-sensitive passwords on the new Power8, effective June 13, 2015. Distribution Centre staff scan ID badges to sign on to RF terminals, so new badges need to be generated. The Code 39 barcode format of these ID badges use special characters to specify lowercase. Thus, a change needs to be pushed out to all the RF terminals to set the Full ASCII mode in the terminal's Scanner Settings to on (it is off by default).&lt;br /&gt;
&lt;br /&gt;
[[Category:RF Guns]]&lt;br /&gt;
[[Category:MobiControl]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:RF_configuration_/_Standard_deployment_package&amp;diff=13854</id>
		<title>Information Systems:RF configuration / Standard deployment package</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:RF_configuration_/_Standard_deployment_package&amp;diff=13854"/>
		<updated>2021-05-17T21:16:13Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Files */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Changes=&lt;br /&gt;
&lt;br /&gt;
A single executable contains all the files necessary to install the MobiControl agent and Windows CE settings for deployment of an RF gun into production use. The following summarizes every single change that the MobiControl agent exacts on the device from its default configuration.&lt;br /&gt;
&lt;br /&gt;
==Registry settings==&lt;br /&gt;
===DHCP===&lt;br /&gt;
DHCP is enabled&lt;br /&gt;
===Power===&lt;br /&gt;
* Display timeout:&lt;br /&gt;
* Backlight settings:&lt;br /&gt;
* Sleep timeout:&lt;br /&gt;
&lt;br /&gt;
===Wireless (Summit Client Utility)===&lt;br /&gt;
The WAP G2 uses a wireless adapter by Summit Wireless. The utility (Start --&amp;gt; Programs --&amp;gt; Summit) has its own registry settings and defines settings associated with roaming, transmit power etc. The roaming settings are particularly important. &lt;br /&gt;
&lt;br /&gt;
More info: http://www.summitdata.com/Documents/Glossary/knowledge_center_r.html#standard_roaming&lt;br /&gt;
&lt;br /&gt;
==Files==&lt;br /&gt;
All the files needed to work with an RF gun are located in superserver\tech\RFguns&lt;br /&gt;
This includes the windows CE OS files &lt;br /&gt;
MCagent &lt;br /&gt;
ActiveSync Installer for windows&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
===Wallpaper===&lt;br /&gt;
Logo-v2.bmp is used as the device wallpaper.&lt;br /&gt;
&lt;br /&gt;
===Config Change: Full ASCII mode for sign-on ID badges (Distribution Centre)===&lt;br /&gt;
&lt;br /&gt;
May 29, 2015 - User accounts will have case-sensitive passwords on the new Power8, effective June 13, 2015. Distribution Centre staff scan ID badges to sign on to RF terminals, so new badges need to be generated. The Code 39 barcode format of these ID badges use special characters to specify lowercase. Thus, a change needs to be pushed out to all the RF terminals to set the Full ASCII mode in the terminal's Scanner Settings to on (it is off by default).&lt;br /&gt;
&lt;br /&gt;
[[Category:RF Guns]]&lt;br /&gt;
[[Category:MobiControl]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Laser_Printers&amp;diff=13853</id>
		<title>Information Systems:Laser Printers</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Laser_Printers&amp;diff=13853"/>
		<updated>2021-05-15T02:37:58Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;This article is to keep track of the laser printers used in the distribution centre and office.&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Hostname !! Location !! Model !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| gm-printer || GM's office || Brother MFC-L3770CDW || -&lt;br /&gt;
|-&lt;br /&gt;
| Example || Example || Example || -&lt;br /&gt;
|-&lt;br /&gt;
| Example || Example || Example || -&lt;br /&gt;
|-&lt;br /&gt;
| Example || Example || Example || -&lt;br /&gt;
|-&lt;br /&gt;
| it-lab-printer || IT Lab/Cage || Lexmark MS415DN || -&lt;br /&gt;
|-&lt;br /&gt;
| buying-dept-printer || Buying Department || Lexmark MS415DN || -&lt;br /&gt;
|-&lt;br /&gt;
| accounting-dept-printer || Accounting Department || Lexmark MS415DN || -&lt;br /&gt;
|-&lt;br /&gt;
| dc-office-printer || DC Office || Lexmark MS415DN || -&lt;br /&gt;
|-&lt;br /&gt;
| dc-large-down-invoice-printer || DC Large Down || Lexmark MS521DN || -&lt;br /&gt;
|-&lt;br /&gt;
| dc-fridge-invoice-printer || DC Fridge || Lexmark MS521DN || -&lt;br /&gt;
|-&lt;br /&gt;
| dc-narc-invoice-printer || DC Narc Cage || Lexmark MS521DN || -&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
===Old===&lt;br /&gt;
&lt;br /&gt;
uniPHARM uses Lexmark laser printers for printing invoices at each picking station in the distribution centre.  The most common model is the T650/T652.  In the past we also used the T640 and T630 which have all been phased out.  Lexmark colour laser and black only laser printers are present in the office areas.  While there is no restriction on the use of other brands of laser printers (HP for example) it is a best practice to keep the number of brands as close to 1 as possible so that users don't have to adjust to 10 different print drivers.  The T650 lasers at each of the picking stations is connected to the HP print server box with a parallel cable.  When purchasing replacement invoice printers, the parallel port must also be purchased as new black only laser printers don't come with a built in port.  This of course wouldn't be a problem if we could just network attach all the picking station printers.  Also keep in mind that the T650s that print invoices at the picking stations are all using their factory defaults because they are not network attached.  All they need is to be plugged into the HP print server box with a parallel cable and powered on.  If the Lexmark still does not print an invoice then power cycle the HP print server box at the picking station.  If that still doesn't work then check the network cable.  If the green lights on the HP print server box are not blinking rapidly then there is no valid network connection.&lt;br /&gt;
&lt;br /&gt;
The Lexmark printers at the picking stations are not setup as shared network printers from a Windows print server.  The HP boxes are configured as TCPIP printers on the Lucy Jetforms server, but they are not shared so that users can print to them.  The 2 Lexmarks in the office area are setup as shared network printers from SuperServer and are used by staff for general office printing.&lt;br /&gt;
&lt;br /&gt;
 &lt;br /&gt;
BONUS MAGIC SAUCE TIP&lt;br /&gt;
If you need to install a new fuser into the LP05 printer in accounting (C748 model) and the printer refuses to see a brand new fuser as a brand new fuser, reboot the printer while holding down the 2 and the 6 buttons on the front panel.  The printer will boot into a special configuration menu where you have to reset the page counter on the new fuser.  I suppose you could do this same trick when that printer prompts for a new fuser because that printer eats consumables like the fat Austrian kid on the Simpsons eats chocolate.&lt;br /&gt;
&lt;br /&gt;
To reset the T650/52 d/dn maintenance counter turn the power off, hold the check mark and the right arrow while turning on and wait for the 128mb to flash then wait for the config menu.Reset the maintenance clock from there. &lt;br /&gt;
&lt;br /&gt;
Replacing the consumables should be evidence based, the print quality or page count should be used to determine if the consumable actually needs to be changed. Resetting the maintenance counter is sometimes preferred as the consumable being low may be inaccurate. &lt;br /&gt;
&lt;br /&gt;
[[Category:Printing]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Xerox_printers&amp;diff=13842</id>
		<title>Information Systems:Xerox printers</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Xerox_printers&amp;diff=13842"/>
		<updated>2021-05-12T17:30:57Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;uniPHARM uses Xerox printers for office printing (as opposed to Lexmark printers used in the warehouse). These printers are under either lease or managed print service agreements:&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Printer hostname !! Model !! Location / purpose !! Contract type&lt;br /&gt;
|-&lt;br /&gt;
| reccopier || Xerox VersaLink B405DN || Receiving area office || Managed Print Services&lt;br /&gt;
|-&lt;br /&gt;
| rtncopier || Xerox VersaLink B405DN || Returns department || Managed Print Services&lt;br /&gt;
|-&lt;br /&gt;
| elaho || Xerox Versa C60 || 2nd-floor printing alcove || Lease&lt;br /&gt;
|-&lt;br /&gt;
| stein || Xerox AltaLink B8055 || 1st-floor [[:Category:uniPHARM Dictionary|dumps area]] || Lease&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Support info==&lt;br /&gt;
&lt;br /&gt;
* Contact number for leased printers (Xerox One Number): 1-800-275-9376&lt;br /&gt;
* Contact number for printers under Managed Print Services: 1-866-487-4239&lt;br /&gt;
* Contract end date: December 2023 (?)&lt;br /&gt;
&lt;br /&gt;
==Old printers==&lt;br /&gt;
This section is for reference purposes. These printers are no longer being used.&lt;br /&gt;
&lt;br /&gt;
There are 4 different Xerox copier models in use as of 2016.  The Colour C60 is located in the printing alcove on the second floor. The colour touch screen is used to setup copy, scan and fax options.  The has 2 fax lines connected so that it can fax inbound and outbound at the same time.  The C60 is leased and Xerox provides consumable toner and other supplies as part of the lease cost.  Xerox also provides technical support and repairs as part of the lease.  When requesting supplies, repairs or support you must provide the serial number which can be found on the copiers admin page.&lt;br /&gt;
&lt;br /&gt;
:[http://elaho.unipharm.local/ Elaho Administration Web GUI]&lt;br /&gt;
&lt;br /&gt;
*admin&lt;br /&gt;
*1111&lt;br /&gt;
*at this time you must use edge/explorer for web administration. &lt;br /&gt;
Supplies Phone Number 1-800-275-9376 &lt;br /&gt;
Support Phone Number 1-800-275-9376&lt;br /&gt;
&lt;br /&gt;
The WorkCentre 5855 is located next the Supervisors Office in the shipping area of the DC.  It has no colour capability but it does have the ability to fax inbound/outbound.  The supplies the 5855 uses are different from the 7775 and there is a much smaller and less complicated touch screen.  The 5855 is also on the same lease program as the 7775.&lt;br /&gt;
&lt;br /&gt;
:[http://stein.unipharm.local/ Stein Administration Web GUI]&lt;br /&gt;
&lt;br /&gt;
*admin&lt;br /&gt;
*1111&lt;br /&gt;
&lt;br /&gt;
The WorkCentre 4265 copiers are located in the Receiving Office and the Returns Areas in the DC.  They are smaller copiers with fewer paper trays.  They both do have a single fax phone line attached and have very similar software capabilities compared to the 5855 and are on the same lease program as the 5855 and 7775.&lt;br /&gt;
&lt;br /&gt;
:[http://reccopier.unipharm.local/ Reccopier Administration Web GUI]&lt;br /&gt;
:[http://rtncopier.unipharm.local/ Rtncopier Administration Web GUI]&lt;br /&gt;
&lt;br /&gt;
*admin&lt;br /&gt;
*1111&lt;br /&gt;
&lt;br /&gt;
The WorkCentre 6605 copiers are slightly smaller than the 4265s but otherwise perform and behave in the same way.  The 6605s were free from Xerox and are NOT on the lease program and toner and supplies DO need to be purchased for the 2 that are used by the payroll administrator and general manager.  Both of the 6605s are network and fax attached.&lt;br /&gt;
&lt;br /&gt;
==Xerox Fleet Management==&lt;br /&gt;
This is a useful portal site that Xerox provides for leased or managed printers&lt;br /&gt;
* https://office.services.xerox.com/FMP/LoginPage.aspx&lt;br /&gt;
* Username is darrenf@unipharm.com&lt;br /&gt;
* Password is NewVisionIT2051@!&lt;br /&gt;
&lt;br /&gt;
==Xerox Device Agent Software===&lt;br /&gt;
There is an application from Xerox called the Xerox Device Agent, installed on the WDS virtual machine.  This program sends the page meter reads for the copiers in Returns and Receiving to WestX for billing purposes.  This application consumes a lot of CPU time.  DarrenF tried for 4 months to get Xerox and its developers to figure out why a crappy little program uses so much CPU 24/7.  Xerox wasn't willing to acknowledge a problem or allow a conversation to happen with their in-house developers - so the support ticket was closed as unresolved.  The Xerox Device Agent software needs to continue to run and report billing data to WestX so if the CPU usage becomes a problem, try to get a new version of the app or open a new ticket with Xerox and prepare for pain.&lt;br /&gt;
&lt;br /&gt;
This was resolved, it was due to not having the newest version of the app provided by west X , running smooth now.&lt;br /&gt;
&lt;br /&gt;
==Xerox NeckBeard Support==&lt;br /&gt;
On June 13th, 2019, a Xerox technician was called onsite to fix the C60 that was not copying paper in the top feeder or from the glass.  He determined that the OS was corrupt and did a factory reset of the machine which wiped out all of its configuration settings.  He failed to notify anyone that he was doing a factory reset and he failed to create a backup clone file of the configuration to restore.  This caused a great deal of inconvenience and extra work that was not necessary if a clone file was available.  If this dumbfuckery ever happens again, there are saved clone files on the SuperServer in the following location : \\superserver.unipharm.local\Tech\Logs And Backups\Xerox Copier Clone Files\.  In that folder are clone files for all the leased and MPS copiers as of June 2019.  The 2 Xerox MFDs that are used by RonG and AngelaC cannot produce clone files.  In case you haven't caught on, a clone file is a file that contains all the settings that are configured on a printer, with the purpose of &amp;quot;cloning&amp;quot; itself onto another printer of the same model or the exact same one after some asshat decides to do something idiotic.&lt;br /&gt;
&lt;br /&gt;
Xerox support is very helpful, when called they respond within a day. They are willing to teach and leave extra supplies in case of emergent need. Recently the C60 needed to have maintenance, remember that the bottom drawer has a security screw, if need be to release the drawer and unjam the document, replace pick rollers. &lt;br /&gt;
&lt;br /&gt;
The Altalink , also under the service has temporary files that need to be cleared out regularly, this can be scheduled, and takes 20-60 minutes based on what you are clearing. &lt;br /&gt;
Software update performed may 12 2021, with support, to resolve network  card restart issue. &lt;br /&gt;
&lt;br /&gt;
[[Category: Printing]]&lt;br /&gt;
[[Category: Pages with Contact Information]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_Office_2019_Training&amp;diff=13841</id>
		<title>Information Systems:Microsoft Office 2019 Training</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_Office_2019_Training&amp;diff=13841"/>
		<updated>2021-05-11T19:49:36Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Oulook how-to, FAQ */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Microsoft Office 2019 Training=&lt;br /&gt;
&lt;br /&gt;
The following link is provided as a free resource that provides comprehensive training on a variety of topics from basic to more advanced topics for Word 2019, Excel 2019, Powerpoint 2019 and Access 2019.  Feel free to go through this training material on your own if you feel you need a refresher or would like to better familiarize yourself with the new look and features of Office 2019.&lt;br /&gt;
&lt;br /&gt;
https://edu.gcfglobal.org/en/topics/office/&lt;br /&gt;
&lt;br /&gt;
Additional training as needed will be added to this page.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Outlook 2019 Training=&lt;br /&gt;
&lt;br /&gt;
The following link is provided by Microsoft as a free resource that provides an excellent overview of Microsoft Outlook functionality for all platforms.  For most staff Windows and iOS &amp;amp; Android training would be the training courses to focus on as we mainly use Outlook on our work provided Windows computers or as an app on your personal Apple or Android mobile device.&lt;br /&gt;
&lt;br /&gt;
https://support.microsoft.com/en-us/office/outlook-training-8a5b816d-9052-4190-a5eb-494512343cca&lt;br /&gt;
&lt;br /&gt;
=Oulook how-to, FAQ=&lt;br /&gt;
'''Outbox'''-This is holding area for emails that are not yet sent. The outbox is in alphabetical order in the folder tree by default, it may be dragged to any position needed.( this is true for all folders!)&lt;br /&gt;
  &lt;br /&gt;
'''Outbox''' is a folder that holds your emails before sending  either by user choice or because you are offline. By default our outlook clients are set to not delay sending emails so this folder will be empty for most. If there is a need to delay the sending of an email, outbox should be configured to meet that requirement. In outlook options under advanced uncheck send immediately if connected, if you would like all emails to wait in the outbox before sending. &lt;br /&gt;
&lt;br /&gt;
'''Junk Mail'''- If you are in your inbox or any folder that receives email, and there is mail there that you would like to block right click on the email and then  hit junk, then hit  block the sender, from now on that senders emails will go to your junk folder. &lt;br /&gt;
Junk Folder&lt;br /&gt;
&lt;br /&gt;
This is a folder that has emails that have been flagged as junk. It may be in alphabetical order in the list of folders and can be dragged into whatever position is best. &lt;br /&gt;
This folder should be checked regularly when there is missing email, similar to barracuda. If an email is expected and it isn’t in your inbox, check the junk folder then reach out to Information Services. &lt;br /&gt;
&lt;br /&gt;
What to do if….&lt;br /&gt;
*an email is in your junk folder and it shouldn’t you may right click on it and can choose to mark it as not junk.&lt;br /&gt;
*an email is in your inbox  and you always want email from this sender to be junk, hit block sender. &lt;br /&gt;
*an email should never be blocked from a domain ,a mailing list, or a group we can choose to never block the sender  preventing the mail from being marked as junk. &lt;br /&gt;
&lt;br /&gt;
If you select junk mail options you will get choices to change the behaviour of automatic filtering, by default this is off. &lt;br /&gt;
There is a tab that has all the safe senders, recipients and blocked senders, you may unblock someone from here, if accidentally blocked. &lt;br /&gt;
&lt;br /&gt;
*If you are selecting many emails at once you may use the home tab and section that is called delete to find the junk icon with all the same options but can be more easily applied to multiple emails at once. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additional training as needed will be added to this page.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Training]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_Office_2019_Training&amp;diff=13840</id>
		<title>Information Systems:Microsoft Office 2019 Training</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_Office_2019_Training&amp;diff=13840"/>
		<updated>2021-05-11T19:49:15Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Microsoft Office 2019 Training=&lt;br /&gt;
&lt;br /&gt;
The following link is provided as a free resource that provides comprehensive training on a variety of topics from basic to more advanced topics for Word 2019, Excel 2019, Powerpoint 2019 and Access 2019.  Feel free to go through this training material on your own if you feel you need a refresher or would like to better familiarize yourself with the new look and features of Office 2019.&lt;br /&gt;
&lt;br /&gt;
https://edu.gcfglobal.org/en/topics/office/&lt;br /&gt;
&lt;br /&gt;
Additional training as needed will be added to this page.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
=Outlook 2019 Training=&lt;br /&gt;
&lt;br /&gt;
The following link is provided by Microsoft as a free resource that provides an excellent overview of Microsoft Outlook functionality for all platforms.  For most staff Windows and iOS &amp;amp; Android training would be the training courses to focus on as we mainly use Outlook on our work provided Windows computers or as an app on your personal Apple or Android mobile device.&lt;br /&gt;
&lt;br /&gt;
https://support.microsoft.com/en-us/office/outlook-training-8a5b816d-9052-4190-a5eb-494512343cca&lt;br /&gt;
&lt;br /&gt;
=Oulook how-to, FAQ=&lt;br /&gt;
Outbox-This is holding area for emails that are not yet sent. The outbox is in alphabetical order in the folder tree by default, it may be dragged to any position needed.( this is true for all folders!)&lt;br /&gt;
  &lt;br /&gt;
'''Outbox''' is a folder that holds your emails before sending  either by user choice or because you are offline. By default our outlook clients are set to not delay sending emails so this folder will be empty for most. If there is a need to delay the sending of an email, outbox should be configured to meet that requirement. In outlook options under advanced uncheck send immediately if connected, if you would like all emails to wait in the outbox before sending. &lt;br /&gt;
&lt;br /&gt;
'''Junk Mail'''- If you are in your inbox or any folder that receives email, and there is mail there that you would like to block right click on the email and then  hit junk, then hit  block the sender, from now on that senders emails will go to your junk folder. &lt;br /&gt;
Junk Folder&lt;br /&gt;
&lt;br /&gt;
This is a folder that has emails that have been flagged as junk. It may be in alphabetical order in the list of folders and can be dragged into whatever position is best. &lt;br /&gt;
This folder should be checked regularly when there is missing email, similar to barracuda. If an email is expected and it isn’t in your inbox, check the junk folder then reach out to Information Services. &lt;br /&gt;
&lt;br /&gt;
What to do if….&lt;br /&gt;
*an email is in your junk folder and it shouldn’t you may right click on it and can choose to mark it as not junk.&lt;br /&gt;
*an email is in your inbox  and you always want email from this sender to be junk, hit block sender. &lt;br /&gt;
*an email should never be blocked from a domain ,a mailing list, or a group we can choose to never block the sender  preventing the mail from being marked as junk. &lt;br /&gt;
&lt;br /&gt;
If you select junk mail options you will get choices to change the behaviour of automatic filtering, by default this is off. &lt;br /&gt;
There is a tab that has all the safe senders, recipients and blocked senders, you may unblock someone from here, if accidentally blocked. &lt;br /&gt;
&lt;br /&gt;
*If you are selecting many emails at once you may use the home tab and section that is called delete to find the junk icon with all the same options but can be more easily applied to multiple emails at once. &lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
Additional training as needed will be added to this page.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Training]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Exchange_and_Outlook_Administration&amp;diff=13831</id>
		<title>Information Systems:Exchange and Outlook Administration</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Exchange_and_Outlook_Administration&amp;diff=13831"/>
		<updated>2021-05-10T22:26:19Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* How-tos */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==How-tos==&lt;br /&gt;
===Fix default mail app glitch===&lt;br /&gt;
On a computer where the HCL Notes installation preceded the Outlook installation, some applications may continue to invoke Notes when using the &amp;quot;Send via email&amp;quot; function. This occurs even after all the file types, protocols, and default application have been changed in Windows -&amp;gt; Default Programs. 2 examples that can be used to test for or reproduce the problem are Microsoft Excel (File -&amp;gt; Share -&amp;gt; Email) and the old Snipping Tool (right-click on screenshot, then &amp;quot;Send To&amp;quot;). &lt;br /&gt;
&lt;br /&gt;
The fix is to delete the '''HCL Notes''' key (and all its subkeys) in &amp;lt;code&amp;gt;HKEY_LOCAL_MACHINE\SOFTWARE\Clients\Mail&amp;lt;/code&amp;gt;.&lt;br /&gt;
&lt;br /&gt;
this is a link to the outlook troubleshooting page. &lt;br /&gt;
https://docs.microsoft.com/en-us/outlook/troubleshoot/outlook-client-welcome&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
[[Category: Email]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Website_SSL_Certificates&amp;diff=13817</id>
		<title>Information Systems:Website SSL Certificates</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Website_SSL_Certificates&amp;diff=13817"/>
		<updated>2021-05-07T15:47:11Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Certificate Details */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Background==&lt;br /&gt;
uniPHARM hosts several websites using HTTPS and therefore maintains SSL/TLS certificates.&lt;br /&gt;
&lt;br /&gt;
==Certificate Details==&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Website/Service !! Provider !! Managed By !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| unipharm.com || Sectigo || Network Solutions || Exware hosts the site, therefore they provide the CSR, which uniPHARM submits to NS. Cert is provided back to Exware.&lt;br /&gt;
|-&lt;br /&gt;
| medicinecentre.com || LetsEncrypt || Exware || Managed by Exware. This is a LetsEncrypt cert that has 90-day validity. Exware automates the renewals.&lt;br /&gt;
|-&lt;br /&gt;
| secure.medicinecentre.com || Sectigo || Network Solutions || Used for the [https://secure.medicinecentre.com/ website Rx refill form]&lt;br /&gt;
|-&lt;br /&gt;
| orders.unipharm.com (Web Orders) || Sectigo || Network Solutions || Web Orders&lt;br /&gt;
|-&lt;br /&gt;
| infonet.unipharm.com || Sectigo || Network Solutions || Infonet&lt;br /&gt;
|-&lt;br /&gt;
| nts.unipharm.com || Sectigo || Network Solutions || IBM iNotes webmail access, I think Traveler/Verse app too, to some degree&lt;br /&gt;
|-&lt;br /&gt;
| mail.unipharm.com || Sectigo || Network Solutions || Used for secure mail protocols, webmail client portal&lt;br /&gt;
|-&lt;br /&gt;
| infonext.unipharm.com || LetsEncrypt || uniPHARM IT || [[Information_Systems:UWDOSS_-_Open_Source_Development_Server#Renew_SSL_certificate|Must be auto-renewed]].&lt;br /&gt;
|-&lt;br /&gt;
| unipharm.3cx.ca || LetsEncrypt || 3CX || Auto-managed by the 3CX software (likely certbot).&lt;br /&gt;
|-&lt;br /&gt;
| rmtgw.unipharm.com || Sectigo || Network Solutions || Developed and maintained for WFH during COVID-19&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
Network Solutions certificates must be renewed on a yearly basis.&lt;br /&gt;
&lt;br /&gt;
==Notes==&lt;br /&gt;
* The Network Solutions certificates are signed by the AddTrust/USERTrust root CA. These CAs are owned by COMODO/Sectigo.&lt;br /&gt;
* Previously, 2+ year certs were allowed. There was a change in industry that now prevents this to something like 390 days (13 months). Any 2-year options e.g. from Network Solutions is likely now just for accounting/payment convenience i.e. a new cert will still need to be generated ever year.&lt;br /&gt;
&lt;br /&gt;
[[Category: SSL Certificates]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Electronic_Ordering&amp;diff=13813</id>
		<title>Information Systems:Electronic Ordering</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Electronic_Ordering&amp;diff=13813"/>
		<updated>2021-05-06T17:07:04Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Setup for email-based order systems */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Background==&lt;br /&gt;
Electronic ordering is colloquially known as POS ordering. POS systems will be used to refer to software at the store that is used to submit electronic orders to uniPHARM.&lt;br /&gt;
There are two primary ways of ordering from uniPHARM: [[:Category:Web Orders | Web Orders]], and electronic ordering. This section discusses the latter. POS systems are proprietary software (with complementing hardware, in some cases) that communicate with uniPHARM to place orders and, in some cases, retrieve invoices. Most POS systems communicate via FTP, while some send orders via email. For the store, a POS system is a way to do inventory management, as quantities can be managed for each product and thus automated ordering can be set up based on levels of stock. While Web Orders allows for convenient on-demand ordering, POS systems are becoming more and more popular for stores that want better control, automated ordering, and insight into their inventory.&lt;br /&gt;
&lt;br /&gt;
==Setup for email-based order systems==&lt;br /&gt;
As of 2018, uniPHARM is trying to discourage email ordering. POS systems that send orders via email are still supported, but new setups are almost always FTP-based. WinRx is the exception.&lt;br /&gt;
As of the fall of 2020 and spring of 2021 WinRx has an FTP option, however they are slow to roll it out to stores as &amp;quot;not all the stores can handle the change&amp;quot;- ARI. &lt;br /&gt;
&lt;br /&gt;
Email ordering is straightforward and is usually carried out by the software provider.&lt;br /&gt;
&lt;br /&gt;
==Setup for FTP-based order systems==&lt;br /&gt;
&lt;br /&gt;
Upon acquiring a POS/PMS system, either the POS vendor (most cases) or the store will request for credentials to be able to connect their software to our system. Most of the configuration is related to FTP connectivity, as email connectivity (where applicable) is pre-configured.&lt;br /&gt;
&lt;br /&gt;
===Create folders on the Mail server===&lt;br /&gt;
Using remote desktop or Windows Explorer, navigate to the C:\FTPOrders folder on Mail. Create a folder for the store using their account number as the folder name. If one already exists, this indicates that this is the store's 2nd POS system. Append a suffix to the folder. This folder will be the user's home directory.&lt;br /&gt;
&lt;br /&gt;
Within this folder, create '''invoices''', '''orders''' and '''orders\z-archive''' i.e.:&lt;br /&gt;
&lt;br /&gt;
: C:\FTPOrders\12345\invoices&lt;br /&gt;
: C:\FTPOrders\12345\orders&lt;br /&gt;
: C:\FTPOrders\12345\orders\z-archive&lt;br /&gt;
&lt;br /&gt;
 Important: The folder name &amp;quot;z-archive&amp;quot; is because the RPG program that reads the folder reads everything alphabetically. Since an &amp;quot;archive&amp;quot; folder comes alphabetically before the filenames of the order files e.g. &amp;quot;order-102323.pos&amp;quot;, the program skips this folder without error. &lt;br /&gt;
&lt;br /&gt;
===Generate Serv-U account===&lt;br /&gt;
Make an FTP account for the store in Serv-U, matching the username with the home directory (folder) you created in the previous step i.e. '12345K' for C:\FTPOrders\12345K. It is important that the username matches the foldername, as the directory permissions and virtual paths that will be pre-configured are based on this. Generate this password. Specify these additional settings: &lt;br /&gt;
&lt;br /&gt;
* Home directory should be set to the folder '''''that contains''''' the '''invoices''' and '''orders''' subfolders i.e. C:\FTPOrders\12345\ranger&lt;br /&gt;
* Ensure ''Lock home user in directory'' is checked.&lt;br /&gt;
&lt;br /&gt;
Finally, under the Groups tab, add the user to either the POS-Shareholders or POS-Customers groups. '''This step is very important''', as directory permissions and virtual paths are specified accordingly.&lt;br /&gt;
&lt;br /&gt;
'''Note: The process of adding POS FTP users has been simplified through the use of the New User template and groups. For details on these pre-configured settings, check out [[Information Systems:Serv-U FTP Server|this page]].'''&lt;br /&gt;
&lt;br /&gt;
===Create AIP records===&lt;br /&gt;
&lt;br /&gt;
FTP configuration on the i involves two files - one to retrieve order files from our FTP server (mail), and one to write invoices to the same server. A record will need to be added to both files for each store setup:&lt;br /&gt;
&lt;br /&gt;
# In Extensions, use menu option 22 - Work with UWD IT Tools and 30 - FTP connections &lt;br /&gt;
# Add the records below by using menu options 4 and 5. F10 within DFU adds a new record&lt;br /&gt;
&lt;br /&gt;
====4-Order FTP Configuration====&lt;br /&gt;
&lt;br /&gt;
 Name:                   Cust12345                                          &lt;br /&gt;
 Description:            Northview Pharmacy                                 &lt;br /&gt;
 FTP Server:             ftp.unipharm.com                                   &lt;br /&gt;
 FTP User ID:            ftporders               &amp;lt;-- The i uses the same account for all stores to access their folders on the FTP server                           &lt;br /&gt;
 FTP Password:           visionit525                                        &lt;br /&gt;
 FTP Directory:          12345/ranger/orders     &amp;lt;-- Double-check this folder to make sure it's the same as the one you created on the FTP server                           &lt;br /&gt;
 FTP Archive Directory:  z-archive                                            &lt;br /&gt;
 M=Move D=Delete N=None: M                       &amp;lt;-- Use D to just delete files instead of archiving if M doesn't work.                          &lt;br /&gt;
 Transmission Source:    FTP                                                &lt;br /&gt;
 Customer # Type:        UWD                                                                       &lt;br /&gt;
 Ext 1:                  X12                     &amp;lt;-- Use KRO for Kroll, DAT for AssystPOS/AssystRx, X12 for DCS/Ranger , ARI/applied robotics                &lt;br /&gt;
 Ext 2:                                                                     &lt;br /&gt;
 Ext 3:&lt;br /&gt;
&lt;br /&gt;
====5-Invoice FTP Configuration====&lt;br /&gt;
                                                                   &lt;br /&gt;
 Partner:       12345                                              &lt;br /&gt;
 Order Source:                                   &amp;lt;-- Leave blank to set as the catch-all i.e. all other invoices sent to this POS&lt;br /&gt;
 Description:   Northview Pharmacy - Default                       &lt;br /&gt;
 FTP Server:    ftp.unipharm.com                                   &lt;br /&gt;
 FTP User ID:   ftporders                                          &lt;br /&gt;
 FTP Password:  visionit525                                        &lt;br /&gt;
 FTP Directory: 12345/ranger/invoices            &amp;lt;-- Double-check this folder to make sure it is the same as the one you created on the FTP server.&lt;br /&gt;
&lt;br /&gt;
===Creating a second account for a second POS system (if necessary)===&lt;br /&gt;
&lt;br /&gt;
Should a store request setup for a second POS/PMS system, follow the steps above with these additional changes:&lt;br /&gt;
&lt;br /&gt;
# Make their second Serv-U account unique by appending a letter to the end of their username e.g. '''12345K''', for a Kroll installation.&lt;br /&gt;
# Append the same letter when creating new records in the Order ,however create the same customer number .  FTP configuration on the i e.g. 12345K and Cust12345K&lt;br /&gt;
# Create the necessary folders, see instructions in section [[#Create folders on the Mail server | Create folders on the Mail server]]&lt;br /&gt;
&lt;br /&gt;
==POS Systems used by uniPHARM customers==&lt;br /&gt;
This section details previous experiences and general notes about the various POS and PMS systems that interact with uniPHARM. With the exception of WinRx, on-site I.T. staff have no access to the software, so the following information is the result of over-the-phone troubleshooting experience and dealing with the technical support departments of these companies. &lt;br /&gt;
===Telus AssystRx/AssystPOS===&lt;br /&gt;
Also known as Assyst Rx-A&lt;br /&gt;
====Contact information====&lt;br /&gt;
* Company name: Telus Health&lt;br /&gt;
* Phone: 1-888-561-6555&lt;br /&gt;
====Notes/Issues====&lt;br /&gt;
* There are stretches of time where some stores place orders that never reach our system. They may or may not get an order confirmation (most of the time they do not), but there is also no seeming error on their end, leading to the frustrating experience of not receiving an expected delivery the next day. To date, the exact cause of this is unknown, but it is suspected that the Pharmanet connection is the culprit. See [[Pharmanet]] for explanation&lt;br /&gt;
&lt;br /&gt;
* The following an email from Don Yakubowski at Telus Assyst Health that sheds some light on how the mailer works in AssystPOS/AssystRx for sending orders to uniPHARM. &lt;br /&gt;
&lt;br /&gt;
 Ok a few things to clarify here..&lt;br /&gt;
  * The Assyst app relies on the routing as defined on their Unix server..site does not run Assyst Rx-A or POS on a Windows server. Yes..they have windows wkstns, and they are using some &lt;br /&gt;
    Windows based mail application to receive their email replies..the confirmation emails...but the orders outbound to Unipharm originate from the Unix server. &lt;br /&gt;
  * The routing the email order will take follows whatever is defined on Unix server and in this case, since the Pharmanet path is the server's Default gateway with no other &lt;br /&gt;
    Static routing defined....ALL traffic from the Unix server is presently going out the Pnet path.  This is NOT something defined within the Assyst application per se...but is at the Unix level. &lt;br /&gt;
  * To alter the path when a customer is using both Assyst RX-A and POS...and therefore needs to send claims to Pnet from the same Unix server, it is common to leave the Pnet path as&lt;br /&gt;
    The default, and if other destinations should have or must have a non-Pnet path such as their alternative HS router, then we would ADD static routes to the Unix server redirecting that traffic&lt;br /&gt;
    Via the alternate gateway. IN this example, if we wish to keep the Unix server sending Pnet /RX related traffic out Pnet path, and only intervene to have  Unipharm destined order emails &lt;br /&gt;
    Go out thru hsrouter, we would add a route on Unix server like: /etc/route add mail.unipharm.com 192.168.0.2   ( where 0.1 is the def GW Pnet path, and 0.2 is the hsrouter path ). &lt;br /&gt;
  * This routing is not application or protocol specific...it would send anything destined to mail.unipharm.com out this hsrouter path after such a setting got applied. &lt;br /&gt;
    This would also remain in place thru any Unix server reboot as it gets added into server startup scripts that execute every time server is rebooted. &lt;br /&gt;
  * As Norwin pointed out, such routing decisions could not be applied by the Dlink 1024 switch as it is not a Layer 3 ( routing capable ) switch, so the only places to &lt;br /&gt;
    Apply and control routing here are directly on the Unix server itself, or depending on what the actual &amp;quot;router&amp;quot; units are that are installed in this network, on the routers themselves. &lt;br /&gt;
    Some routers can support having &amp;quot;static&amp;quot;routes added into them, others can not.&lt;br /&gt;
    -Don&lt;br /&gt;
&lt;br /&gt;
===RangerPOS===&lt;br /&gt;
====Contact info====&lt;br /&gt;
* Company name: DCS Tech&lt;br /&gt;
&lt;br /&gt;
===CashRx===&lt;br /&gt;
* Company name: CashRx&lt;br /&gt;
* Website: http://www.cashrx.ca/&lt;br /&gt;
&lt;br /&gt;
===KrollRx===&lt;br /&gt;
* Company name: Kroll Systems&lt;br /&gt;
&lt;br /&gt;
===ARI WinRx===&lt;br /&gt;
====Contact info====&lt;br /&gt;
Company name: Applied Robotics Inc.&lt;br /&gt;
&lt;br /&gt;
--[[User:Norwinu|norwinu]] ([[User talk:Norwinu|talk]]) 10:17, 13 July 2015 (PDT) To my limited understanding, a PMS has the functionality of a POS, in that it is able to place orders from uniPHARM, but it also manages the dispensing and inventory of pharmaceuticals.&lt;br /&gt;
&lt;br /&gt;
==Troubleshooting==&lt;br /&gt;
===IOP reporting duplicate POs===&lt;br /&gt;
If IOP reports duplicate POs, delete the files manually on the FTP server. They will likely still be sitting there. Then, set the Orders configuration file to D for delete, or, if it's M, make sure the files are being moved to the archive folder (which might mean renaming the folder).&lt;br /&gt;
&lt;br /&gt;
The AIP programs (RPG) responsible for fetching the order files from ServU via FTP do not read the directory listings elegantly. For example, if there is a folder called archive, and the order files are of the Telus Assyst format e.g. order-1023.pos, then AIP will pick up and process the order, but fail to move the file into the archive folder (for reasons unknown, because the program silently fails). If the folder is re-named z-archive, the M works, but then AIP will log errors every 3 minutes because it's not hardcoded to recognize &amp;quot;z-archive&amp;quot; (although this is an acceptable outcome).&lt;br /&gt;
&lt;br /&gt;
[[Category: Ordering]]&lt;br /&gt;
[[Category: FTP]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Staff_Onboarding_How-To&amp;diff=13812</id>
		<title>Information Systems:Staff Onboarding How-To</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Staff_Onboarding_How-To&amp;diff=13812"/>
		<updated>2021-05-05T22:19:51Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Extra things to check */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This page outlines the process for setting up a new Unipharm employee / staff member.&lt;br /&gt;
&lt;br /&gt;
Main areas where user profiles have to be defined or linked to AD/green-screen profiles:&lt;br /&gt;
* Active Directory domain user&lt;br /&gt;
* IBM i user profile (green-screen/Mocha access)&lt;br /&gt;
* ASW profile for IBM i user&lt;br /&gt;
* UNITY user profile&lt;br /&gt;
* MS365 Mailbox &lt;br /&gt;
* Moodle user (linked to AD user)&lt;br /&gt;
* Unipharm wiki user (linked to AD user)&lt;br /&gt;
* WiNG wireless (staff WiFi)&lt;br /&gt;
* Kofax scanning profile, if applicable (linked to AD user)&lt;br /&gt;
* DocView permissions (IBM i user profile)&lt;br /&gt;
* Xerox scanning profile, if applicable&lt;br /&gt;
&lt;br /&gt;
==Instructions==&lt;br /&gt;
* Create AD user, verify group membership if copying another user, or set manually. &lt;br /&gt;
* Use Navigator or green screen to create IBM i user profile. Also copy existing user for convenience.&lt;br /&gt;
* Go into UNITY (green-screen), System Administration -&amp;gt; OMM Menus -&amp;gt; Work with User Security (if prompted for password, just press Enter).&lt;br /&gt;
* Position to or search for existing user to be used a template, use 8 beside the entry to copy user into a new UNITY user matching green-screen username.&lt;br /&gt;
* Configure MA (menu authority) for new user by entering MA beside their name. F10 to copy from existing user. Leave Menu name blank and just enter the source and target user profiles to copy all menu authorities.&lt;br /&gt;
* Configure FA (functional authority) using FA beside the name. To copy from existing user, type 'USR' in '''Type''', and the source user profile in '''Qualifier'''. Press Enter, and you should see a comparison of the source and target functional authorities. Use F19 (shift F7) to grant missing.&lt;br /&gt;
* Configure ASW user profile [[Information Systems: ASW User Security|using these instructions]]&lt;br /&gt;
&lt;br /&gt;
==Extra things to check==&lt;br /&gt;
Depending on the role of the new employee, the following may also need to be checked and configured in advance:&lt;br /&gt;
&lt;br /&gt;
* Mapped drives&lt;br /&gt;
* Permissions to send to Notes distribution lists&lt;br /&gt;
* SRFax&lt;br /&gt;
*http://owl.unipharm.local/mediawiki/index.php/Information_Systems:Extension_User_Security&lt;br /&gt;
* [[Information Systems:ASW favorites (menu items)|ASW favorites (menu items)]]&lt;br /&gt;
&lt;br /&gt;
[[Category: Staff On-boarding]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Staff_Onboarding_How-To&amp;diff=13811</id>
		<title>Information Systems:Staff Onboarding How-To</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Staff_Onboarding_How-To&amp;diff=13811"/>
		<updated>2021-05-05T20:47:28Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Overview */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This page outlines the process for setting up a new Unipharm employee / staff member.&lt;br /&gt;
&lt;br /&gt;
Main areas where user profiles have to be defined or linked to AD/green-screen profiles:&lt;br /&gt;
* Active Directory domain user&lt;br /&gt;
* IBM i user profile (green-screen/Mocha access)&lt;br /&gt;
* ASW profile for IBM i user&lt;br /&gt;
* UNITY user profile&lt;br /&gt;
* MS365 Mailbox &lt;br /&gt;
* Moodle user (linked to AD user)&lt;br /&gt;
* Unipharm wiki user (linked to AD user)&lt;br /&gt;
* WiNG wireless (staff WiFi)&lt;br /&gt;
* Kofax scanning profile, if applicable (linked to AD user)&lt;br /&gt;
* DocView permissions (IBM i user profile)&lt;br /&gt;
* Xerox scanning profile, if applicable&lt;br /&gt;
&lt;br /&gt;
==Instructions==&lt;br /&gt;
* Create AD user, verify group membership if copying another user, or set manually. &lt;br /&gt;
* Use Navigator or green screen to create IBM i user profile. Also copy existing user for convenience.&lt;br /&gt;
* Go into UNITY (green-screen), System Administration -&amp;gt; OMM Menus -&amp;gt; Work with User Security (if prompted for password, just press Enter).&lt;br /&gt;
* Position to or search for existing user to be used a template, use 8 beside the entry to copy user into a new UNITY user matching green-screen username.&lt;br /&gt;
* Configure MA (menu authority) for new user by entering MA beside their name. F10 to copy from existing user. Leave Menu name blank and just enter the source and target user profiles to copy all menu authorities.&lt;br /&gt;
* Configure FA (functional authority) using FA beside the name. To copy from existing user, type 'USR' in '''Type''', and the source user profile in '''Qualifier'''. Press Enter, and you should see a comparison of the source and target functional authorities. Use F19 (shift F7) to grant missing.&lt;br /&gt;
* Configure ASW user profile [[Information Systems: ASW User Security|using these instructions]]&lt;br /&gt;
&lt;br /&gt;
==Extra things to check==&lt;br /&gt;
Depending on the role of the new employee, the following may also need to be checked and configured in advance:&lt;br /&gt;
&lt;br /&gt;
* Mapped drives&lt;br /&gt;
* Permissions to send to Notes distribution lists&lt;br /&gt;
* SRFax&lt;br /&gt;
* [[Information Systems:ASW favorites (menu items)|ASW favorites (menu items)]]&lt;br /&gt;
&lt;br /&gt;
[[Category: Staff On-boarding]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:SuperServer&amp;diff=13807</id>
		<title>Information Systems:SuperServer</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:SuperServer&amp;diff=13807"/>
		<updated>2021-05-04T20:26:47Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;SuperServer is the file and print server used by all staff.  All user created files such as Word or Excel files need to be saved on the SuperServer.  All of the office area laser printers and copiers are shared from SuperServer.&lt;br /&gt;
&lt;br /&gt;
The OS on this machine is Windows Server 2008R2.  The file and print server role is the only role that is installed on SuperServer.  The C: drive on the SuperServer only contains the OS and small applications for monitoring and controlling the RAID hardware and emailing of faxes.  The D: and E: drives are used for file storage.  Both the D: and E: have Shadow Copies turned on with a 100GB limit and the Shadow Copy service is on a schedule running every 2 hours from 7AM to 6PM daily.  The Shadow Copy service is set to take a snapshot every 2 hours starting at 7AM and stop at 5PM.  Please note that most if not all Cryptolocker malware is able to delete Shadow Copy snapshots.&lt;br /&gt;
&lt;br /&gt;
The structure of the shared folders is either by department or by general function.  Permissions are applied through Active Directory groups with either read or modify permissions.  The &amp;quot;messiness&amp;quot; of the shared folders is mostly under control but there is room for improvement.  There are very large numbers of files that are not used or opened but need to be retained.  Be very careful if files dated as being old are deleted.&lt;br /&gt;
&lt;br /&gt;
Most ( but not all ) users in Active Directory are roaming users which means their user profile on their workstation actually resides as a copy on the D:\Profiles share on the SuperServer.  When a user logs off from their workstation, any file updates get copied to the SuperServer.  Staff using laptops are not roaming users.&lt;br /&gt;
&lt;br /&gt;
Office printers are shared from the SuperServer using a DNS hostname instead of an IP address.  DONT use an IP address to share a printer.  Both 32bit and 64bit drivers are installed for each shared printer.  Try not to use generic universal print drivers, especially for copiers.  Print driver isolation should also be turned on for all print drivers to protect the print spooler from crashing on badly coded print drivers. &lt;br /&gt;
&lt;br /&gt;
All files on all volumes are backed up to tape Monday to Friday nights starting at midnight.  Monthly backups also contain all files and those tapes are not recycled.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
==Changes==&lt;br /&gt;
* On 04-05-21 AaronT replaced the file permissions on the folder , DC supervisors book. Inherited permissions were all removed and the folder was given allow permissions to the security group DC Supervisors, and Deny to the group non supervisors, Full Control to Management and Domain Admins. &lt;br /&gt;
&lt;br /&gt;
[[Category: Servers - Hardware]]&lt;br /&gt;
[[Category: IBM System x Servers]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:SuperServer&amp;diff=13806</id>
		<title>Information Systems:SuperServer</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:SuperServer&amp;diff=13806"/>
		<updated>2021-05-04T20:26:08Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;SuperServer is the file and print server used by all staff.  All user created files such as Word or Excel files need to be saved on the SuperServer.  All of the office area laser printers and copiers are shared from SuperServer.&lt;br /&gt;
&lt;br /&gt;
The OS on this machine is Windows Server 2008R2.  The file and print server role is the only role that is installed on SuperServer.  The C: drive on the SuperServer only contains the OS and small applications for monitoring and controlling the RAID hardware and emailing of faxes.  The D: and E: drives are used for file storage.  Both the D: and E: have Shadow Copies turned on with a 100GB limit and the Shadow Copy service is on a schedule running every 2 hours from 7AM to 6PM daily.  The Shadow Copy service is set to take a snapshot every 2 hours starting at 7AM and stop at 5PM.  Please note that most if not all Cryptolocker malware is able to delete Shadow Copy snapshots.&lt;br /&gt;
&lt;br /&gt;
The structure of the shared folders is either by department or by general function.  Permissions are applied through Active Directory groups with either read or modify permissions.  The &amp;quot;messiness&amp;quot; of the shared folders is mostly under control but there is room for improvement.  There are very large numbers of files that are not used or opened but need to be retained.  Be very careful if files dated as being old are deleted.&lt;br /&gt;
&lt;br /&gt;
Most ( but not all ) users in Active Directory are roaming users which means their user profile on their workstation actually resides as a copy on the D:\Profiles share on the SuperServer.  When a user logs off from their workstation, any file updates get copied to the SuperServer.  Staff using laptops are not roaming users.&lt;br /&gt;
&lt;br /&gt;
Office printers are shared from the SuperServer using a DNS hostname instead of an IP address.  DONT use an IP address to share a printer.  Both 32bit and 64bit drivers are installed for each shared printer.  Try not to use generic universal print drivers, especially for copiers.  Print driver isolation should also be turned on for all print drivers to protect the print spooler from crashing on badly coded print drivers. &lt;br /&gt;
&lt;br /&gt;
All files on all volumes are backed up to tape Monday to Friday nights starting at midnight.  Monthly backups also contain all files and those tapes are not recycled.&lt;br /&gt;
&lt;br /&gt;
* On 04-05-21 AaronT replaced the file permissions on the folder , DC supervisors book. Inherited permissions were all removed and the folder was given allow permissions to the security group DC Supervisors, and Deny to the group non supervisors, Full Control to Management and Domain Admins. *&lt;br /&gt;
&lt;br /&gt;
[[Category: Servers - Hardware]]&lt;br /&gt;
[[Category: IBM System x Servers]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=13792</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=13792"/>
		<updated>2021-04-28T23:23:13Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
&lt;br /&gt;
password&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=13791</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=13791"/>
		<updated>2021-04-28T23:23:00Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
rmtgw.unipharm.com&lt;br /&gt;
&lt;br /&gt;
UNIPHARM\username&lt;br /&gt;
password&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=13786</id>
		<title>Information Systems:Remote Desktop Gateway</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Remote_Desktop_Gateway&amp;diff=13786"/>
		<updated>2021-04-28T20:34:14Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Remote Desktop Gateway&lt;br /&gt;
&lt;br /&gt;
Developed Spring 2020 due to COVID WFH&lt;br /&gt;
&lt;br /&gt;
lives on DC1&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
rmtgw.unipharm.com&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Setting_up_an_IBM_i_printer&amp;diff=13776</id>
		<title>Information Systems:Setting up an IBM i printer</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Setting_up_an_IBM_i_printer&amp;diff=13776"/>
		<updated>2021-04-26T22:35:25Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Set device up in JetForm */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Steps==&lt;br /&gt;
===Configure basic printer settings===&lt;br /&gt;
* Unbox, power on, and network the device.&lt;br /&gt;
* Access the web GUI, fill out device information (name, location, SNMP). &lt;br /&gt;
* Set static IP and other network settings (DNS, gateway etc.). Use an IP within the range for printers (check DNS server or do a network scan). Use Colosoft to scan the network for acceptable IP range. Confirm selection of IP address with nslookup. Leave Netmask and gateway unchanged.&lt;br /&gt;
* Give the device a hostname, using the convention (check DNS server for current printer names).&lt;br /&gt;
* Register the hostname in DNS (domain controllers, or MMC).&lt;br /&gt;
&lt;br /&gt;
===Set device up as a printer on Lucy===&lt;br /&gt;
* Printers that will be used primarily for IBM i printing (i.e. invoice printers) need to be defined on lucy.unipharm.local, as that is where JetForm is installed). Define a printer share here. Follow the naming convention for the device/printer/share name because IBM i has a 10-character limit.&lt;br /&gt;
&lt;br /&gt;
===Set device up as an IBM i network printer===&lt;br /&gt;
* Follow IBM i instructions for setting up a printer as a '''device description''' (of type 3812). This should be done using the CRTDEVD command. Important parameters to note are the manufacturer type/model, the host name, and device description type etc. [https://www.ibm.com/support/pages/information-printers-lexmark This page] will indicate which printer protocol to use, most likely IPP or SNMP (this page is for Lexmark but there are similar pages for other printer manufacturers).&lt;br /&gt;
* Remember to vary on the device and start the printer writer (STRPRTWTR ''printer name'').&lt;br /&gt;
* Test print from IBM i using WRKSPLF and changing the printer on a 1-pager. You may receive a QSYSOPR message such as this when trying to print, in which case you can reply with 'I' to ignore.&lt;br /&gt;
 Load form type '*STD' device L90INV22A writer L90INV22A.&lt;br /&gt;
&lt;br /&gt;
===Set device up as an ASW printer===&lt;br /&gt;
* Log in to ASW.&lt;br /&gt;
* Go to System Management -&amp;gt; System setup -&amp;gt; Printer control tasks -&amp;gt; Work with Jetform printers.&lt;br /&gt;
* F6 to add, enter the device name as configured everywhere else (the 10-character-limit name).&lt;br /&gt;
&lt;br /&gt;
===Set device up in JetForm===&lt;br /&gt;
remote into lucy1 &lt;br /&gt;
open jetforms under file|management|add a printer&lt;br /&gt;
add the printer.&lt;br /&gt;
&lt;br /&gt;
===Add printer in RF print control table===&lt;br /&gt;
unity|start unipharm extensions|VA company|50 warehouse menu|80 IT MENU | 50 update printer control&lt;br /&gt;
&lt;br /&gt;
[[Category: IBM i]]&lt;br /&gt;
[[Category: Printing]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Setting_up_an_IBM_i_printer&amp;diff=13775</id>
		<title>Information Systems:Setting up an IBM i printer</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Setting_up_an_IBM_i_printer&amp;diff=13775"/>
		<updated>2021-04-26T22:33:28Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Add printer in RF print control table */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Steps==&lt;br /&gt;
===Configure basic printer settings===&lt;br /&gt;
* Unbox, power on, and network the device.&lt;br /&gt;
* Access the web GUI, fill out device information (name, location, SNMP). &lt;br /&gt;
* Set static IP and other network settings (DNS, gateway etc.). Use an IP within the range for printers (check DNS server or do a network scan). Use Colosoft to scan the network for acceptable IP range. Confirm selection of IP address with nslookup. Leave Netmask and gateway unchanged.&lt;br /&gt;
* Give the device a hostname, using the convention (check DNS server for current printer names).&lt;br /&gt;
* Register the hostname in DNS (domain controllers, or MMC).&lt;br /&gt;
&lt;br /&gt;
===Set device up as a printer on Lucy===&lt;br /&gt;
* Printers that will be used primarily for IBM i printing (i.e. invoice printers) need to be defined on lucy.unipharm.local, as that is where JetForm is installed). Define a printer share here. Follow the naming convention for the device/printer/share name because IBM i has a 10-character limit.&lt;br /&gt;
&lt;br /&gt;
===Set device up as an IBM i network printer===&lt;br /&gt;
* Follow IBM i instructions for setting up a printer as a '''device description''' (of type 3812). This should be done using the CRTDEVD command. Important parameters to note are the manufacturer type/model, the host name, and device description type etc. [https://www.ibm.com/support/pages/information-printers-lexmark This page] will indicate which printer protocol to use, most likely IPP or SNMP (this page is for Lexmark but there are similar pages for other printer manufacturers).&lt;br /&gt;
* Remember to vary on the device and start the printer writer (STRPRTWTR ''printer name'').&lt;br /&gt;
* Test print from IBM i using WRKSPLF and changing the printer on a 1-pager. You may receive a QSYSOPR message such as this when trying to print, in which case you can reply with 'I' to ignore.&lt;br /&gt;
 Load form type '*STD' device L90INV22A writer L90INV22A.&lt;br /&gt;
&lt;br /&gt;
===Set device up as an ASW printer===&lt;br /&gt;
* Log in to ASW.&lt;br /&gt;
* Go to System Management -&amp;gt; System setup -&amp;gt; Printer control tasks -&amp;gt; Work with Jetform printers.&lt;br /&gt;
* F6 to add, enter the device name as configured everywhere else (the 10-character-limit name).&lt;br /&gt;
&lt;br /&gt;
===Set device up in JetForm===&lt;br /&gt;
&lt;br /&gt;
===Add printer in RF print control table===&lt;br /&gt;
unity|start unipharm extensions|VA company|50 warehouse menu|80 IT MENU | 50 update printer control&lt;br /&gt;
&lt;br /&gt;
[[Category: IBM i]]&lt;br /&gt;
[[Category: Printing]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Printers_And_Picking_Stations_In_The_DC&amp;diff=13772</id>
		<title>Information Systems:Printers And Picking Stations In The DC</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Printers_And_Picking_Stations_In_The_DC&amp;diff=13772"/>
		<updated>2021-04-26T21:45:54Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Recommendations For Future Improvement */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; Information about printers should be moved to these two articles:&lt;br /&gt;
  [[Information Systems:Zebra Thermal printers |Zebra Thermal Printers]]&lt;br /&gt;
  [[Information Systems:Workgroup Laser Printers |Workgroup Laser Printers]]&lt;br /&gt;
 &lt;br /&gt;
 Info about picking stations can remain in this article.&lt;br /&gt;
==Production Printer Fleet Totals==&lt;br /&gt;
 For an updated list, please refer to [[Information_Systems:Workgroup_Laser_Printers |this article]]&lt;br /&gt;
* Lexmark MS415 invoice printer - 1&lt;br /&gt;
* Lexmark T650 invoice printers - 8&lt;br /&gt;
* Lexmark T640 invoice printers - 2&lt;br /&gt;
* Lexmark T630 invoice printers - 1&lt;br /&gt;
* Zebra S4M direct thermal label printers - 20&lt;br /&gt;
* Zebra 2746e label printers - 4 plus 1 using a ribbon for a total of 5&lt;br /&gt;
* Zebra small label printers - 1(GX420t) 1(LP2242) 1(TLP2742) 1(TLP2844) in Returns and Receiving&lt;br /&gt;
&lt;br /&gt;
==Ready Spares Printer Fleet Totals==&lt;br /&gt;
* Lexmark MS521 ready for deployment- need RF control testing :1&lt;br /&gt;
* Lexmark MS521 windows print ready:1&lt;br /&gt;
* Lexmark T650 spare invoice printers - 1&lt;br /&gt;
* Lexmark T640 spare invoice printers - 1&lt;br /&gt;
* Lexmark T630 spare invoice printers - 0&lt;br /&gt;
* Zebra S4M ready spare - 4&lt;br /&gt;
&lt;br /&gt;
==Production Picking Stations==&lt;br /&gt;
* OTC picking station has 1 Lexmark T650 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* HABA picking stations has 1 Lexmark T650 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* LargeDown picking station has 1 Lexmark T650 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* Lower90s picking station has 1 Lexmark T650 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* Pharmies picking station has 1 Lexmark T650 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* HomeHealthCare picking station has 1 Lexmark T650 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* FridgeArea picking station has 1 Lexmark T640 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* NarcCage picking station has 1 Lexmark MS415 and 2 Zebra S4M all connected via parallel cable to an HP print box (Lexmark MS410 also network attached)&lt;br /&gt;
* Candy picking station has 1 Lexmark T640 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* SalesArea picking station has 1 Lexmark T650 and 2 Zebra 2746e all connected via parallel cable to an HP print box&lt;br /&gt;
* TobaccoArea picking station has 1 Lexmark T630 and 2 Zebra 2746e all connected via parallel cable to an HP print box (yes they still pick here)&lt;br /&gt;
&lt;br /&gt;
==Other Laser Printer Or Label Printers In The DC==&lt;br /&gt;
* Mail slots desk in shipping has a Zebra S4M connected to an HP print box&lt;br /&gt;
* DC Supervisors office has a Zebra 2746e connected to a Lexmark print box under the desk using a ribbon to print shelf labels&lt;br /&gt;
* The cold chain receiving workstation in Receiving has a Zebra TLP 2844 connected via parallel cable to print item labels&lt;br /&gt;
* The desktop that JeffP uses has a parallel cable attached Zebra LP2242 used to print item labels&lt;br /&gt;
* The desktop that DexterG uses has a parallel cable attached Zebra TLP2742 used to print item labels&lt;br /&gt;
* There is a network attached Zebra GX420t label printer that BarryF uses for item labels&lt;br /&gt;
* Under the mezzanine in Receiving there is a Zebra S4M attached to an HP print box that is used to print license plates&lt;br /&gt;
&lt;br /&gt;
==Recommendations For Future Improvement==&lt;br /&gt;
* According to Gerald if the Buyers moved items out of the &amp;quot;Tobacco Area&amp;quot; into some other spot in the warehouse then we could take the printers from that picking station and make them spares- this was done&lt;br /&gt;
* License plate label printer in Receiving may not need to be there because any S4M can print license plates&lt;br /&gt;
* The high traffic picking stations have network cabling that can be used to network attach printers without the use of a HP print box, but tracing and terminating those network cables doesn't happen instantaneously.&lt;br /&gt;
* Something think about is that Zebra has industrial spec label printers similar to the S4M that can connect via wifi which would greatly simplify the cabling mess in the DC&lt;br /&gt;
* If we are to use the Lexmark MS521 printers then we have to have the corresponding cable termination supplies and tools&lt;br /&gt;
* Pictures (some blurry) of all the printers mentioned on this page are available on the SuperServer in Tech\Common&lt;br /&gt;
&lt;br /&gt;
==Links To Other Printer Wiki Pages==&lt;br /&gt;
* Mobile_belt_printers[[http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:Mobile_belt_printers]]&lt;br /&gt;
* Lexmark_printers[[http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:Lexmark_printers]]&lt;br /&gt;
* Xerox_printers[[http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:Xerox_printers]]&lt;br /&gt;
* Zebra_Thermal_printers[[http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:Zebra_Thermal_printers]]&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
* This page is current as of July 2, 2019&lt;br /&gt;
* If an invoice printer fails to print , check lucy1 and the print manager for the spooler ,services to make sure they are running. &lt;br /&gt;
[[Category:Printing]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Printers_And_Picking_Stations_In_The_DC&amp;diff=13771</id>
		<title>Information Systems:Printers And Picking Stations In The DC</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Printers_And_Picking_Stations_In_The_DC&amp;diff=13771"/>
		<updated>2021-04-26T21:44:51Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Ready Spares Printer Fleet Totals */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt; Information about printers should be moved to these two articles:&lt;br /&gt;
  [[Information Systems:Zebra Thermal printers |Zebra Thermal Printers]]&lt;br /&gt;
  [[Information Systems:Workgroup Laser Printers |Workgroup Laser Printers]]&lt;br /&gt;
 &lt;br /&gt;
 Info about picking stations can remain in this article.&lt;br /&gt;
==Production Printer Fleet Totals==&lt;br /&gt;
 For an updated list, please refer to [[Information_Systems:Workgroup_Laser_Printers |this article]]&lt;br /&gt;
* Lexmark MS415 invoice printer - 1&lt;br /&gt;
* Lexmark T650 invoice printers - 8&lt;br /&gt;
* Lexmark T640 invoice printers - 2&lt;br /&gt;
* Lexmark T630 invoice printers - 1&lt;br /&gt;
* Zebra S4M direct thermal label printers - 20&lt;br /&gt;
* Zebra 2746e label printers - 4 plus 1 using a ribbon for a total of 5&lt;br /&gt;
* Zebra small label printers - 1(GX420t) 1(LP2242) 1(TLP2742) 1(TLP2844) in Returns and Receiving&lt;br /&gt;
&lt;br /&gt;
==Ready Spares Printer Fleet Totals==&lt;br /&gt;
* Lexmark MS521 ready for deployment- need RF control testing :1&lt;br /&gt;
* Lexmark MS521 windows print ready:1&lt;br /&gt;
* Lexmark T650 spare invoice printers - 1&lt;br /&gt;
* Lexmark T640 spare invoice printers - 1&lt;br /&gt;
* Lexmark T630 spare invoice printers - 0&lt;br /&gt;
* Zebra S4M ready spare - 4&lt;br /&gt;
&lt;br /&gt;
==Production Picking Stations==&lt;br /&gt;
* OTC picking station has 1 Lexmark T650 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* HABA picking stations has 1 Lexmark T650 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* LargeDown picking station has 1 Lexmark T650 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* Lower90s picking station has 1 Lexmark T650 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* Pharmies picking station has 1 Lexmark T650 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* HomeHealthCare picking station has 1 Lexmark T650 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* FridgeArea picking station has 1 Lexmark T640 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* NarcCage picking station has 1 Lexmark MS415 and 2 Zebra S4M all connected via parallel cable to an HP print box (Lexmark MS410 also network attached)&lt;br /&gt;
* Candy picking station has 1 Lexmark T640 and 2 Zebra S4M all connected via parallel cable to an HP print box&lt;br /&gt;
* SalesArea picking station has 1 Lexmark T650 and 2 Zebra 2746e all connected via parallel cable to an HP print box&lt;br /&gt;
* TobaccoArea picking station has 1 Lexmark T630 and 2 Zebra 2746e all connected via parallel cable to an HP print box (yes they still pick here)&lt;br /&gt;
&lt;br /&gt;
==Other Laser Printer Or Label Printers In The DC==&lt;br /&gt;
* Mail slots desk in shipping has a Zebra S4M connected to an HP print box&lt;br /&gt;
* DC Supervisors office has a Zebra 2746e connected to a Lexmark print box under the desk using a ribbon to print shelf labels&lt;br /&gt;
* The cold chain receiving workstation in Receiving has a Zebra TLP 2844 connected via parallel cable to print item labels&lt;br /&gt;
* The desktop that JeffP uses has a parallel cable attached Zebra LP2242 used to print item labels&lt;br /&gt;
* The desktop that DexterG uses has a parallel cable attached Zebra TLP2742 used to print item labels&lt;br /&gt;
* There is a network attached Zebra GX420t label printer that BarryF uses for item labels&lt;br /&gt;
* Under the mezzanine in Receiving there is a Zebra S4M attached to an HP print box that is used to print license plates&lt;br /&gt;
&lt;br /&gt;
==Recommendations For Future Improvement==&lt;br /&gt;
* According to Gerald if the Buyers moved items out of the &amp;quot;Tobacco Area&amp;quot; into some other spot in the warehouse then we could take the printers from that picking station and make them spares&lt;br /&gt;
* License plate label printer in Receiving may not need to be there because any S4M can print license plates&lt;br /&gt;
* The high traffic picking stations have network cabling that can be used to network attach printers without the use of a HP print box, but tracing and terminating those network cables doesn't happen instantaneously.&lt;br /&gt;
* Something think about is that Zebra has industrial spec label printers similar to the S4M that can connect via wifi which would greatly simplify the cabling mess in the DC&lt;br /&gt;
* If we are to use the Lexmark MS521 printers then we have to have the corresponding cable termination supplies and tools&lt;br /&gt;
* Pictures (some blurry) of all the printers mentioned on this page are available on the SuperServer in Tech\Common&lt;br /&gt;
&lt;br /&gt;
==Links To Other Printer Wiki Pages==&lt;br /&gt;
* Mobile_belt_printers[[http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:Mobile_belt_printers]]&lt;br /&gt;
* Lexmark_printers[[http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:Lexmark_printers]]&lt;br /&gt;
* Xerox_printers[[http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:Xerox_printers]]&lt;br /&gt;
* Zebra_Thermal_printers[[http://elearning.unipharm.local:8080/mediawiki/index.php/Information_Systems:Zebra_Thermal_printers]]&lt;br /&gt;
&lt;br /&gt;
==Changelog==&lt;br /&gt;
* This page is current as of July 2, 2019&lt;br /&gt;
* If an invoice printer fails to print , check lucy1 and the print manager for the spooler ,services to make sure they are running. &lt;br /&gt;
[[Category:Printing]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_365_Exchange_Online_-_Setup_and_Configuration&amp;diff=13753</id>
		<title>Information Systems:Microsoft 365 Exchange Online - Setup and Configuration</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_365_Exchange_Online_-_Setup_and_Configuration&amp;diff=13753"/>
		<updated>2021-04-26T18:14:18Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* SPF */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This wiki page attempts to document and discuss major topics of Exchange setup and configuration. This will be a mix of design/strategy talk and some how-tos for technical administration. Ultimately, another page should be made to adapt the information discussed here into more concise technical instructions for specific administration tasks.&lt;br /&gt;
&lt;br /&gt;
==Mailboxes==&lt;br /&gt;
Users are essentially mailboxes in Exchange i.e. there is no Users section. In Exchange Online, a mailbox shows up when a user is created in 365 Admin Center.&lt;br /&gt;
&lt;br /&gt;
===Shared Mailboxes===&lt;br /&gt;
Like groups/lists, shared mailboxes are communal to a group of users. But unlike groups/lists, they are actual mailboxes that accumulate mail. The company requires a few of these:&lt;br /&gt;
* Accounts Payable: accountspayable@unipharm.com&lt;br /&gt;
* Accounts Receivable: accountsreceivable@unipharm.com&lt;br /&gt;
* EDI Support: edisupport@unipharm.com&lt;br /&gt;
* Customer Service Voicemail: csvm@unipharm.com&lt;br /&gt;
&lt;br /&gt;
====Adding a shared mailbox====&lt;br /&gt;
 Given the limited number of shared mailboxes, and the company's particular use of them as mailbox &amp;quot;identities&amp;quot; rather than a communal email &amp;quot;sink&amp;quot;, it has been decided to add shared mailboxes as separate accounts as opposed to opening them as additional mailboxes.&lt;br /&gt;
&lt;br /&gt;
To add a shared mailbox:&lt;br /&gt;
* Remove any shared mailboxes previously opened as additional mailboxes (and not added as accounts).&lt;br /&gt;
* Perform the steps to add another email account (Office 365).&lt;br /&gt;
* Enter in the shared mailbox email.&lt;br /&gt;
* Instead of entering a password, click ''Sign in as another account''.&lt;br /&gt;
* Enter in the user's credentials. This will only work if the user has Full Access permissions to the shared mailbox (do this in EAC).&lt;br /&gt;
&lt;br /&gt;
====Other methods====&lt;br /&gt;
The other ways of adding shared mailboxes are discussed here just for reference:&lt;br /&gt;
&lt;br /&gt;
'''''Manually opening a shared mailbox'''''&lt;br /&gt;
:* In Outlook 2019, File -&amp;gt; Account Settings -&amp;gt; double-click account -&amp;gt; More Settings -&amp;gt; Advanced&lt;br /&gt;
:* In the Mailboxes section -&amp;gt; Add -&amp;gt; Enter exact Display Name of shared mailbox&lt;br /&gt;
:* Save/Apply&lt;br /&gt;
&lt;br /&gt;
'''''Automapping'''''&lt;br /&gt;
:'''Note: Automapping has been disabled for all shared mailboxes.'''&lt;br /&gt;
&lt;br /&gt;
:* Automapping is a feature that makes the shared mailboxes which a user has access to automatically visible in Outlook i.e. the shared mailboxes are automatically mapped to the user. This is enabled by default. There are implications:&lt;br /&gt;
::* Automapping lumps the data of shared mailboxes in the same OST file as the user's own mailbox. This is one of the reasons there is official documentation on how to disable automapping and [https://docs.microsoft.com/en-us/outlook/troubleshoot/profiles-and-accounts/remove-automapping-for-shared-mailbox how to reset an automapped Outlook configuration]. Considering the company's user base and computer/desktop assignments, this isn't expected to be a problem. But it's something to keep aware of. Imagine a case of 3 users that access 2 shared mailboxes ecah including their own, all logging in to the same computer with a 120GB SSD, with Outlook set to sync all mail. It is feasible for this to grow massively.&lt;br /&gt;
::* Automapping appears to be very finicky when mailbox delegation (permissions) are set to security groups instead of users. Discussion on the internet refers to having to reset permissions.&lt;br /&gt;
&lt;br /&gt;
==Contacts and Groups==&lt;br /&gt;
===Contacts===&lt;br /&gt;
Contacts are non-Exchange users i.e. either external to the organization e.g. a shareholder store. For now, the primary use of contacts is the distribution lists. Unlike in the previous Lotus Notes system where these contacts were merely email addresses e.g. &amp;quot;strings&amp;quot;, contacts in Exchange are &amp;quot;objects&amp;quot; and therefore have attributes like Company, First Name, Phone Number etc. This makes it feasible to have a directory of external contacts instead of just internal users.&lt;br /&gt;
====Shareholder email addresses====&lt;br /&gt;
 Note: It is not yet a company policy to maintain an address book of individual shareholder emails in Exchange/Outlook. These contacts are maintained for the sake of the mailing lists.&lt;br /&gt;
In an attempt to maintain clean and consistent entries, several conventions have already been put into play, best depicted in the following example entry for the personal email associated with Marks Marine Pharmacy (the one that would go in the private/sensitive list). The Classic Exchange admin center is shown as it exposes more fields:&lt;br /&gt;
::[[File:2021-03-06 22_15_29-Edit Mail Contact.png|400px|border]]&lt;br /&gt;
&lt;br /&gt;
Recommendations when creating new entries:&lt;br /&gt;
* If this contact/email will be used in private/confidential list only, prefix the Display Name with [Private]. Also, check the 'Hide contacts from the address list'. You may need to do this in Classic EAC.&lt;br /&gt;
* If this contact will be a member of both private and general/publicly-visible distribution lists, do not prefix the name.&lt;br /&gt;
&lt;br /&gt;
===Groups===&lt;br /&gt;
{{quote|03/31/2021 - Take these docs with a grain of salt, there's a lot of changes right now}}&lt;br /&gt;
The term groups in Exchange is encompassing of distribution lists and security groups (permissions). There are 4 types of Exchange groups. The two used primarily are ''Distribution list'' groups and ''Mail security'' groups. The former is equivalent to the idea of a conventional mailing list, wherein an email sent to the group address is distributed to its members. The latter is used for assigning permissions.&lt;br /&gt;
====Distribution Lists====&lt;br /&gt;
* The email address convention for department-based groups (and most other groups) is ''department''group@unipharm.com&lt;br /&gt;
* The following is an example of a configured group. The manager has been specified as a group owner in addition to IT to enable self-management.&lt;br /&gt;
::[[File:2021-03-06 14_41_32-Exchange admin center.png|300px|border]]&lt;br /&gt;
* Some groups are meant to be internal (e.g IT group), while others are meant to also be addressable by users outside the organization (e.g. Returns). Check related permissions and set up aliases accordingly. For example, Returns group follows the convention returnsgroup@unpharm.com, but it is logical to have '''returns@unipharm.com''' as an alias, as this is a more common format for a public-facing contact email address (same as customerservice@unipharm.com).&lt;br /&gt;
::[[File:2021-03-06 14_58_33-Exchange admin center.png|200px|border]]&lt;br /&gt;
&lt;br /&gt;
====Shareholder mailing lists====&lt;br /&gt;
There exist several mailing lists for correspondence with shareholders and associate members. Refer to the Contacts section above for how shareholder email addresses are maintained.&lt;br /&gt;
&lt;br /&gt;
====Sensitive mailing lists====&lt;br /&gt;
A few of the distribution lists are for sending confidential information to shareholders and associate members, and therefore have the 'Specified senders' permissons set. The option to prevent these lists and their constituent contacts from being displayed in the global address book should also be checked. The ability to hide contacts from address lists appears to currently be available only in the Classic admin center:&lt;br /&gt;
::[[File:2021-03-06 16_53_57-Edit Mail Contact.png|400px|border]]&lt;br /&gt;
====Other group types====&lt;br /&gt;
* '''Microsoft 365 groups''' have additional functionality to enable better collaboration for the group's members. The company currently does not collaborate in such a fashion for these to be useful (e.g. no Sharepoint, no Teams, no shared folders on cloud storage).&lt;br /&gt;
* '''Dynamic distribution list''' is a good concept on paper as it allows distribution lists to be &amp;quot;self-adjusting&amp;quot; based on attributes e.g. a Customer Service list could be set up to include any users with the Department attribute set to Customer Service. However, it was tested to have one major showstopping limitation - the dynamic nature of the list (recipients determined at the time of send) means it is not possible to view members of that list (neither in Outlook when trying to send to the list, or in the admin console). Not being able to see the recipients severely limits its usefulness, and therefore, setting up dynamic lists was forgone as an endeavor to potentially ease contact group administration. &lt;br /&gt;
====Nested groups====&lt;br /&gt;
'''A word of caution regarding nested groups.'''&lt;br /&gt;
&lt;br /&gt;
Nesting groups within other groups generally makes sense when it comes to permissions. This is especially true with Microsoft AD, where object hierarchy and the concept of RBAC are predominant (a user can be assigned one or more roles, which grants them the specific set of permissions associated with those roles). However, issues have been encountered with group nesting during setup, primarily related to &amp;quot;trying to get too fancy&amp;quot;. The ultimate goal was to have permissions and group membership dynamically assigned based on attribute e.g. the user's department. This was found to not even be remotely achievable in Exchange. These general rules of thumb have been surmised from experimentation with group nesting:&lt;br /&gt;
&lt;br /&gt;
* Nesting like group types appears to work. Distribution lists groups are ok to nest within other distribution list groups. The same goes for mail security groups.&lt;br /&gt;
* Nesting security groups can lead to some quirks, but is still recommended. For example, nested security groups seems to break shared mailbox automapping and ownership.&lt;br /&gt;
* Distribution list groups should not be nested within security groups (see point #1).&lt;br /&gt;
&lt;br /&gt;
TL;DR - exercise caution when using group nesting, and assign permissions to users as a fallback (troubleshoot later).&lt;br /&gt;
&lt;br /&gt;
==Address Book==&lt;br /&gt;
With Exchange address books, there exists two types of implementations: out-of-the-box or address book policies. This fork on the road comes early; either accept the out of the box functionality and do nothing else, or enter the world of address book policy routing and accept the more complex management. This of course depends on the needs of the company, and we needed and decided on the latter. This path also requires PowerShell (no options or visibility exists in EAC, besides the ability to assign an existing policy (created with PowerShell) to a user).&lt;br /&gt;
&lt;br /&gt;
===Address book policies===&lt;br /&gt;
An address book policy allows you to customize what a user sees, from the sublists, to the contacts viewable in those sublists. For example, the default address book policy has the following address lists: All Groups, All Users, All Distribution Lists etc. It is both unintuitive if you are not fully invested in the Microsoft way. For example, we don't use Microsoft groups, so All Groups is empty, and what we know as groups are actually, Distribution Lists. All Users, on the other hand, contains staff, but also shared mailboxes and resources (Projector, iPad), but not rooms. To make even one customization to all of this, ABPs are needed. &lt;br /&gt;
&lt;br /&gt;
* ABP routing is an Exchange flag that has been enabled for our domain.&lt;br /&gt;
* An address book policy specifies the following:&lt;br /&gt;
: * 1 x '''Global Address List (GAL)''' - contains all objects (mailboxes, contacts, rooms etc.) that a user is able to &amp;quot;see&amp;quot;. An ABP is linked to 1 GAL and therefore a user can only see 1 GAL.&lt;br /&gt;
: * 1 x '''Offline Address Book (OAB)''' - specifies one or more address lists to download/cache. To make it more confusing, the Offline Address Book behaves more like an address list.&lt;br /&gt;
: * 1 x '''Room Address List'''&lt;br /&gt;
: * 1 or more custom (or built-in) '''Address Lists''' - Address Lists are groupings that are subsetted from the GAL. For example, the built-in All Rooms address list filters for GAL objects where the ObjectType is RoomMailbox (not quite, but something to that effect).&lt;br /&gt;
&lt;br /&gt;
Again, all these are created/set in PowerShell.&lt;br /&gt;
&lt;br /&gt;
====Current address book policies====&lt;br /&gt;
There are two ABPs (default still exists but is not meant to be used).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Address Book Policy !! Global Address List !! Offline Address Book -&amp;gt; Offline Address List !! Room List !! Address Lists !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| Staff Address Book Policy || Staff Global Address List || Staff Offline Address Book -&amp;gt; Offline Address List (Staff) || Rooms and Resources || Company Contacts, Distribution Lists, Staff, Public Folders || Should be the default assigned to staff members.&lt;br /&gt;
|-&lt;br /&gt;
| Executive Address Book Policy || Executive Global Address List || Executive Offline Address Book -&amp;gt; Offline Address List (Executive) || Rooms and Resources || Company Contacts, Company Contacts (Executive), Distribution Lists, Distribution Lists (Executive), Staff, Public Folders || Can see what staff see, and the private lists/contacts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
''Congrats if you're still following at this point.''&lt;br /&gt;
&lt;br /&gt;
====Address Lists and Filtering====&lt;br /&gt;
The usefuleness of address book policies lies in filtering (inclusion filtering), which is used to produce address lists. This is a big topic and is mostly PowerShell talk. Therefore, this is left for official technical docs, but provided are two examples to try and explain the concept:&lt;br /&gt;
* The address list '''Distribution Lists (Executive)''' specifies a filter that translates to: &lt;br /&gt;
:Include only objects where:&lt;br /&gt;
::* ObjectClass equals 'group'&lt;br /&gt;
::* DisplayName is like '*(Private)'&lt;br /&gt;
* The address list '''Staff''' specifies a filter that translates to:&lt;br /&gt;
::Include only objects where:&lt;br /&gt;
::* ObjectCategory equals 'person' AND 'user'&lt;br /&gt;
::* RecipientType does not equal 'RoomMailbox'&lt;br /&gt;
::* RecipientType does not equal 'EquipmentMailbox'&lt;br /&gt;
&lt;br /&gt;
''These are not the exact filters used, they're meant to explain the concept only.''&lt;br /&gt;
&lt;br /&gt;
====Relationship between contact management and ABPs====&lt;br /&gt;
It should be noted that contacts, groups, and group membership are not affected by address book policies. ABPs only affect what a user sees in the address book. A not-good analogy: you can take out pages of a phone directory and group them differently or put stickers over some entries so they're not visible (ABPs), but you don't change what's printed in the directory (that's contact management).&lt;br /&gt;
&lt;br /&gt;
==Mail flow and mail rules==&lt;br /&gt;
===Connectors===&lt;br /&gt;
Because mail hosting for unipharm.com is spread over 2 servers, configuring Exchange &amp;quot;connectors&amp;quot; is necessary to properly route mail to and from MDaemon (the on-prem mail server). This is a complex topic and should be described on another page.&lt;br /&gt;
&lt;br /&gt;
==Email security==&lt;br /&gt;
Email security is handled by Exchange Online Protection, a feature that comes with all Exchange Online / 365 accounts. It &amp;quot;sits&amp;quot; before the mail routing/delivery process - for both inbound and outbound mail flows - and checks messages for threats and spam. The policies determine what gets detected as spam/threats and the outcome of those messages. Depending on if the new or classic admin portal is being used, there are various areas to configure or tweak these policies:&lt;br /&gt;
:* In Classic Admin Center, these policies are found in the '''protection''' section.&lt;br /&gt;
:* In New Admin Center, these policies are found in a separate '''Security and Compliance''' Admin Center altogether, under '''Threat management'''.&lt;br /&gt;
&lt;br /&gt;
===Malware policies===&lt;br /&gt;
* Email servers do a fairly good job detecting and blocking viruses in emails, silently. As an organization, we also don't deal with attachment types (.exe, audio/video containers etc.) that are normally flagged as viruses. Therefore, these policies have not been changed from the defaults. &lt;br /&gt;
&lt;br /&gt;
===Spam policies===&lt;br /&gt;
* Unlike spam-handling pre-Exchange that involved a user quarantine, the current spam policy is set to direct spam to a user's junk folder.&lt;br /&gt;
:[[File:2021-03-30 15_50_03-edit spam filter policy.png|400px]]&lt;br /&gt;
&lt;br /&gt;
====Spam scoring====&lt;br /&gt;
There are two scores related to spam-handling: SCL (Spam Confidence Level), and BCL (Bulk Complaint Level). The Bulk Complaint Level threshold can be set, but the SCL appears to be set (at least for Exchange Online). These values are 5 (spam) and 9 (high-confidence spam), according to [https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/spam-confidence-levels?view=o365-worldwide the docs]&lt;br /&gt;
&lt;br /&gt;
Note: These scores are present in the message headers, and have been validated to make it all the way to MDaemon (in messages destined for non-Exchange mailboxes). Therefore, we could potentially capitalize on the spam and bulk scoring done by EOP by having MDaemon recognize and act on these headers.&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
Phishing remains the greatest threat when it comes to email security. Without Advanced Threat Prection (additional cost on top of EOP), we rely on reputation-based and heuristic-based detection mechanisms of the email security service (EOP) to flag emails that contain phishing content. Barracuda did a fantastic job (very low penetration from empirical evidence). It remains to be seen how EOP handles these types of &amp;quot;attacks&amp;quot; (they come in waves).&lt;br /&gt;
&lt;br /&gt;
==Security/AAA==&lt;br /&gt;
===Custom Admin Roles===&lt;br /&gt;
Exchange allows for the creation of custom admin roles that have a specific combination of permissions. For example, the Company Directory Management role was created to allow users to manage the address book:&lt;br /&gt;
::[[File:2021-03-23 11_58_18-Exchange admin center.png|400px]]&lt;br /&gt;
&lt;br /&gt;
===Password policies===&lt;br /&gt;
* Password expiry has been disabled in 365 from the 90-day default:&lt;br /&gt;
::[[File:2021-03-23 12_14_04-Microsoft 365 admin center.png|border|400px]]&lt;br /&gt;
* Self-service password resets have been enabled in Azure AD. Users will be notified when they reset their passwords:&lt;br /&gt;
::[[File:2021-03-23 12_21_01-Password reset - Azure Active Directory admin center.png|400px|border]][[File:2021-03-23 12_23_00-Password reset - Azure Active Directory admin center.png|400px|border]]&lt;br /&gt;
* (Update this section with info on password management strategy when it gets discussed)&lt;br /&gt;
&lt;br /&gt;
==Other Notes==&lt;br /&gt;
* Microsoft is currently transitioning from what they're now terming Classic Exchange admin center to the New Exchange admin center. Some options remain editable only in the old portal.&lt;br /&gt;
&lt;br /&gt;
==SPF==&lt;br /&gt;
SPF has been enabled, https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/set-up-spf-in-office-365-to-help-prevent-spoofing?view=o365-worldwide, &lt;br /&gt;
Using a company like mxtoolbox, we can put in the email that we want to check the SPF record for and see how it is set.&lt;br /&gt;
::[[File:mtoolboxupipharmspf.png]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_365_Exchange_Online_-_Setup_and_Configuration&amp;diff=13752</id>
		<title>Information Systems:Microsoft 365 Exchange Online - Setup and Configuration</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_365_Exchange_Online_-_Setup_and_Configuration&amp;diff=13752"/>
		<updated>2021-04-26T18:10:03Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* SPF */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This wiki page attempts to document and discuss major topics of Exchange setup and configuration. This will be a mix of design/strategy talk and some how-tos for technical administration. Ultimately, another page should be made to adapt the information discussed here into more concise technical instructions for specific administration tasks.&lt;br /&gt;
&lt;br /&gt;
==Mailboxes==&lt;br /&gt;
Users are essentially mailboxes in Exchange i.e. there is no Users section. In Exchange Online, a mailbox shows up when a user is created in 365 Admin Center.&lt;br /&gt;
&lt;br /&gt;
===Shared Mailboxes===&lt;br /&gt;
Like groups/lists, shared mailboxes are communal to a group of users. But unlike groups/lists, they are actual mailboxes that accumulate mail. The company requires a few of these:&lt;br /&gt;
* Accounts Payable: accountspayable@unipharm.com&lt;br /&gt;
* Accounts Receivable: accountsreceivable@unipharm.com&lt;br /&gt;
* EDI Support: edisupport@unipharm.com&lt;br /&gt;
* Customer Service Voicemail: csvm@unipharm.com&lt;br /&gt;
&lt;br /&gt;
====Adding a shared mailbox====&lt;br /&gt;
 Given the limited number of shared mailboxes, and the company's particular use of them as mailbox &amp;quot;identities&amp;quot; rather than a communal email &amp;quot;sink&amp;quot;, it has been decided to add shared mailboxes as separate accounts as opposed to opening them as additional mailboxes.&lt;br /&gt;
&lt;br /&gt;
To add a shared mailbox:&lt;br /&gt;
* Remove any shared mailboxes previously opened as additional mailboxes (and not added as accounts).&lt;br /&gt;
* Perform the steps to add another email account (Office 365).&lt;br /&gt;
* Enter in the shared mailbox email.&lt;br /&gt;
* Instead of entering a password, click ''Sign in as another account''.&lt;br /&gt;
* Enter in the user's credentials. This will only work if the user has Full Access permissions to the shared mailbox (do this in EAC).&lt;br /&gt;
&lt;br /&gt;
====Other methods====&lt;br /&gt;
The other ways of adding shared mailboxes are discussed here just for reference:&lt;br /&gt;
&lt;br /&gt;
'''''Manually opening a shared mailbox'''''&lt;br /&gt;
:* In Outlook 2019, File -&amp;gt; Account Settings -&amp;gt; double-click account -&amp;gt; More Settings -&amp;gt; Advanced&lt;br /&gt;
:* In the Mailboxes section -&amp;gt; Add -&amp;gt; Enter exact Display Name of shared mailbox&lt;br /&gt;
:* Save/Apply&lt;br /&gt;
&lt;br /&gt;
'''''Automapping'''''&lt;br /&gt;
:'''Note: Automapping has been disabled for all shared mailboxes.'''&lt;br /&gt;
&lt;br /&gt;
:* Automapping is a feature that makes the shared mailboxes which a user has access to automatically visible in Outlook i.e. the shared mailboxes are automatically mapped to the user. This is enabled by default. There are implications:&lt;br /&gt;
::* Automapping lumps the data of shared mailboxes in the same OST file as the user's own mailbox. This is one of the reasons there is official documentation on how to disable automapping and [https://docs.microsoft.com/en-us/outlook/troubleshoot/profiles-and-accounts/remove-automapping-for-shared-mailbox how to reset an automapped Outlook configuration]. Considering the company's user base and computer/desktop assignments, this isn't expected to be a problem. But it's something to keep aware of. Imagine a case of 3 users that access 2 shared mailboxes ecah including their own, all logging in to the same computer with a 120GB SSD, with Outlook set to sync all mail. It is feasible for this to grow massively.&lt;br /&gt;
::* Automapping appears to be very finicky when mailbox delegation (permissions) are set to security groups instead of users. Discussion on the internet refers to having to reset permissions.&lt;br /&gt;
&lt;br /&gt;
==Contacts and Groups==&lt;br /&gt;
===Contacts===&lt;br /&gt;
Contacts are non-Exchange users i.e. either external to the organization e.g. a shareholder store. For now, the primary use of contacts is the distribution lists. Unlike in the previous Lotus Notes system where these contacts were merely email addresses e.g. &amp;quot;strings&amp;quot;, contacts in Exchange are &amp;quot;objects&amp;quot; and therefore have attributes like Company, First Name, Phone Number etc. This makes it feasible to have a directory of external contacts instead of just internal users.&lt;br /&gt;
====Shareholder email addresses====&lt;br /&gt;
 Note: It is not yet a company policy to maintain an address book of individual shareholder emails in Exchange/Outlook. These contacts are maintained for the sake of the mailing lists.&lt;br /&gt;
In an attempt to maintain clean and consistent entries, several conventions have already been put into play, best depicted in the following example entry for the personal email associated with Marks Marine Pharmacy (the one that would go in the private/sensitive list). The Classic Exchange admin center is shown as it exposes more fields:&lt;br /&gt;
::[[File:2021-03-06 22_15_29-Edit Mail Contact.png|400px|border]]&lt;br /&gt;
&lt;br /&gt;
Recommendations when creating new entries:&lt;br /&gt;
* If this contact/email will be used in private/confidential list only, prefix the Display Name with [Private]. Also, check the 'Hide contacts from the address list'. You may need to do this in Classic EAC.&lt;br /&gt;
* If this contact will be a member of both private and general/publicly-visible distribution lists, do not prefix the name.&lt;br /&gt;
&lt;br /&gt;
===Groups===&lt;br /&gt;
{{quote|03/31/2021 - Take these docs with a grain of salt, there's a lot of changes right now}}&lt;br /&gt;
The term groups in Exchange is encompassing of distribution lists and security groups (permissions). There are 4 types of Exchange groups. The two used primarily are ''Distribution list'' groups and ''Mail security'' groups. The former is equivalent to the idea of a conventional mailing list, wherein an email sent to the group address is distributed to its members. The latter is used for assigning permissions.&lt;br /&gt;
====Distribution Lists====&lt;br /&gt;
* The email address convention for department-based groups (and most other groups) is ''department''group@unipharm.com&lt;br /&gt;
* The following is an example of a configured group. The manager has been specified as a group owner in addition to IT to enable self-management.&lt;br /&gt;
::[[File:2021-03-06 14_41_32-Exchange admin center.png|300px|border]]&lt;br /&gt;
* Some groups are meant to be internal (e.g IT group), while others are meant to also be addressable by users outside the organization (e.g. Returns). Check related permissions and set up aliases accordingly. For example, Returns group follows the convention returnsgroup@unpharm.com, but it is logical to have '''returns@unipharm.com''' as an alias, as this is a more common format for a public-facing contact email address (same as customerservice@unipharm.com).&lt;br /&gt;
::[[File:2021-03-06 14_58_33-Exchange admin center.png|200px|border]]&lt;br /&gt;
&lt;br /&gt;
====Shareholder mailing lists====&lt;br /&gt;
There exist several mailing lists for correspondence with shareholders and associate members. Refer to the Contacts section above for how shareholder email addresses are maintained.&lt;br /&gt;
&lt;br /&gt;
====Sensitive mailing lists====&lt;br /&gt;
A few of the distribution lists are for sending confidential information to shareholders and associate members, and therefore have the 'Specified senders' permissons set. The option to prevent these lists and their constituent contacts from being displayed in the global address book should also be checked. The ability to hide contacts from address lists appears to currently be available only in the Classic admin center:&lt;br /&gt;
::[[File:2021-03-06 16_53_57-Edit Mail Contact.png|400px|border]]&lt;br /&gt;
====Other group types====&lt;br /&gt;
* '''Microsoft 365 groups''' have additional functionality to enable better collaboration for the group's members. The company currently does not collaborate in such a fashion for these to be useful (e.g. no Sharepoint, no Teams, no shared folders on cloud storage).&lt;br /&gt;
* '''Dynamic distribution list''' is a good concept on paper as it allows distribution lists to be &amp;quot;self-adjusting&amp;quot; based on attributes e.g. a Customer Service list could be set up to include any users with the Department attribute set to Customer Service. However, it was tested to have one major showstopping limitation - the dynamic nature of the list (recipients determined at the time of send) means it is not possible to view members of that list (neither in Outlook when trying to send to the list, or in the admin console). Not being able to see the recipients severely limits its usefulness, and therefore, setting up dynamic lists was forgone as an endeavor to potentially ease contact group administration. &lt;br /&gt;
====Nested groups====&lt;br /&gt;
'''A word of caution regarding nested groups.'''&lt;br /&gt;
&lt;br /&gt;
Nesting groups within other groups generally makes sense when it comes to permissions. This is especially true with Microsoft AD, where object hierarchy and the concept of RBAC are predominant (a user can be assigned one or more roles, which grants them the specific set of permissions associated with those roles). However, issues have been encountered with group nesting during setup, primarily related to &amp;quot;trying to get too fancy&amp;quot;. The ultimate goal was to have permissions and group membership dynamically assigned based on attribute e.g. the user's department. This was found to not even be remotely achievable in Exchange. These general rules of thumb have been surmised from experimentation with group nesting:&lt;br /&gt;
&lt;br /&gt;
* Nesting like group types appears to work. Distribution lists groups are ok to nest within other distribution list groups. The same goes for mail security groups.&lt;br /&gt;
* Nesting security groups can lead to some quirks, but is still recommended. For example, nested security groups seems to break shared mailbox automapping and ownership.&lt;br /&gt;
* Distribution list groups should not be nested within security groups (see point #1).&lt;br /&gt;
&lt;br /&gt;
TL;DR - exercise caution when using group nesting, and assign permissions to users as a fallback (troubleshoot later).&lt;br /&gt;
&lt;br /&gt;
==Address Book==&lt;br /&gt;
With Exchange address books, there exists two types of implementations: out-of-the-box or address book policies. This fork on the road comes early; either accept the out of the box functionality and do nothing else, or enter the world of address book policy routing and accept the more complex management. This of course depends on the needs of the company, and we needed and decided on the latter. This path also requires PowerShell (no options or visibility exists in EAC, besides the ability to assign an existing policy (created with PowerShell) to a user).&lt;br /&gt;
&lt;br /&gt;
===Address book policies===&lt;br /&gt;
An address book policy allows you to customize what a user sees, from the sublists, to the contacts viewable in those sublists. For example, the default address book policy has the following address lists: All Groups, All Users, All Distribution Lists etc. It is both unintuitive if you are not fully invested in the Microsoft way. For example, we don't use Microsoft groups, so All Groups is empty, and what we know as groups are actually, Distribution Lists. All Users, on the other hand, contains staff, but also shared mailboxes and resources (Projector, iPad), but not rooms. To make even one customization to all of this, ABPs are needed. &lt;br /&gt;
&lt;br /&gt;
* ABP routing is an Exchange flag that has been enabled for our domain.&lt;br /&gt;
* An address book policy specifies the following:&lt;br /&gt;
: * 1 x '''Global Address List (GAL)''' - contains all objects (mailboxes, contacts, rooms etc.) that a user is able to &amp;quot;see&amp;quot;. An ABP is linked to 1 GAL and therefore a user can only see 1 GAL.&lt;br /&gt;
: * 1 x '''Offline Address Book (OAB)''' - specifies one or more address lists to download/cache. To make it more confusing, the Offline Address Book behaves more like an address list.&lt;br /&gt;
: * 1 x '''Room Address List'''&lt;br /&gt;
: * 1 or more custom (or built-in) '''Address Lists''' - Address Lists are groupings that are subsetted from the GAL. For example, the built-in All Rooms address list filters for GAL objects where the ObjectType is RoomMailbox (not quite, but something to that effect).&lt;br /&gt;
&lt;br /&gt;
Again, all these are created/set in PowerShell.&lt;br /&gt;
&lt;br /&gt;
====Current address book policies====&lt;br /&gt;
There are two ABPs (default still exists but is not meant to be used).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Address Book Policy !! Global Address List !! Offline Address Book -&amp;gt; Offline Address List !! Room List !! Address Lists !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| Staff Address Book Policy || Staff Global Address List || Staff Offline Address Book -&amp;gt; Offline Address List (Staff) || Rooms and Resources || Company Contacts, Distribution Lists, Staff, Public Folders || Should be the default assigned to staff members.&lt;br /&gt;
|-&lt;br /&gt;
| Executive Address Book Policy || Executive Global Address List || Executive Offline Address Book -&amp;gt; Offline Address List (Executive) || Rooms and Resources || Company Contacts, Company Contacts (Executive), Distribution Lists, Distribution Lists (Executive), Staff, Public Folders || Can see what staff see, and the private lists/contacts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
''Congrats if you're still following at this point.''&lt;br /&gt;
&lt;br /&gt;
====Address Lists and Filtering====&lt;br /&gt;
The usefuleness of address book policies lies in filtering (inclusion filtering), which is used to produce address lists. This is a big topic and is mostly PowerShell talk. Therefore, this is left for official technical docs, but provided are two examples to try and explain the concept:&lt;br /&gt;
* The address list '''Distribution Lists (Executive)''' specifies a filter that translates to: &lt;br /&gt;
:Include only objects where:&lt;br /&gt;
::* ObjectClass equals 'group'&lt;br /&gt;
::* DisplayName is like '*(Private)'&lt;br /&gt;
* The address list '''Staff''' specifies a filter that translates to:&lt;br /&gt;
::Include only objects where:&lt;br /&gt;
::* ObjectCategory equals 'person' AND 'user'&lt;br /&gt;
::* RecipientType does not equal 'RoomMailbox'&lt;br /&gt;
::* RecipientType does not equal 'EquipmentMailbox'&lt;br /&gt;
&lt;br /&gt;
''These are not the exact filters used, they're meant to explain the concept only.''&lt;br /&gt;
&lt;br /&gt;
====Relationship between contact management and ABPs====&lt;br /&gt;
It should be noted that contacts, groups, and group membership are not affected by address book policies. ABPs only affect what a user sees in the address book. A not-good analogy: you can take out pages of a phone directory and group them differently or put stickers over some entries so they're not visible (ABPs), but you don't change what's printed in the directory (that's contact management).&lt;br /&gt;
&lt;br /&gt;
==Mail flow and mail rules==&lt;br /&gt;
===Connectors===&lt;br /&gt;
Because mail hosting for unipharm.com is spread over 2 servers, configuring Exchange &amp;quot;connectors&amp;quot; is necessary to properly route mail to and from MDaemon (the on-prem mail server). This is a complex topic and should be described on another page.&lt;br /&gt;
&lt;br /&gt;
==Email security==&lt;br /&gt;
Email security is handled by Exchange Online Protection, a feature that comes with all Exchange Online / 365 accounts. It &amp;quot;sits&amp;quot; before the mail routing/delivery process - for both inbound and outbound mail flows - and checks messages for threats and spam. The policies determine what gets detected as spam/threats and the outcome of those messages. Depending on if the new or classic admin portal is being used, there are various areas to configure or tweak these policies:&lt;br /&gt;
:* In Classic Admin Center, these policies are found in the '''protection''' section.&lt;br /&gt;
:* In New Admin Center, these policies are found in a separate '''Security and Compliance''' Admin Center altogether, under '''Threat management'''.&lt;br /&gt;
&lt;br /&gt;
===Malware policies===&lt;br /&gt;
* Email servers do a fairly good job detecting and blocking viruses in emails, silently. As an organization, we also don't deal with attachment types (.exe, audio/video containers etc.) that are normally flagged as viruses. Therefore, these policies have not been changed from the defaults. &lt;br /&gt;
&lt;br /&gt;
===Spam policies===&lt;br /&gt;
* Unlike spam-handling pre-Exchange that involved a user quarantine, the current spam policy is set to direct spam to a user's junk folder.&lt;br /&gt;
:[[File:2021-03-30 15_50_03-edit spam filter policy.png|400px]]&lt;br /&gt;
&lt;br /&gt;
====Spam scoring====&lt;br /&gt;
There are two scores related to spam-handling: SCL (Spam Confidence Level), and BCL (Bulk Complaint Level). The Bulk Complaint Level threshold can be set, but the SCL appears to be set (at least for Exchange Online). These values are 5 (spam) and 9 (high-confidence spam), according to [https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/spam-confidence-levels?view=o365-worldwide the docs]&lt;br /&gt;
&lt;br /&gt;
Note: These scores are present in the message headers, and have been validated to make it all the way to MDaemon (in messages destined for non-Exchange mailboxes). Therefore, we could potentially capitalize on the spam and bulk scoring done by EOP by having MDaemon recognize and act on these headers.&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
Phishing remains the greatest threat when it comes to email security. Without Advanced Threat Prection (additional cost on top of EOP), we rely on reputation-based and heuristic-based detection mechanisms of the email security service (EOP) to flag emails that contain phishing content. Barracuda did a fantastic job (very low penetration from empirical evidence). It remains to be seen how EOP handles these types of &amp;quot;attacks&amp;quot; (they come in waves).&lt;br /&gt;
&lt;br /&gt;
==Security/AAA==&lt;br /&gt;
===Custom Admin Roles===&lt;br /&gt;
Exchange allows for the creation of custom admin roles that have a specific combination of permissions. For example, the Company Directory Management role was created to allow users to manage the address book:&lt;br /&gt;
::[[File:2021-03-23 11_58_18-Exchange admin center.png|400px]]&lt;br /&gt;
&lt;br /&gt;
===Password policies===&lt;br /&gt;
* Password expiry has been disabled in 365 from the 90-day default:&lt;br /&gt;
::[[File:2021-03-23 12_14_04-Microsoft 365 admin center.png|border|400px]]&lt;br /&gt;
* Self-service password resets have been enabled in Azure AD. Users will be notified when they reset their passwords:&lt;br /&gt;
::[[File:2021-03-23 12_21_01-Password reset - Azure Active Directory admin center.png|400px|border]][[File:2021-03-23 12_23_00-Password reset - Azure Active Directory admin center.png|400px|border]]&lt;br /&gt;
* (Update this section with info on password management strategy when it gets discussed)&lt;br /&gt;
&lt;br /&gt;
==Other Notes==&lt;br /&gt;
* Microsoft is currently transitioning from what they're now terming Classic Exchange admin center to the New Exchange admin center. Some options remain editable only in the old portal.&lt;br /&gt;
&lt;br /&gt;
==SPF==&lt;br /&gt;
SPF has been enabled, https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/set-up-spf-in-office-365-to-help-prevent-spoofing?view=o365-worldwide, &lt;br /&gt;
Using a company like mxtoolbox, we can put in the email that we want to check the SPF record for and see how it is set.&lt;br /&gt;
::[[File:mxtoolboxunipharmspf.png]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=File:mtoolboxupipharmspf.png&amp;diff=13751</id>
		<title>File:mtoolboxupipharmspf.png</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=File:mtoolboxupipharmspf.png&amp;diff=13751"/>
		<updated>2021-04-26T18:02:15Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_365_Exchange_Online_-_Setup_and_Configuration&amp;diff=13750</id>
		<title>Information Systems:Microsoft 365 Exchange Online - Setup and Configuration</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_365_Exchange_Online_-_Setup_and_Configuration&amp;diff=13750"/>
		<updated>2021-04-26T17:56:59Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Other Notes */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This wiki page attempts to document and discuss major topics of Exchange setup and configuration. This will be a mix of design/strategy talk and some how-tos for technical administration. Ultimately, another page should be made to adapt the information discussed here into more concise technical instructions for specific administration tasks.&lt;br /&gt;
&lt;br /&gt;
==Mailboxes==&lt;br /&gt;
Users are essentially mailboxes in Exchange i.e. there is no Users section. In Exchange Online, a mailbox shows up when a user is created in 365 Admin Center.&lt;br /&gt;
&lt;br /&gt;
===Shared Mailboxes===&lt;br /&gt;
Like groups/lists, shared mailboxes are communal to a group of users. But unlike groups/lists, they are actual mailboxes that accumulate mail. The company requires a few of these:&lt;br /&gt;
* Accounts Payable: accountspayable@unipharm.com&lt;br /&gt;
* Accounts Receivable: accountsreceivable@unipharm.com&lt;br /&gt;
* EDI Support: edisupport@unipharm.com&lt;br /&gt;
* Customer Service Voicemail: csvm@unipharm.com&lt;br /&gt;
&lt;br /&gt;
====Adding a shared mailbox====&lt;br /&gt;
 Given the limited number of shared mailboxes, and the company's particular use of them as mailbox &amp;quot;identities&amp;quot; rather than a communal email &amp;quot;sink&amp;quot;, it has been decided to add shared mailboxes as separate accounts as opposed to opening them as additional mailboxes.&lt;br /&gt;
&lt;br /&gt;
To add a shared mailbox:&lt;br /&gt;
* Remove any shared mailboxes previously opened as additional mailboxes (and not added as accounts).&lt;br /&gt;
* Perform the steps to add another email account (Office 365).&lt;br /&gt;
* Enter in the shared mailbox email.&lt;br /&gt;
* Instead of entering a password, click ''Sign in as another account''.&lt;br /&gt;
* Enter in the user's credentials. This will only work if the user has Full Access permissions to the shared mailbox (do this in EAC).&lt;br /&gt;
&lt;br /&gt;
====Other methods====&lt;br /&gt;
The other ways of adding shared mailboxes are discussed here just for reference:&lt;br /&gt;
&lt;br /&gt;
'''''Manually opening a shared mailbox'''''&lt;br /&gt;
:* In Outlook 2019, File -&amp;gt; Account Settings -&amp;gt; double-click account -&amp;gt; More Settings -&amp;gt; Advanced&lt;br /&gt;
:* In the Mailboxes section -&amp;gt; Add -&amp;gt; Enter exact Display Name of shared mailbox&lt;br /&gt;
:* Save/Apply&lt;br /&gt;
&lt;br /&gt;
'''''Automapping'''''&lt;br /&gt;
:'''Note: Automapping has been disabled for all shared mailboxes.'''&lt;br /&gt;
&lt;br /&gt;
:* Automapping is a feature that makes the shared mailboxes which a user has access to automatically visible in Outlook i.e. the shared mailboxes are automatically mapped to the user. This is enabled by default. There are implications:&lt;br /&gt;
::* Automapping lumps the data of shared mailboxes in the same OST file as the user's own mailbox. This is one of the reasons there is official documentation on how to disable automapping and [https://docs.microsoft.com/en-us/outlook/troubleshoot/profiles-and-accounts/remove-automapping-for-shared-mailbox how to reset an automapped Outlook configuration]. Considering the company's user base and computer/desktop assignments, this isn't expected to be a problem. But it's something to keep aware of. Imagine a case of 3 users that access 2 shared mailboxes ecah including their own, all logging in to the same computer with a 120GB SSD, with Outlook set to sync all mail. It is feasible for this to grow massively.&lt;br /&gt;
::* Automapping appears to be very finicky when mailbox delegation (permissions) are set to security groups instead of users. Discussion on the internet refers to having to reset permissions.&lt;br /&gt;
&lt;br /&gt;
==Contacts and Groups==&lt;br /&gt;
===Contacts===&lt;br /&gt;
Contacts are non-Exchange users i.e. either external to the organization e.g. a shareholder store. For now, the primary use of contacts is the distribution lists. Unlike in the previous Lotus Notes system where these contacts were merely email addresses e.g. &amp;quot;strings&amp;quot;, contacts in Exchange are &amp;quot;objects&amp;quot; and therefore have attributes like Company, First Name, Phone Number etc. This makes it feasible to have a directory of external contacts instead of just internal users.&lt;br /&gt;
====Shareholder email addresses====&lt;br /&gt;
 Note: It is not yet a company policy to maintain an address book of individual shareholder emails in Exchange/Outlook. These contacts are maintained for the sake of the mailing lists.&lt;br /&gt;
In an attempt to maintain clean and consistent entries, several conventions have already been put into play, best depicted in the following example entry for the personal email associated with Marks Marine Pharmacy (the one that would go in the private/sensitive list). The Classic Exchange admin center is shown as it exposes more fields:&lt;br /&gt;
::[[File:2021-03-06 22_15_29-Edit Mail Contact.png|400px|border]]&lt;br /&gt;
&lt;br /&gt;
Recommendations when creating new entries:&lt;br /&gt;
* If this contact/email will be used in private/confidential list only, prefix the Display Name with [Private]. Also, check the 'Hide contacts from the address list'. You may need to do this in Classic EAC.&lt;br /&gt;
* If this contact will be a member of both private and general/publicly-visible distribution lists, do not prefix the name.&lt;br /&gt;
&lt;br /&gt;
===Groups===&lt;br /&gt;
{{quote|03/31/2021 - Take these docs with a grain of salt, there's a lot of changes right now}}&lt;br /&gt;
The term groups in Exchange is encompassing of distribution lists and security groups (permissions). There are 4 types of Exchange groups. The two used primarily are ''Distribution list'' groups and ''Mail security'' groups. The former is equivalent to the idea of a conventional mailing list, wherein an email sent to the group address is distributed to its members. The latter is used for assigning permissions.&lt;br /&gt;
====Distribution Lists====&lt;br /&gt;
* The email address convention for department-based groups (and most other groups) is ''department''group@unipharm.com&lt;br /&gt;
* The following is an example of a configured group. The manager has been specified as a group owner in addition to IT to enable self-management.&lt;br /&gt;
::[[File:2021-03-06 14_41_32-Exchange admin center.png|300px|border]]&lt;br /&gt;
* Some groups are meant to be internal (e.g IT group), while others are meant to also be addressable by users outside the organization (e.g. Returns). Check related permissions and set up aliases accordingly. For example, Returns group follows the convention returnsgroup@unpharm.com, but it is logical to have '''returns@unipharm.com''' as an alias, as this is a more common format for a public-facing contact email address (same as customerservice@unipharm.com).&lt;br /&gt;
::[[File:2021-03-06 14_58_33-Exchange admin center.png|200px|border]]&lt;br /&gt;
&lt;br /&gt;
====Shareholder mailing lists====&lt;br /&gt;
There exist several mailing lists for correspondence with shareholders and associate members. Refer to the Contacts section above for how shareholder email addresses are maintained.&lt;br /&gt;
&lt;br /&gt;
====Sensitive mailing lists====&lt;br /&gt;
A few of the distribution lists are for sending confidential information to shareholders and associate members, and therefore have the 'Specified senders' permissons set. The option to prevent these lists and their constituent contacts from being displayed in the global address book should also be checked. The ability to hide contacts from address lists appears to currently be available only in the Classic admin center:&lt;br /&gt;
::[[File:2021-03-06 16_53_57-Edit Mail Contact.png|400px|border]]&lt;br /&gt;
====Other group types====&lt;br /&gt;
* '''Microsoft 365 groups''' have additional functionality to enable better collaboration for the group's members. The company currently does not collaborate in such a fashion for these to be useful (e.g. no Sharepoint, no Teams, no shared folders on cloud storage).&lt;br /&gt;
* '''Dynamic distribution list''' is a good concept on paper as it allows distribution lists to be &amp;quot;self-adjusting&amp;quot; based on attributes e.g. a Customer Service list could be set up to include any users with the Department attribute set to Customer Service. However, it was tested to have one major showstopping limitation - the dynamic nature of the list (recipients determined at the time of send) means it is not possible to view members of that list (neither in Outlook when trying to send to the list, or in the admin console). Not being able to see the recipients severely limits its usefulness, and therefore, setting up dynamic lists was forgone as an endeavor to potentially ease contact group administration. &lt;br /&gt;
====Nested groups====&lt;br /&gt;
'''A word of caution regarding nested groups.'''&lt;br /&gt;
&lt;br /&gt;
Nesting groups within other groups generally makes sense when it comes to permissions. This is especially true with Microsoft AD, where object hierarchy and the concept of RBAC are predominant (a user can be assigned one or more roles, which grants them the specific set of permissions associated with those roles). However, issues have been encountered with group nesting during setup, primarily related to &amp;quot;trying to get too fancy&amp;quot;. The ultimate goal was to have permissions and group membership dynamically assigned based on attribute e.g. the user's department. This was found to not even be remotely achievable in Exchange. These general rules of thumb have been surmised from experimentation with group nesting:&lt;br /&gt;
&lt;br /&gt;
* Nesting like group types appears to work. Distribution lists groups are ok to nest within other distribution list groups. The same goes for mail security groups.&lt;br /&gt;
* Nesting security groups can lead to some quirks, but is still recommended. For example, nested security groups seems to break shared mailbox automapping and ownership.&lt;br /&gt;
* Distribution list groups should not be nested within security groups (see point #1).&lt;br /&gt;
&lt;br /&gt;
TL;DR - exercise caution when using group nesting, and assign permissions to users as a fallback (troubleshoot later).&lt;br /&gt;
&lt;br /&gt;
==Address Book==&lt;br /&gt;
With Exchange address books, there exists two types of implementations: out-of-the-box or address book policies. This fork on the road comes early; either accept the out of the box functionality and do nothing else, or enter the world of address book policy routing and accept the more complex management. This of course depends on the needs of the company, and we needed and decided on the latter. This path also requires PowerShell (no options or visibility exists in EAC, besides the ability to assign an existing policy (created with PowerShell) to a user).&lt;br /&gt;
&lt;br /&gt;
===Address book policies===&lt;br /&gt;
An address book policy allows you to customize what a user sees, from the sublists, to the contacts viewable in those sublists. For example, the default address book policy has the following address lists: All Groups, All Users, All Distribution Lists etc. It is both unintuitive if you are not fully invested in the Microsoft way. For example, we don't use Microsoft groups, so All Groups is empty, and what we know as groups are actually, Distribution Lists. All Users, on the other hand, contains staff, but also shared mailboxes and resources (Projector, iPad), but not rooms. To make even one customization to all of this, ABPs are needed. &lt;br /&gt;
&lt;br /&gt;
* ABP routing is an Exchange flag that has been enabled for our domain.&lt;br /&gt;
* An address book policy specifies the following:&lt;br /&gt;
: * 1 x '''Global Address List (GAL)''' - contains all objects (mailboxes, contacts, rooms etc.) that a user is able to &amp;quot;see&amp;quot;. An ABP is linked to 1 GAL and therefore a user can only see 1 GAL.&lt;br /&gt;
: * 1 x '''Offline Address Book (OAB)''' - specifies one or more address lists to download/cache. To make it more confusing, the Offline Address Book behaves more like an address list.&lt;br /&gt;
: * 1 x '''Room Address List'''&lt;br /&gt;
: * 1 or more custom (or built-in) '''Address Lists''' - Address Lists are groupings that are subsetted from the GAL. For example, the built-in All Rooms address list filters for GAL objects where the ObjectType is RoomMailbox (not quite, but something to that effect).&lt;br /&gt;
&lt;br /&gt;
Again, all these are created/set in PowerShell.&lt;br /&gt;
&lt;br /&gt;
====Current address book policies====&lt;br /&gt;
There are two ABPs (default still exists but is not meant to be used).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Address Book Policy !! Global Address List !! Offline Address Book -&amp;gt; Offline Address List !! Room List !! Address Lists !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| Staff Address Book Policy || Staff Global Address List || Staff Offline Address Book -&amp;gt; Offline Address List (Staff) || Rooms and Resources || Company Contacts, Distribution Lists, Staff, Public Folders || Should be the default assigned to staff members.&lt;br /&gt;
|-&lt;br /&gt;
| Executive Address Book Policy || Executive Global Address List || Executive Offline Address Book -&amp;gt; Offline Address List (Executive) || Rooms and Resources || Company Contacts, Company Contacts (Executive), Distribution Lists, Distribution Lists (Executive), Staff, Public Folders || Can see what staff see, and the private lists/contacts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
''Congrats if you're still following at this point.''&lt;br /&gt;
&lt;br /&gt;
====Address Lists and Filtering====&lt;br /&gt;
The usefuleness of address book policies lies in filtering (inclusion filtering), which is used to produce address lists. This is a big topic and is mostly PowerShell talk. Therefore, this is left for official technical docs, but provided are two examples to try and explain the concept:&lt;br /&gt;
* The address list '''Distribution Lists (Executive)''' specifies a filter that translates to: &lt;br /&gt;
:Include only objects where:&lt;br /&gt;
::* ObjectClass equals 'group'&lt;br /&gt;
::* DisplayName is like '*(Private)'&lt;br /&gt;
* The address list '''Staff''' specifies a filter that translates to:&lt;br /&gt;
::Include only objects where:&lt;br /&gt;
::* ObjectCategory equals 'person' AND 'user'&lt;br /&gt;
::* RecipientType does not equal 'RoomMailbox'&lt;br /&gt;
::* RecipientType does not equal 'EquipmentMailbox'&lt;br /&gt;
&lt;br /&gt;
''These are not the exact filters used, they're meant to explain the concept only.''&lt;br /&gt;
&lt;br /&gt;
====Relationship between contact management and ABPs====&lt;br /&gt;
It should be noted that contacts, groups, and group membership are not affected by address book policies. ABPs only affect what a user sees in the address book. A not-good analogy: you can take out pages of a phone directory and group them differently or put stickers over some entries so they're not visible (ABPs), but you don't change what's printed in the directory (that's contact management).&lt;br /&gt;
&lt;br /&gt;
==Mail flow and mail rules==&lt;br /&gt;
===Connectors===&lt;br /&gt;
Because mail hosting for unipharm.com is spread over 2 servers, configuring Exchange &amp;quot;connectors&amp;quot; is necessary to properly route mail to and from MDaemon (the on-prem mail server). This is a complex topic and should be described on another page.&lt;br /&gt;
&lt;br /&gt;
==Email security==&lt;br /&gt;
Email security is handled by Exchange Online Protection, a feature that comes with all Exchange Online / 365 accounts. It &amp;quot;sits&amp;quot; before the mail routing/delivery process - for both inbound and outbound mail flows - and checks messages for threats and spam. The policies determine what gets detected as spam/threats and the outcome of those messages. Depending on if the new or classic admin portal is being used, there are various areas to configure or tweak these policies:&lt;br /&gt;
:* In Classic Admin Center, these policies are found in the '''protection''' section.&lt;br /&gt;
:* In New Admin Center, these policies are found in a separate '''Security and Compliance''' Admin Center altogether, under '''Threat management'''.&lt;br /&gt;
&lt;br /&gt;
===Malware policies===&lt;br /&gt;
* Email servers do a fairly good job detecting and blocking viruses in emails, silently. As an organization, we also don't deal with attachment types (.exe, audio/video containers etc.) that are normally flagged as viruses. Therefore, these policies have not been changed from the defaults. &lt;br /&gt;
&lt;br /&gt;
===Spam policies===&lt;br /&gt;
* Unlike spam-handling pre-Exchange that involved a user quarantine, the current spam policy is set to direct spam to a user's junk folder.&lt;br /&gt;
:[[File:2021-03-30 15_50_03-edit spam filter policy.png|400px]]&lt;br /&gt;
&lt;br /&gt;
====Spam scoring====&lt;br /&gt;
There are two scores related to spam-handling: SCL (Spam Confidence Level), and BCL (Bulk Complaint Level). The Bulk Complaint Level threshold can be set, but the SCL appears to be set (at least for Exchange Online). These values are 5 (spam) and 9 (high-confidence spam), according to [https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/spam-confidence-levels?view=o365-worldwide the docs]&lt;br /&gt;
&lt;br /&gt;
Note: These scores are present in the message headers, and have been validated to make it all the way to MDaemon (in messages destined for non-Exchange mailboxes). Therefore, we could potentially capitalize on the spam and bulk scoring done by EOP by having MDaemon recognize and act on these headers.&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
Phishing remains the greatest threat when it comes to email security. Without Advanced Threat Prection (additional cost on top of EOP), we rely on reputation-based and heuristic-based detection mechanisms of the email security service (EOP) to flag emails that contain phishing content. Barracuda did a fantastic job (very low penetration from empirical evidence). It remains to be seen how EOP handles these types of &amp;quot;attacks&amp;quot; (they come in waves).&lt;br /&gt;
&lt;br /&gt;
==Security/AAA==&lt;br /&gt;
===Custom Admin Roles===&lt;br /&gt;
Exchange allows for the creation of custom admin roles that have a specific combination of permissions. For example, the Company Directory Management role was created to allow users to manage the address book:&lt;br /&gt;
::[[File:2021-03-23 11_58_18-Exchange admin center.png|400px]]&lt;br /&gt;
&lt;br /&gt;
===Password policies===&lt;br /&gt;
* Password expiry has been disabled in 365 from the 90-day default:&lt;br /&gt;
::[[File:2021-03-23 12_14_04-Microsoft 365 admin center.png|border|400px]]&lt;br /&gt;
* Self-service password resets have been enabled in Azure AD. Users will be notified when they reset their passwords:&lt;br /&gt;
::[[File:2021-03-23 12_21_01-Password reset - Azure Active Directory admin center.png|400px|border]][[File:2021-03-23 12_23_00-Password reset - Azure Active Directory admin center.png|400px|border]]&lt;br /&gt;
* (Update this section with info on password management strategy when it gets discussed)&lt;br /&gt;
&lt;br /&gt;
==Other Notes==&lt;br /&gt;
* Microsoft is currently transitioning from what they're now terming Classic Exchange admin center to the New Exchange admin center. Some options remain editable only in the old portal.&lt;br /&gt;
&lt;br /&gt;
==SPF==&lt;br /&gt;
SPF has been enabled, https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/set-up-spf-in-office-365-to-help-prevent-spoofing?view=o365-worldwide, &lt;br /&gt;
Using a company like mxtoolbox, we can put in the email that we want to check the SPF record for and see how it is set.&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_365_Exchange_Online_-_Setup_and_Configuration&amp;diff=13749</id>
		<title>Information Systems:Microsoft 365 Exchange Online - Setup and Configuration</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Microsoft_365_Exchange_Online_-_Setup_and_Configuration&amp;diff=13749"/>
		<updated>2021-04-26T17:56:11Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Other Notes */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;==Overview==&lt;br /&gt;
This wiki page attempts to document and discuss major topics of Exchange setup and configuration. This will be a mix of design/strategy talk and some how-tos for technical administration. Ultimately, another page should be made to adapt the information discussed here into more concise technical instructions for specific administration tasks.&lt;br /&gt;
&lt;br /&gt;
==Mailboxes==&lt;br /&gt;
Users are essentially mailboxes in Exchange i.e. there is no Users section. In Exchange Online, a mailbox shows up when a user is created in 365 Admin Center.&lt;br /&gt;
&lt;br /&gt;
===Shared Mailboxes===&lt;br /&gt;
Like groups/lists, shared mailboxes are communal to a group of users. But unlike groups/lists, they are actual mailboxes that accumulate mail. The company requires a few of these:&lt;br /&gt;
* Accounts Payable: accountspayable@unipharm.com&lt;br /&gt;
* Accounts Receivable: accountsreceivable@unipharm.com&lt;br /&gt;
* EDI Support: edisupport@unipharm.com&lt;br /&gt;
* Customer Service Voicemail: csvm@unipharm.com&lt;br /&gt;
&lt;br /&gt;
====Adding a shared mailbox====&lt;br /&gt;
 Given the limited number of shared mailboxes, and the company's particular use of them as mailbox &amp;quot;identities&amp;quot; rather than a communal email &amp;quot;sink&amp;quot;, it has been decided to add shared mailboxes as separate accounts as opposed to opening them as additional mailboxes.&lt;br /&gt;
&lt;br /&gt;
To add a shared mailbox:&lt;br /&gt;
* Remove any shared mailboxes previously opened as additional mailboxes (and not added as accounts).&lt;br /&gt;
* Perform the steps to add another email account (Office 365).&lt;br /&gt;
* Enter in the shared mailbox email.&lt;br /&gt;
* Instead of entering a password, click ''Sign in as another account''.&lt;br /&gt;
* Enter in the user's credentials. This will only work if the user has Full Access permissions to the shared mailbox (do this in EAC).&lt;br /&gt;
&lt;br /&gt;
====Other methods====&lt;br /&gt;
The other ways of adding shared mailboxes are discussed here just for reference:&lt;br /&gt;
&lt;br /&gt;
'''''Manually opening a shared mailbox'''''&lt;br /&gt;
:* In Outlook 2019, File -&amp;gt; Account Settings -&amp;gt; double-click account -&amp;gt; More Settings -&amp;gt; Advanced&lt;br /&gt;
:* In the Mailboxes section -&amp;gt; Add -&amp;gt; Enter exact Display Name of shared mailbox&lt;br /&gt;
:* Save/Apply&lt;br /&gt;
&lt;br /&gt;
'''''Automapping'''''&lt;br /&gt;
:'''Note: Automapping has been disabled for all shared mailboxes.'''&lt;br /&gt;
&lt;br /&gt;
:* Automapping is a feature that makes the shared mailboxes which a user has access to automatically visible in Outlook i.e. the shared mailboxes are automatically mapped to the user. This is enabled by default. There are implications:&lt;br /&gt;
::* Automapping lumps the data of shared mailboxes in the same OST file as the user's own mailbox. This is one of the reasons there is official documentation on how to disable automapping and [https://docs.microsoft.com/en-us/outlook/troubleshoot/profiles-and-accounts/remove-automapping-for-shared-mailbox how to reset an automapped Outlook configuration]. Considering the company's user base and computer/desktop assignments, this isn't expected to be a problem. But it's something to keep aware of. Imagine a case of 3 users that access 2 shared mailboxes ecah including their own, all logging in to the same computer with a 120GB SSD, with Outlook set to sync all mail. It is feasible for this to grow massively.&lt;br /&gt;
::* Automapping appears to be very finicky when mailbox delegation (permissions) are set to security groups instead of users. Discussion on the internet refers to having to reset permissions.&lt;br /&gt;
&lt;br /&gt;
==Contacts and Groups==&lt;br /&gt;
===Contacts===&lt;br /&gt;
Contacts are non-Exchange users i.e. either external to the organization e.g. a shareholder store. For now, the primary use of contacts is the distribution lists. Unlike in the previous Lotus Notes system where these contacts were merely email addresses e.g. &amp;quot;strings&amp;quot;, contacts in Exchange are &amp;quot;objects&amp;quot; and therefore have attributes like Company, First Name, Phone Number etc. This makes it feasible to have a directory of external contacts instead of just internal users.&lt;br /&gt;
====Shareholder email addresses====&lt;br /&gt;
 Note: It is not yet a company policy to maintain an address book of individual shareholder emails in Exchange/Outlook. These contacts are maintained for the sake of the mailing lists.&lt;br /&gt;
In an attempt to maintain clean and consistent entries, several conventions have already been put into play, best depicted in the following example entry for the personal email associated with Marks Marine Pharmacy (the one that would go in the private/sensitive list). The Classic Exchange admin center is shown as it exposes more fields:&lt;br /&gt;
::[[File:2021-03-06 22_15_29-Edit Mail Contact.png|400px|border]]&lt;br /&gt;
&lt;br /&gt;
Recommendations when creating new entries:&lt;br /&gt;
* If this contact/email will be used in private/confidential list only, prefix the Display Name with [Private]. Also, check the 'Hide contacts from the address list'. You may need to do this in Classic EAC.&lt;br /&gt;
* If this contact will be a member of both private and general/publicly-visible distribution lists, do not prefix the name.&lt;br /&gt;
&lt;br /&gt;
===Groups===&lt;br /&gt;
{{quote|03/31/2021 - Take these docs with a grain of salt, there's a lot of changes right now}}&lt;br /&gt;
The term groups in Exchange is encompassing of distribution lists and security groups (permissions). There are 4 types of Exchange groups. The two used primarily are ''Distribution list'' groups and ''Mail security'' groups. The former is equivalent to the idea of a conventional mailing list, wherein an email sent to the group address is distributed to its members. The latter is used for assigning permissions.&lt;br /&gt;
====Distribution Lists====&lt;br /&gt;
* The email address convention for department-based groups (and most other groups) is ''department''group@unipharm.com&lt;br /&gt;
* The following is an example of a configured group. The manager has been specified as a group owner in addition to IT to enable self-management.&lt;br /&gt;
::[[File:2021-03-06 14_41_32-Exchange admin center.png|300px|border]]&lt;br /&gt;
* Some groups are meant to be internal (e.g IT group), while others are meant to also be addressable by users outside the organization (e.g. Returns). Check related permissions and set up aliases accordingly. For example, Returns group follows the convention returnsgroup@unpharm.com, but it is logical to have '''returns@unipharm.com''' as an alias, as this is a more common format for a public-facing contact email address (same as customerservice@unipharm.com).&lt;br /&gt;
::[[File:2021-03-06 14_58_33-Exchange admin center.png|200px|border]]&lt;br /&gt;
&lt;br /&gt;
====Shareholder mailing lists====&lt;br /&gt;
There exist several mailing lists for correspondence with shareholders and associate members. Refer to the Contacts section above for how shareholder email addresses are maintained.&lt;br /&gt;
&lt;br /&gt;
====Sensitive mailing lists====&lt;br /&gt;
A few of the distribution lists are for sending confidential information to shareholders and associate members, and therefore have the 'Specified senders' permissons set. The option to prevent these lists and their constituent contacts from being displayed in the global address book should also be checked. The ability to hide contacts from address lists appears to currently be available only in the Classic admin center:&lt;br /&gt;
::[[File:2021-03-06 16_53_57-Edit Mail Contact.png|400px|border]]&lt;br /&gt;
====Other group types====&lt;br /&gt;
* '''Microsoft 365 groups''' have additional functionality to enable better collaboration for the group's members. The company currently does not collaborate in such a fashion for these to be useful (e.g. no Sharepoint, no Teams, no shared folders on cloud storage).&lt;br /&gt;
* '''Dynamic distribution list''' is a good concept on paper as it allows distribution lists to be &amp;quot;self-adjusting&amp;quot; based on attributes e.g. a Customer Service list could be set up to include any users with the Department attribute set to Customer Service. However, it was tested to have one major showstopping limitation - the dynamic nature of the list (recipients determined at the time of send) means it is not possible to view members of that list (neither in Outlook when trying to send to the list, or in the admin console). Not being able to see the recipients severely limits its usefulness, and therefore, setting up dynamic lists was forgone as an endeavor to potentially ease contact group administration. &lt;br /&gt;
====Nested groups====&lt;br /&gt;
'''A word of caution regarding nested groups.'''&lt;br /&gt;
&lt;br /&gt;
Nesting groups within other groups generally makes sense when it comes to permissions. This is especially true with Microsoft AD, where object hierarchy and the concept of RBAC are predominant (a user can be assigned one or more roles, which grants them the specific set of permissions associated with those roles). However, issues have been encountered with group nesting during setup, primarily related to &amp;quot;trying to get too fancy&amp;quot;. The ultimate goal was to have permissions and group membership dynamically assigned based on attribute e.g. the user's department. This was found to not even be remotely achievable in Exchange. These general rules of thumb have been surmised from experimentation with group nesting:&lt;br /&gt;
&lt;br /&gt;
* Nesting like group types appears to work. Distribution lists groups are ok to nest within other distribution list groups. The same goes for mail security groups.&lt;br /&gt;
* Nesting security groups can lead to some quirks, but is still recommended. For example, nested security groups seems to break shared mailbox automapping and ownership.&lt;br /&gt;
* Distribution list groups should not be nested within security groups (see point #1).&lt;br /&gt;
&lt;br /&gt;
TL;DR - exercise caution when using group nesting, and assign permissions to users as a fallback (troubleshoot later).&lt;br /&gt;
&lt;br /&gt;
==Address Book==&lt;br /&gt;
With Exchange address books, there exists two types of implementations: out-of-the-box or address book policies. This fork on the road comes early; either accept the out of the box functionality and do nothing else, or enter the world of address book policy routing and accept the more complex management. This of course depends on the needs of the company, and we needed and decided on the latter. This path also requires PowerShell (no options or visibility exists in EAC, besides the ability to assign an existing policy (created with PowerShell) to a user).&lt;br /&gt;
&lt;br /&gt;
===Address book policies===&lt;br /&gt;
An address book policy allows you to customize what a user sees, from the sublists, to the contacts viewable in those sublists. For example, the default address book policy has the following address lists: All Groups, All Users, All Distribution Lists etc. It is both unintuitive if you are not fully invested in the Microsoft way. For example, we don't use Microsoft groups, so All Groups is empty, and what we know as groups are actually, Distribution Lists. All Users, on the other hand, contains staff, but also shared mailboxes and resources (Projector, iPad), but not rooms. To make even one customization to all of this, ABPs are needed. &lt;br /&gt;
&lt;br /&gt;
* ABP routing is an Exchange flag that has been enabled for our domain.&lt;br /&gt;
* An address book policy specifies the following:&lt;br /&gt;
: * 1 x '''Global Address List (GAL)''' - contains all objects (mailboxes, contacts, rooms etc.) that a user is able to &amp;quot;see&amp;quot;. An ABP is linked to 1 GAL and therefore a user can only see 1 GAL.&lt;br /&gt;
: * 1 x '''Offline Address Book (OAB)''' - specifies one or more address lists to download/cache. To make it more confusing, the Offline Address Book behaves more like an address list.&lt;br /&gt;
: * 1 x '''Room Address List'''&lt;br /&gt;
: * 1 or more custom (or built-in) '''Address Lists''' - Address Lists are groupings that are subsetted from the GAL. For example, the built-in All Rooms address list filters for GAL objects where the ObjectType is RoomMailbox (not quite, but something to that effect).&lt;br /&gt;
&lt;br /&gt;
Again, all these are created/set in PowerShell.&lt;br /&gt;
&lt;br /&gt;
====Current address book policies====&lt;br /&gt;
There are two ABPs (default still exists but is not meant to be used).&lt;br /&gt;
&lt;br /&gt;
{| class=&amp;quot;wikitable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! Address Book Policy !! Global Address List !! Offline Address Book -&amp;gt; Offline Address List !! Room List !! Address Lists !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| Staff Address Book Policy || Staff Global Address List || Staff Offline Address Book -&amp;gt; Offline Address List (Staff) || Rooms and Resources || Company Contacts, Distribution Lists, Staff, Public Folders || Should be the default assigned to staff members.&lt;br /&gt;
|-&lt;br /&gt;
| Executive Address Book Policy || Executive Global Address List || Executive Offline Address Book -&amp;gt; Offline Address List (Executive) || Rooms and Resources || Company Contacts, Company Contacts (Executive), Distribution Lists, Distribution Lists (Executive), Staff, Public Folders || Can see what staff see, and the private lists/contacts.&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
''Congrats if you're still following at this point.''&lt;br /&gt;
&lt;br /&gt;
====Address Lists and Filtering====&lt;br /&gt;
The usefuleness of address book policies lies in filtering (inclusion filtering), which is used to produce address lists. This is a big topic and is mostly PowerShell talk. Therefore, this is left for official technical docs, but provided are two examples to try and explain the concept:&lt;br /&gt;
* The address list '''Distribution Lists (Executive)''' specifies a filter that translates to: &lt;br /&gt;
:Include only objects where:&lt;br /&gt;
::* ObjectClass equals 'group'&lt;br /&gt;
::* DisplayName is like '*(Private)'&lt;br /&gt;
* The address list '''Staff''' specifies a filter that translates to:&lt;br /&gt;
::Include only objects where:&lt;br /&gt;
::* ObjectCategory equals 'person' AND 'user'&lt;br /&gt;
::* RecipientType does not equal 'RoomMailbox'&lt;br /&gt;
::* RecipientType does not equal 'EquipmentMailbox'&lt;br /&gt;
&lt;br /&gt;
''These are not the exact filters used, they're meant to explain the concept only.''&lt;br /&gt;
&lt;br /&gt;
====Relationship between contact management and ABPs====&lt;br /&gt;
It should be noted that contacts, groups, and group membership are not affected by address book policies. ABPs only affect what a user sees in the address book. A not-good analogy: you can take out pages of a phone directory and group them differently or put stickers over some entries so they're not visible (ABPs), but you don't change what's printed in the directory (that's contact management).&lt;br /&gt;
&lt;br /&gt;
==Mail flow and mail rules==&lt;br /&gt;
===Connectors===&lt;br /&gt;
Because mail hosting for unipharm.com is spread over 2 servers, configuring Exchange &amp;quot;connectors&amp;quot; is necessary to properly route mail to and from MDaemon (the on-prem mail server). This is a complex topic and should be described on another page.&lt;br /&gt;
&lt;br /&gt;
==Email security==&lt;br /&gt;
Email security is handled by Exchange Online Protection, a feature that comes with all Exchange Online / 365 accounts. It &amp;quot;sits&amp;quot; before the mail routing/delivery process - for both inbound and outbound mail flows - and checks messages for threats and spam. The policies determine what gets detected as spam/threats and the outcome of those messages. Depending on if the new or classic admin portal is being used, there are various areas to configure or tweak these policies:&lt;br /&gt;
:* In Classic Admin Center, these policies are found in the '''protection''' section.&lt;br /&gt;
:* In New Admin Center, these policies are found in a separate '''Security and Compliance''' Admin Center altogether, under '''Threat management'''.&lt;br /&gt;
&lt;br /&gt;
===Malware policies===&lt;br /&gt;
* Email servers do a fairly good job detecting and blocking viruses in emails, silently. As an organization, we also don't deal with attachment types (.exe, audio/video containers etc.) that are normally flagged as viruses. Therefore, these policies have not been changed from the defaults. &lt;br /&gt;
&lt;br /&gt;
===Spam policies===&lt;br /&gt;
* Unlike spam-handling pre-Exchange that involved a user quarantine, the current spam policy is set to direct spam to a user's junk folder.&lt;br /&gt;
:[[File:2021-03-30 15_50_03-edit spam filter policy.png|400px]]&lt;br /&gt;
&lt;br /&gt;
====Spam scoring====&lt;br /&gt;
There are two scores related to spam-handling: SCL (Spam Confidence Level), and BCL (Bulk Complaint Level). The Bulk Complaint Level threshold can be set, but the SCL appears to be set (at least for Exchange Online). These values are 5 (spam) and 9 (high-confidence spam), according to [https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/spam-confidence-levels?view=o365-worldwide the docs]&lt;br /&gt;
&lt;br /&gt;
Note: These scores are present in the message headers, and have been validated to make it all the way to MDaemon (in messages destined for non-Exchange mailboxes). Therefore, we could potentially capitalize on the spam and bulk scoring done by EOP by having MDaemon recognize and act on these headers.&lt;br /&gt;
&lt;br /&gt;
===Phishing===&lt;br /&gt;
Phishing remains the greatest threat when it comes to email security. Without Advanced Threat Prection (additional cost on top of EOP), we rely on reputation-based and heuristic-based detection mechanisms of the email security service (EOP) to flag emails that contain phishing content. Barracuda did a fantastic job (very low penetration from empirical evidence). It remains to be seen how EOP handles these types of &amp;quot;attacks&amp;quot; (they come in waves).&lt;br /&gt;
&lt;br /&gt;
==Security/AAA==&lt;br /&gt;
===Custom Admin Roles===&lt;br /&gt;
Exchange allows for the creation of custom admin roles that have a specific combination of permissions. For example, the Company Directory Management role was created to allow users to manage the address book:&lt;br /&gt;
::[[File:2021-03-23 11_58_18-Exchange admin center.png|400px]]&lt;br /&gt;
&lt;br /&gt;
===Password policies===&lt;br /&gt;
* Password expiry has been disabled in 365 from the 90-day default:&lt;br /&gt;
::[[File:2021-03-23 12_14_04-Microsoft 365 admin center.png|border|400px]]&lt;br /&gt;
* Self-service password resets have been enabled in Azure AD. Users will be notified when they reset their passwords:&lt;br /&gt;
::[[File:2021-03-23 12_21_01-Password reset - Azure Active Directory admin center.png|400px|border]][[File:2021-03-23 12_23_00-Password reset - Azure Active Directory admin center.png|400px|border]]&lt;br /&gt;
* (Update this section with info on password management strategy when it gets discussed)&lt;br /&gt;
&lt;br /&gt;
==Other Notes==&lt;br /&gt;
* Microsoft is currently transitioning from what they're now terming Classic Exchange admin center to the New Exchange admin center. Some options remain editable only in the old portal.&lt;br /&gt;
&lt;br /&gt;
==SPF has been enabled, https://docs.microsoft.com/en-us/microsoft-365/security/office-365-security/set-up-spf-in-office-365-to-help-prevent-spoofing?view=o365-worldwide, &lt;br /&gt;
Using a company like mxtoolbox, we can put in the email that we want to check the SPF record for and see how it is set.&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Outlook_and_Exchange_-_Tips_for_Staff&amp;diff=13748</id>
		<title>Information Systems:Outlook and Exchange - Tips for Staff</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Outlook_and_Exchange_-_Tips_for_Staff&amp;diff=13748"/>
		<updated>2021-04-26T16:27:09Z</updated>

		<summary type="html">&lt;p&gt;Aaront: &lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;=Tips=&lt;br /&gt;
==Enable From: and BCC: fields==&lt;br /&gt;
* Create new email&lt;br /&gt;
* Go to Options tab&lt;br /&gt;
* Select From and BCC. These settings are enabled permanently thereafter.&lt;br /&gt;
:[[File:2021-03-30 22_32_27-Untitled - Message (HTML).png|300px|thumb| Only BCC is shown here, but you will likely have the From option as well.]]&lt;br /&gt;
&lt;br /&gt;
==Alternate navigation pane==&lt;br /&gt;
The navigation pane to toggle between Mail, Calendar, Contacts has icons by default. Change these to words:&lt;br /&gt;
* Click ellipses (3 dots, as shown below) in the navigation screen (bottom left of the screen):&lt;br /&gt;
:[[File:2021-03-30 22_38_48-Inbox - norwinu@unipharm.com - Outlook.png|300px|thumb]]&lt;br /&gt;
* Select ''Navigation Options''.&lt;br /&gt;
* Un-check Compact Navigation. Save.&lt;br /&gt;
:[[File:2021-03-30 22_40_28-Inbox - norwinu@unipharm.com - Outlook.png|300px|thumb]]&lt;br /&gt;
&lt;br /&gt;
==The elusive List view in Calendar==&lt;br /&gt;
Unlike in Notes, viewing the calendar as a list of events is not amongst the other quick toggles e.g. Day/Week/Month. However, it can be found in Change View:&lt;br /&gt;
&lt;br /&gt;
==Scheduled Delivery==&lt;br /&gt;
Finished an email but don't want to send it just yet, but also don't want to forget? Use the '''Delay Delivery''' feature, in the Options tab when creating an email&lt;br /&gt;
:[[File:2021-03-30 22_57_33-Untitled - Message (HTML).png|300px|thumb]]&lt;br /&gt;
Use this to schedule Away notices to staff, or scheduling an email at the start of the next business day so it doesn't get lost in the backlog ;)&lt;br /&gt;
&lt;br /&gt;
:[[File:2021-03-30 22_47_47-uniPHARM IS Operations Calendar - Internet Calendars - Outlook.png|300px]]&lt;br /&gt;
&lt;br /&gt;
==Recover deleted items from the server==&lt;br /&gt;
If you deleted a message and then emptied your Trash (''Deleted Items'' in Outlook) folder, there is a last resort / bailout. Navigate to the Deleted Items folder, and the ''Recover Deleted Items from Server'' option should appear at the top:&lt;br /&gt;
:[[File:2021-03-30 22_57_33-Untitled - Message (HTML).png|300px|thumb]]&lt;br /&gt;
&lt;br /&gt;
==Archive rather than delete==&lt;br /&gt;
Deleting emails should be done by choice, not to keep within quota. While a limit does still exist (50GB), this is on average 10-100x more than your previous mail quota.&lt;br /&gt;
&lt;br /&gt;
==Email signatures do not take up==&lt;br /&gt;
&lt;br /&gt;
==Templates or Saved Drafts==&lt;br /&gt;
In lotus notes folks used a lot of templates or pre made emails containing specific information that is used over and over. In order to do this in outlook, one way is to create a new email with all the required information and saving the email to the desktop. &lt;br /&gt;
&lt;br /&gt;
Another way is to create a template email and create a shortcut to the template on the desktop or somewhere the user is familiar with.&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
	<entry>
		<id>https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Workstation_UPS&amp;diff=13747</id>
		<title>Information Systems:Workstation UPS</title>
		<link rel="alternate" type="text/html" href="https://owl.unipharm.com/mediawiki/index.php?title=Information_Systems:Workstation_UPS&amp;diff=13747"/>
		<updated>2021-04-24T18:25:40Z</updated>

		<summary type="html">&lt;p&gt;Aaront: /* Notes */&lt;/p&gt;
&lt;hr /&gt;
&lt;div&gt;Many staff have a small UPS for their workstation. The models vary, and some serve multiple computers. Most are non-smart devices with no network presence.&lt;br /&gt;
&lt;br /&gt;
==Inventory==&lt;br /&gt;
{| class=&amp;quot;wikitable sortable&amp;quot;&lt;br /&gt;
|-&lt;br /&gt;
! User !! Location !! Model !! Date of last battery replacement !! Notes&lt;br /&gt;
|-&lt;br /&gt;
| Scanning PC 2 || Receiving Office || APC Back-UPS 1500 RS || 2020-05 || -&lt;br /&gt;
|-&lt;br /&gt;
| Customer Service || RavinderA desk || APC Smart 750 XL || 2020-05 || -&lt;br /&gt;
|-&lt;br /&gt;
|AaronT Workstation || - || Example || N/A || -&lt;br /&gt;
|-&lt;br /&gt;
|Returns-PC-1 || - || || ||-&lt;br /&gt;
|-&lt;br /&gt;
|Returns-PC-2 || - || || || -&lt;br /&gt;
|-&lt;br /&gt;
|Promo-PC2 || - || || || -&lt;br /&gt;
&lt;br /&gt;
|}&lt;br /&gt;
&lt;br /&gt;
==Notes==&lt;br /&gt;
* Free management software should be installed on each workstation with a UPS (and connected via USB). To date, this has never been done.&lt;br /&gt;
&lt;br /&gt;
There is software configured on the customer service UPS and is a great example of how to setup the rest.&lt;br /&gt;
[[Category: Power, Alarms, and Monitoring]]&lt;/div&gt;</summary>
		<author><name>Aaront</name></author>
	</entry>
</feed>